Repository navigation
chore: add Docker images, docker-compose, and CI workflow - #38
Conversation
CodeLens Pre-Review Analysis10 hunks scanned · 50 similar past patterns matched Finding 1: GitHub Actions uses unpinned action references (checkout@v4, setup-node@v4) (inferred)Location: Your code (this PR): Evidence: Past reviewers flagged unpinned actions as a security issue in similar workflow files Past reviews that triggered this (2 matches):
Finding 2: The bcryptjs dependency was downgraded from ^3.0.3 to ^3.0.2 without an explicit justification (inferred)Location: Your code (this PR): "bcryptjs": "^3.0.2",
"express-rate-limit": "^8.2.1",
"jsonwebtoken": "^9.0.2",Evidence: Past reviewers warned to double‑check version changes against lockfiles and installed versions Past reviews that triggered this (1 match):
Finding 3: The express-rate-limit dependency was downgraded from ^8.7.0 to ^8.2.1, which may introduce regressions (inferred)Location: Your code (this PR): "bcryptjs": "^3.0.2",
"express-rate-limit": "^8.2.1",
"jsonwebtoken": "^9.0.2",Evidence: Similar past comments highlighted the need to verify resolved versions after a downgrade Past reviews that triggered this (1 match):
Finding 4: The jsonwebtoken dependency was downgraded from ^9.0.3 to ^9.0.2, potentially affecting security patches (inferred)Location: Your code (this PR): "bcryptjs": "^3.0.2",
"express-rate-limit": "^8.2.1",
"jsonwebtoken": "^9.0.2",Evidence: Reviewers previously emphasized checking that version pins align with the lockfile and installed packages Past reviews that triggered this (1 match):
Finding 5: Downgrading @types/supertest to 6.0.2 while keeping supertest at 7.1.4 may cause type incompatibilities (inferred)Location: Your code (this PR): "@types/jsonwebtoken": "^9.0.7",
"@types/supertest": "^6.0.2",
"supertest": "^7.1.4",Evidence: Past reviewers warned that version downgrades can break builds, e.g., the comment about a downgrade causing GitHub Actions tests to fail Past reviews that triggered this (1 match):
Finding 6: Using the floating image tag 'mongo:7' could introduce unexpected breaking changes when the upstream image updates (inferred)Location: Your code (this PR): Evidence: Past reviewers flagged version pinning concerns, noting the need for explicit version floors to avoid breakages Past reviews that triggered this (2 matches):
Finding 7: Hardcoded upstream API URL in proxy_pass (inferred)Location: Your code (this PR): Evidence: Past review comment [0] flagged a hardcoded proxy target and suggested using an environment variable Past reviews that triggered this (1 match):
This analysis was generated automatically by CodeLens based on historical review patterns. |
|
|
||
| WORKDIR /app | ||
|
|
||
| COPY package.json package-lock.json ./ |
There was a problem hiding this comment.
Lockfiles copied before the rest of the source in both stages, deliberately, so the npm ci layer only invalidates when dependencies actually change, not on every code edit.
|
|
||
| FROM node:24-alpine | ||
|
|
||
| ENV NODE_ENV=production |
There was a problem hiding this comment.
NODE_ENV set to production before the second npm ci runs, not after, so the install itself happens in the same mode the app will actually run in.
| WORKDIR /app | ||
|
|
||
| COPY package.json package-lock.json ./ | ||
| RUN npm ci --omit=dev |
There was a problem hiding this comment.
--omit=dev here versus a plain npm ci in the builder stage above. The builder needs devDependencies to run tsc; the runtime image never should, that's exactly what keeps pino-pretty and the rest of the dev toolchain out of the shipped image.
| COPY package.json package-lock.json ./ | ||
| RUN npm ci --omit=dev | ||
|
|
||
| COPY --from=builder --chown=node:node /app/dist ./dist |
There was a problem hiding this comment.
--chown=node:node set at copy time rather than a separate RUN chown afterward, since COPY always runs as root regardless of the USER instruction below it.
|
|
||
| COPY --from=builder --chown=node:node /app/dist ./dist | ||
|
|
||
| USER node |
There was a problem hiding this comment.
Switches to the node user, which official Node images already ship pre-created specifically for this, rather than creating a new user manually.
| env_file: | ||
| - ./api/.env | ||
| environment: | ||
| NODE_ENV: production |
There was a problem hiding this comment.
NODE_ENV explicitly set to production here rather than left to inherit from the api container's own .env file, which has NODE_ENV=development for local dev. Confirmed this matters concretely, the container crashes on boot if this is left as development, since pino-pretty is a dev dependency that's deliberately absent from the production image.
| CLIENT_ORIGIN: http://localhost:5173 | ||
| ports: | ||
| - "4000:4000" | ||
| depends_on: |
There was a problem hiding this comment.
depends_on with condition service_healthy specifically, not the bare form. The bare form only waits for the mongo container to start, which happens almost immediately, well before the replica set is actually usable.
| defaults: | ||
| run: | ||
| working-directory: api | ||
| env: |
There was a problem hiding this comment.
These env values are placeholders, not secrets, and that's deliberate. The test suite never actually connects to MONGODB_URI's value, it spins up its own in-memory replica set instead, these only exist so config/env.ts's Zod validation doesn't reject an empty process.env and exit before a single test runs. Confirmed this exact scenario locally by running the full suite with no .env file present and only these values set.
|
|
||
| - uses: actions/setup-node@v4 | ||
| with: | ||
| node-version-file: ".nvmrc" |
There was a problem hiding this comment.
node-version-file pointed at .nvmrc directly rather than a hardcoded version number, so CI and local dev are guaranteed to run the identical Node version instead of two version strings that can quietly drift apart.
| cache-dependency-path: api/package-lock.json | ||
|
|
||
| - run: npm ci | ||
| - run: npm run lint |
There was a problem hiding this comment.
Lint before typecheck before test, cheapest and fastest check first so an obvious style failure doesn't wait behind an eight-second test run to report.
chore: add Docker images, docker-compose, and CI workflow
chore: add Docker images, docker-compose, and CI workflow
No description provided.