Skip to content

Migrate rest-api-typescript to BullMQ v6 - #1450

Open
ryjones wants to merge 1 commit into
mainfrom
fix/rest-api-bullmq-v6
Open

ryjones wants to merge 1 commit into
mainfrom
fix/rest-api-bullmq-v6

Conversation

@ryjones

@ryjones ryjones commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

bullmq@1 depends on uuid@^9, which is affected by GHSA-w5hq-g745-h8pq (missing buffer bounds check in v3/v5/v6, patched in 11.1.1). No patched uuid is reachable while bullmq stays on v1, so move the sample to v6, which has no uuid dependency at all.

Dependabot tried the same bump in #1448 and broke CI, because it cannot be done as a dependency-only change:

  • bullmq@1 vendored its own ioredis@5 under node_modules/bullmq, so it never met the root's ioredis@4. bullmq@6 declares ioredis as a peer (>=5.0.0) instead, so it now resolves against the root, which must move to ioredis 5 along with ioredis-mock 8. @types/ioredis goes away because ioredis 5 ships its own types.

  • QueueScheduler was removed in bullmq v2, its stalled and delayed job handling folded into Worker. Drop initJobQueueScheduler, its startup and shutdown paths, and the SUBMIT_JOB_QUEUE_SCHEDULER config option that gated it.

  • Job.update was renamed Job.updateData in v5.

  • ioredis 5 types the CONFIG GET reply as unknown.

engines.node moves from >=12 to >=20 to match the other maintained TypeScript samples; bullmq 6 cannot run on Node 12 anyway.

tsconfig.json now names its types explicitly. Newer @tsconfig/node12 releases set "types": ["node"], which silently drops the jest globals: suites that import jest-mock-extended still see them through its triple-slash reference, but config.spec.ts and redis.spec.ts do not, and fail to compile the moment the lockfile re-resolves that package.

Fixes #1449

@ryjones
ryjones requested a review from a team as a code owner September 8, 2026 08:17
@ryjones
ryjones force-pushed the fix/rest-api-bullmq-v6 branch from 0db5b18 to 24f3d84 Compare September 8, 2026 14:39
bullmq@1 depends on uuid@^9, which is affected by GHSA-w5hq-g745-h8pq
(missing buffer bounds check in v3/v5/v6, patched in 11.1.1).  No patched
uuid is reachable while bullmq stays on v1, so move the sample to v6,
which has no uuid dependency at all.

Dependabot tried the same bump in #1448 and broke CI, because it cannot
be done as a dependency-only change:

- bullmq@1 vendored its own ioredis@5 under node_modules/bullmq, so it
  never met the root's ioredis@4.  bullmq@6 declares ioredis as a peer
  (>=5.0.0) instead, so it now resolves against the root, which must
  move to ioredis 5 along with ioredis-mock 8.  @types/ioredis goes away
  because ioredis 5 ships its own types.

- QueueScheduler was removed in bullmq v2, its stalled and delayed job
  handling folded into Worker.  Drop initJobQueueScheduler, its startup
  and shutdown paths, and the SUBMIT_JOB_QUEUE_SCHEDULER config option
  that gated it.

- Job.update was renamed Job.updateData in v5.

- ioredis 5 types the CONFIG GET reply as unknown.

engines.node moves from >=12 to >=20 to match the other maintained
TypeScript samples; bullmq 6 cannot run on Node 12 anyway.

tsconfig.json now names its types explicitly.  Newer @tsconfig/node12
releases set "types": ["node"], which silently drops the jest globals:
suites that import jest-mock-extended still see them through its
triple-slash reference, but config.spec.ts and redis.spec.ts do not, and
fail to compile the moment the lockfile re-resolves that package.

Fixes #1449

Assisted-by: anthropic:claude-fable-5-1
Signed-off-by: Ry Jones <ry@linux.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

rest-api-typescript: migrate off bullmq v1 to clear the uuid advisory

1 participant