Repository navigation
chore(deps): bump svix to 1.99.1 and cover webhook signature verification - #66
Merged
Merged
Conversation
…tion The Snyk PR could not pass CI because it edits package.json without regenerating bun.lock, and lint installs with --frozen-lockfile. Claude-Session: https://claude.ai/code/session_01F1stiNzuNtJXoXtiW9ZCbs
Contributor
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
This was referenced Aug 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces #65. Snyk's PR bumps
package.jsonbut cannot regeneratebun.lock, and every CI job installs withbun install --frozen-lockfile, so that PR fails at the install step and can never go green. Any future Snyk PR here will fail the same way.This does the bump properly (svix 1.94.0 to 1.99.1, the current latest, lockfile regenerated) and adds the test coverage that was missing:
verifyWebhookSignaturehad no tests at all in this SDK, even though the go and python SDKs both cover their equivalents. The new tests sign a payload with svix and assert the SDK verifies it, then assert it rejects a tampered payload, a signature made with a different secret, and a timestamp outside the tolerated window. That is what makes this dependency bump verifiable rather than hopeful.Version 5.0.0 to 5.0.1 so consumers pick up the dependency change (publish.yaml's registry guard releases it on merge).
Proof
bun run test: 19 files, 97 tests pass (was 93; 4 new)bun run lint:check: cleanbun run check-types: cleannode scripts/contract-check.mjs: OK, 1428 fields checked, 23 webhook events, 27 allow-list entries in usehttps://claude.ai/code/session_01F1stiNzuNtJXoXtiW9ZCbs