Repository navigation
Comparing changes
Open a pull request
base repository: PNHD/https-localhost
base: master
head repository: daquinoaldo/https-localhost
compare: master
- 15 commits
- 54 files changed
- 3 contributors
Commits on Sep 6, 2026
-
Configuration menu - View commit details
-
Copy full SHA for f0d9b9f - Browse repository at this point
Copy the full SHA f0d9b9fView commit details -
Configuration menu - View commit details
-
Copy full SHA for 8afb669 - Browse repository at this point
Copy the full SHA 8afb669View commit details -
Avoid installing a global uncaughtException handler on import (daquin…
…oaldo#112) # Pull Request Details ## Related Issue Addresses daquinoaldo#77. Importing `https-localhost` currently installs a process-wide `uncaughtException` handler even when the package is only used as a module. That changes application-level error handling and can hide the original stack-trace behavior. This change scopes the existing handler to the CLI path (`require.main === module`) so the CLI keeps its friendly `EACCES` / `EADDRINUSE` messages while library consumers no longer get a global process listener as a side effect of `require("https-localhost")`. A regression test re-imports the module after clearing the require cache and verifies that the `uncaughtException` listener count does not change. ## Types of changes - [ ] Docs change / refactoring / dependency upgrade - [x] Bug fix (non-breaking change which fixes an issue) - [ ] New feature (non-breaking change which adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) ## Checklist - [x] My code follows the code style of this project. - [x] I have updated the documentation or my changes dont require it. - [x] I have read the CONTRIBUTING document. - [x] I have added tests to cover my changes. - [ ] All new and existing tests passed.
Configuration menu - View commit details
-
Copy full SHA for 3bee595 - Browse repository at this point
Copy the full SHA 3bee595View commit details -
Configuration menu - View commit details
-
Copy full SHA for 0ef1cb9 - Browse repository at this point
Copy the full SHA 0ef1cb9View commit details -
ci: use npm trusted publishing (daquinoaldo#117)
Configure the release workflow for npm Trusted Publishing via GitHub OIDC. Supports publishing the already-tagged v4.7.2 without creating another version bump.
Configuration menu - View commit details
-
Copy full SHA for 314eee3 - Browse repository at this point
Copy the full SHA 314eee3View commit details -
ci: use Node 24 and add 'existing' option to release workflow (daquin…
…oaldo#118) Bump release runner to Node 24 for npm Trusted Publishing OIDC support, and consolidate the release action into a single `upgrade` input with options: `patch`, `minor`, `major`, and `existing` (publish without re-bumping).
Configuration menu - View commit details
-
Copy full SHA for dd59376 - Browse repository at this point
Copy the full SHA dd59376View commit details
Commits on Sep 14, 2026
-
feat!: modernize to TypeScript, plain Node http, and pnpm (Node 24+) (d…
…aquinoaldo#119) ## Breaking changes - **Node.js 24 or newer is required** (tested on Node 24 and 26; release runs on 26) - **License changed from AGPL-3.0 to MIT** - **`express` app replaced with a minimal router**: the module no longer returns an express app. `createServer()` now takes named options (`domain`, `certPath`, `reinstall`) and exposes `get`, `listen`, `redirect`, `serve` - **Dual ESM/CJS build**: published package ships `dist/` (ESM + CJS + types) instead of raw source - **Production mode removed**: HTTP/2 (`spdy`), compression, minify, and the packaged-binary update checker are gone — this is a development tool - **pnpm** replaces npm for development and CI ## What changed - **Migrated the whole project to TypeScript** (`strict`, type-aware linting) - **Replaced `express` and `cors` with plain `node:http` handlers**: static serving (ETag, Last-Modified, range requests, 404 fallback, directory redirect, MIME types via `mrmime`), request routing, and CORS headers now live in small dedicated modules; dependencies reduced to `mrmime` and `zod` - **Validated CLI configuration**: flags via `parseArgs` (`-p`, `-H`, `--cert-path`, `--reinstall`) layered over environment variables, parsed with `zod` - **Security hardening** (resolves all open CodeQL alerts): - `execFile` instead of shell string concatenation for mkcert invocations - path traversal protection and sanitized directory redirects in the static handler - rejection of protocol-relative and absolute-form request targets - tests trust the mkcert root CA instead of disabling certificate validation - **mkcert upgraded to v1.4.4**; download is skipped when the binary already exists, and the download stream is closed cleanly - **Toolchain**: `oxlint` + `oxfmt` + `knip` replace ESLint; native `node:test` runner with tests split by source module; internalized `appdata-path` - **CI**: test matrix on Node 24/26 across Ubuntu/macOS, explicit workflow permissions, SHA-pinned actions, concurrency cancellation, lint step in CI; Coveralls and stale-bot message config updated - **New `CONTRIBUTING.md`** with the local gate commands ## Verification - All CI checks green (CodeQL, tests on 24/26 × Ubuntu/macOS) - Locally: `pnpm run lint` and `pnpm test` (33/33) pass on Node 24
Configuration menu - View commit details
-
Copy full SHA for c580766 - Browse repository at this point
Copy the full SHA c580766View commit details -
🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
Configuration menu - View commit details
-
Copy full SHA for 7ed932f - Browse repository at this point
Copy the full SHA 7ed932fView commit details -
Configuration menu - View commit details
-
Copy full SHA for 607efc4 - Browse repository at this point
Copy the full SHA 607efc4View commit details -
feat: add proxy mode for forwarding requests to an upstream server
- add src/proxy.ts with hop-by-hop header filtering and x-forwarded-* headers - add --proxy CLI flag and PROXY_TARGET env var (mutually exclusive with path) - make serve/redirect/proxy/listen async, resolving once listening - remove app.get() custom-route API - add proxy, env validation, and CLI exclusivity tests 🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
Configuration menu - View commit details
-
Copy full SHA for 9718252 - Browse repository at this point
Copy the full SHA 9718252View commit details
Commits on Sep 15, 2026
-
fix: crash and RFC compliance edge cases (daquinoaldo#121)
## Summary Fixes all ten crash, hang, RFC-compliance, proxy, and response-quality bugs found in the review. Each fix is a separate commit; the edge-case test suite lands first. - **Malformed percent-encoding crashed the server**: `/%zz` threw `URIError`; now rejected safely. (`904a911`) - **Directory without `index.html` crashed the server**: now serves 404. (`f6209f7`) - **`If-Modified-Since` alone never produced 304**: now honored per RFC 9110. (`f407c96`) - **Upstream dying mid-response hung clients**: client socket now closes. (`9db8e12`) - **Proxy CORS preflight hit the upstream**: OPTIONS now returns 204 directly. (`98305ef`) - **Packaged update check could raise an uncaught callback error**: callback failures are contained. (`b3f8b15`) - **Multi-range requests incorrectly returned 416**: first range is served. (`1f0ab67`) - **WebSocket upgrades were unsupported**: HTTP and HTTPS upstream upgrade tunneling added. (`28183b9`) - **Existing `X-Forwarded-For` was overwritten**: client address is appended. (`330e42d`) - **Static 400/403/405/416 responses had empty bodies**: descriptive text bodies added. (`e998c05`) ## Verification - Edge-case suite and full tests pass where ports are available. - `pnpm lint` passes. - The two redirect tests are blocked locally by an unrelated `node server.js` process occupying port 8080. 🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
Configuration menu - View commit details
-
Copy full SHA for 8dea99e - Browse repository at this point
Copy the full SHA 8dea99eView commit details -
Configuration menu - View commit details
-
Copy full SHA for f4a0825 - Browse repository at this point
Copy the full SHA f4a0825View commit details
Commits on Sep 16, 2026
-
ci: enforce lint and formatting instead of silently fixing them (daqu…
…inoaldo#123) ## Summary `pnpm lint` ran `oxfmt` in write mode and `oxlint --fix`, so CI silently rewrote an unformatted tree and passed — format and lint drift was never caught. - `lint` is now non-mutating: `oxfmt --check && oxlint && knip && tsc --noEmit` - New `fix` script that runs everything `lint` does, plus the auto-format (`oxfmt`) and auto-fix (`oxlint --fix`) passes: `oxfmt && oxlint --fix && knip && tsc --noEmit` - CONTRIBUTING documents both Verified: `pnpm lint` and `pnpm fix` both pass on a clean tree. 🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
Configuration menu - View commit details
-
Copy full SHA for 04bac62 - Browse repository at this point
Copy the full SHA 04bac62View commit details -
feat!: remove standalone binaries and the pkg update check (daquinoal…
…do#124) ## Summary Removes the standalone-binary feature entirely. The binaries bundled the app with vercel/pkg (archived upstream) on an EOL Node 16 runtime, and the update check they carried (`checkUpdates`) never worked even inside the binary. The package already requires Node ≥ 24, so anyone without Node cannot use it anyway. - Remove the `pkg` config from package.json - Remove the binary build/upload step from the release workflow (publish to npm only) - Remove the "Standalone binaries" section from the README - Remove the dead `checkUpdates` code from src/certs.ts **Breaking:** the GitHub release assets (`https-localhost-linux/macos/win.exe`) will no longer be produced. Users without Node must install Node (≥ 24) and `npm i -g https-localhost`. Verified: `pnpm lint` green, `pnpm test` green (except the 2 pre-existing environmental port-8080 failures on my machine). 🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
Configuration menu - View commit details
-
Copy full SHA for b0544be - Browse repository at this point
Copy the full SHA b0544beView commit details -
ci: configure monthly Dependabot updates (daquinoaldo#125)
## Summary Configure Dependabot to open monthly grouped update PRs for: - npm dependencies (`package.json` / `pnpm-lock.yaml`) - GitHub Actions Both group all updates into one PR and limit open Dependabot PRs to one per ecosystem. Note: all Actions in this repo are already pinned to commit SHAs; Dependabot updates the SHA (and the version comment) for each pinned action. 🤖 Generated with [OpenCode](https://opencode.ai)
Configuration menu - View commit details
-
Copy full SHA for 177899e - Browse repository at this point
Copy the full SHA 177899eView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff master...master