Conversation
ryjones
force-pushed
the
fix/rest-api-bullmq-v6
branch
from
September 8, 2026 14:39
0db5b18 to
24f3d84
Compare
bullmq@1 depends on uuid@^9, which is affected by GHSA-w5hq-g745-h8pq (missing buffer bounds check in v3/v5/v6, patched in 11.1.1). No patched uuid is reachable while bullmq stays on v1, so move the sample to v6, which has no uuid dependency at all. Dependabot tried the same bump in #1448 and broke CI, because it cannot be done as a dependency-only change: - bullmq@1 vendored its own ioredis@5 under node_modules/bullmq, so it never met the root's ioredis@4. bullmq@6 declares ioredis as a peer (>=5.0.0) instead, so it now resolves against the root, which must move to ioredis 5 along with ioredis-mock 8. @types/ioredis goes away because ioredis 5 ships its own types. - QueueScheduler was removed in bullmq v2, its stalled and delayed job handling folded into Worker. Drop initJobQueueScheduler, its startup and shutdown paths, and the SUBMIT_JOB_QUEUE_SCHEDULER config option that gated it. - Job.update was renamed Job.updateData in v5. - ioredis 5 types the CONFIG GET reply as unknown. engines.node moves from >=12 to >=20 to match the other maintained TypeScript samples; bullmq 6 cannot run on Node 12 anyway. tsconfig.json now names its types explicitly. Newer @tsconfig/node12 releases set "types": ["node"], which silently drops the jest globals: suites that import jest-mock-extended still see them through its triple-slash reference, but config.spec.ts and redis.spec.ts do not, and fail to compile the moment the lockfile re-resolves that package. Fixes #1449 Assisted-by: anthropic:claude-fable-5-1 Signed-off-by: Ry Jones <ry@linux.com>
ryjones
force-pushed
the
fix/rest-api-bullmq-v6
branch
from
September 8, 2026 14:43
24f3d84 to
3b256a0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
bullmq@1 depends on uuid@^9, which is affected by GHSA-w5hq-g745-h8pq (missing buffer bounds check in v3/v5/v6, patched in 11.1.1). No patched uuid is reachable while bullmq stays on v1, so move the sample to v6, which has no uuid dependency at all.
Dependabot tried the same bump in #1448 and broke CI, because it cannot be done as a dependency-only change:
bullmq@1 vendored its own ioredis@5 under node_modules/bullmq, so it never met the root's ioredis@4. bullmq@6 declares ioredis as a peer (>=5.0.0) instead, so it now resolves against the root, which must move to ioredis 5 along with ioredis-mock 8. @types/ioredis goes away because ioredis 5 ships its own types.
QueueScheduler was removed in bullmq v2, its stalled and delayed job handling folded into Worker. Drop initJobQueueScheduler, its startup and shutdown paths, and the SUBMIT_JOB_QUEUE_SCHEDULER config option that gated it.
Job.update was renamed Job.updateData in v5.
ioredis 5 types the CONFIG GET reply as unknown.
engines.node moves from >=12 to >=20 to match the other maintained TypeScript samples; bullmq 6 cannot run on Node 12 anyway.
tsconfig.json now names its types explicitly. Newer @tsconfig/node12 releases set "types": ["node"], which silently drops the jest globals: suites that import jest-mock-extended still see them through its triple-slash reference, but config.spec.ts and redis.spec.ts do not, and fail to compile the moment the lockfile re-resolves that package.
Fixes #1449