Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: karzanOnline/https-localhost
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: master
Choose a base ref
...
head repository: daquinoaldo/https-localhost
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: master
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 15 commits
  • 54 files changed
  • 3 contributors

Commits on Sep 6, 2026

  1. Configuration menu
    Copy the full SHA
    f0d9b9f View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    8afb669 View commit details
    Browse the repository at this point in the history
  3. Avoid installing a global uncaughtException handler on import (daquin…

    …oaldo#112)
    
    # Pull Request Details
    
    ## Related Issue
    Addresses daquinoaldo#77.
    
    Importing `https-localhost` currently installs a process-wide
    `uncaughtException` handler even when the package is only used as a
    module. That changes application-level error handling and can hide the
    original stack-trace behavior.
    
    This change scopes the existing handler to the CLI path (`require.main
    === module`) so the CLI keeps its friendly `EACCES` / `EADDRINUSE`
    messages while library consumers no longer get a global process listener
    as a side effect of `require("https-localhost")`.
    
    A regression test re-imports the module after clearing the require cache
    and verifies that the `uncaughtException` listener count does not
    change.
    
    ## Types of changes
    - [ ] Docs change / refactoring / dependency upgrade
    - [x] Bug fix (non-breaking change which fixes an issue)
    - [ ] New feature (non-breaking change which adds functionality)
    - [ ] Breaking change (fix or feature that would cause existing
    functionality to change)
    
    ## Checklist
    - [x] My code follows the code style of this project.
    - [x] I have updated the documentation or my changes dont require it.
    - [x] I have read the CONTRIBUTING document.
    - [x] I have added tests to cover my changes.
    - [ ] All new and existing tests passed.
    PNHD authored Sep 6, 2026
    Configuration menu
    Copy the full SHA
    3bee595 View commit details
    Browse the repository at this point in the history
  4. 4.7.2

    github-actions[bot] committed Sep 6, 2026
    Configuration menu
    Copy the full SHA
    0ef1cb9 View commit details
    Browse the repository at this point in the history
  5. ci: use npm trusted publishing (daquinoaldo#117)

    Configure the release workflow for npm Trusted Publishing via GitHub
    OIDC. Supports publishing the already-tagged v4.7.2 without creating
    another version bump.
    daquinoaldo authored Sep 6, 2026
    Configuration menu
    Copy the full SHA
    314eee3 View commit details
    Browse the repository at this point in the history
  6. ci: use Node 24 and add 'existing' option to release workflow (daquin…

    …oaldo#118)
    
    Bump release runner to Node 24 for npm Trusted Publishing OIDC support,
    and consolidate the release action into a single `upgrade` input with
    options: `patch`, `minor`, `major`, and `existing` (publish without
    re-bumping).
    daquinoaldo authored Sep 6, 2026
    Configuration menu
    Copy the full SHA
    dd59376 View commit details
    Browse the repository at this point in the history

Commits on Sep 14, 2026

  1. feat!: modernize to TypeScript, plain Node http, and pnpm (Node 24+) (d…

    …aquinoaldo#119)
    
    ## Breaking changes
    
    - **Node.js 24 or newer is required** (tested on Node 24 and 26; release
    runs on 26)
    - **License changed from AGPL-3.0 to MIT**
    - **`express` app replaced with a minimal router**: the module no longer
    returns an express app. `createServer()` now takes named options
    (`domain`, `certPath`, `reinstall`) and exposes `get`, `listen`,
    `redirect`, `serve`
    - **Dual ESM/CJS build**: published package ships `dist/` (ESM + CJS +
    types) instead of raw source
    - **Production mode removed**: HTTP/2 (`spdy`), compression, minify, and
    the packaged-binary update checker are gone — this is a development tool
    - **pnpm** replaces npm for development and CI
    
    ## What changed
    
    - **Migrated the whole project to TypeScript** (`strict`, type-aware
    linting)
    - **Replaced `express` and `cors` with plain `node:http` handlers**:
    static serving (ETag, Last-Modified, range requests, 404 fallback,
    directory redirect, MIME types via `mrmime`), request routing, and CORS
    headers now live in small dedicated modules; dependencies reduced to
    `mrmime` and `zod`
    - **Validated CLI configuration**: flags via `parseArgs` (`-p`, `-H`,
    `--cert-path`, `--reinstall`) layered over environment variables, parsed
    with `zod`
    - **Security hardening** (resolves all open CodeQL alerts):
    - `execFile` instead of shell string concatenation for mkcert
    invocations
    - path traversal protection and sanitized directory redirects in the
    static handler
      - rejection of protocol-relative and absolute-form request targets
    - tests trust the mkcert root CA instead of disabling certificate
    validation
    - **mkcert upgraded to v1.4.4**; download is skipped when the binary
    already exists, and the download stream is closed cleanly
    - **Toolchain**: `oxlint` + `oxfmt` + `knip` replace ESLint; native
    `node:test` runner with tests split by source module; internalized
    `appdata-path`
    - **CI**: test matrix on Node 24/26 across Ubuntu/macOS, explicit
    workflow permissions, SHA-pinned actions, concurrency cancellation, lint
    step in CI; Coveralls and stale-bot message config updated
    - **New `CONTRIBUTING.md`** with the local gate commands
    
    ## Verification
    
    - All CI checks green (CodeQL, tests on 24/26 × Ubuntu/macOS)
    - Locally: `pnpm run lint` and `pnpm test` (33/33) pass on Node 24
    daquinoaldo authored Sep 14, 2026
    Configuration menu
    Copy the full SHA
    c580766 View commit details
    Browse the repository at this point in the history
  2. fix: repair release workflow

    🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
    daquinoaldo committed Sep 14, 2026
    Configuration menu
    Copy the full SHA
    7ed932f View commit details
    Browse the repository at this point in the history
  3. docs: improve README

    daquinoaldo committed Sep 14, 2026
    Configuration menu
    Copy the full SHA
    607efc4 View commit details
    Browse the repository at this point in the history
  4. feat: add proxy mode for forwarding requests to an upstream server

    - add src/proxy.ts with hop-by-hop header filtering and x-forwarded-* headers
    - add --proxy CLI flag and PROXY_TARGET env var (mutually exclusive with path)
    - make serve/redirect/proxy/listen async, resolving once listening
    - remove app.get() custom-route API
    - add proxy, env validation, and CLI exclusivity tests
    
    🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
    daquinoaldo committed Sep 14, 2026
    Configuration menu
    Copy the full SHA
    9718252 View commit details
    Browse the repository at this point in the history

Commits on Sep 15, 2026

  1. fix: crash and RFC compliance edge cases (daquinoaldo#121)

    ## Summary
    
    Fixes all ten crash, hang, RFC-compliance, proxy, and response-quality
    bugs found in the review. Each fix is a separate commit; the edge-case
    test suite lands first.
    
    - **Malformed percent-encoding crashed the server**: `/%zz` threw
    `URIError`; now rejected safely. (`904a911`)
    - **Directory without `index.html` crashed the server**: now serves 404.
    (`f6209f7`)
    - **`If-Modified-Since` alone never produced 304**: now honored per RFC
    9110. (`f407c96`)
    - **Upstream dying mid-response hung clients**: client socket now
    closes. (`9db8e12`)
    - **Proxy CORS preflight hit the upstream**: OPTIONS now returns 204
    directly. (`98305ef`)
    - **Packaged update check could raise an uncaught callback error**:
    callback failures are contained. (`b3f8b15`)
    - **Multi-range requests incorrectly returned 416**: first range is
    served. (`1f0ab67`)
    - **WebSocket upgrades were unsupported**: HTTP and HTTPS upstream
    upgrade tunneling added. (`28183b9`)
    - **Existing `X-Forwarded-For` was overwritten**: client address is
    appended. (`330e42d`)
    - **Static 400/403/405/416 responses had empty bodies**: descriptive
    text bodies added. (`e998c05`)
    
    ## Verification
    
    - Edge-case suite and full tests pass where ports are available.
    - `pnpm lint` passes.
    - The two redirect tests are blocked locally by an unrelated `node
    server.js` process occupying port 8080.
    
    🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
    daquinoaldo authored Sep 15, 2026
    Configuration menu
    Copy the full SHA
    8dea99e View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    f4a0825 View commit details
    Browse the repository at this point in the history

Commits on Sep 16, 2026

  1. ci: enforce lint and formatting instead of silently fixing them (daqu…

    …inoaldo#123)
    
    ## Summary
    
    `pnpm lint` ran `oxfmt` in write mode and `oxlint --fix`, so CI silently
    rewrote an unformatted tree and passed — format and lint drift was never
    caught.
    
    - `lint` is now non-mutating: `oxfmt --check && oxlint && knip && tsc
    --noEmit`
    - New `fix` script that runs everything `lint` does, plus the
    auto-format (`oxfmt`) and auto-fix (`oxlint --fix`) passes: `oxfmt &&
    oxlint --fix && knip && tsc --noEmit`
    - CONTRIBUTING documents both
    
    Verified: `pnpm lint` and `pnpm fix` both pass on a clean tree.
    
    🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
    daquinoaldo authored Sep 16, 2026
    Configuration menu
    Copy the full SHA
    04bac62 View commit details
    Browse the repository at this point in the history
  2. feat!: remove standalone binaries and the pkg update check (daquinoal…

    …do#124)
    
    ## Summary
    
    Removes the standalone-binary feature entirely.
    
    The binaries bundled the app with vercel/pkg (archived upstream) on an
    EOL Node 16 runtime, and the update check they carried (`checkUpdates`)
    never worked even inside the binary. The package already requires Node ≥
    24, so anyone without Node cannot use it anyway.
    
    - Remove the `pkg` config from package.json
    - Remove the binary build/upload step from the release workflow (publish
    to npm only)
    - Remove the "Standalone binaries" section from the README
    - Remove the dead `checkUpdates` code from src/certs.ts
    
    **Breaking:** the GitHub release assets
    (`https-localhost-linux/macos/win.exe`) will no longer be produced.
    Users without Node must install Node (≥ 24) and `npm i -g
    https-localhost`.
    
    Verified: `pnpm lint` green, `pnpm test` green (except the 2
    pre-existing environmental port-8080 failures on my machine).
    
    🤖 Generated with [OpenCode](https://opencode.ai) (Smart-router)
    daquinoaldo authored Sep 16, 2026
    Configuration menu
    Copy the full SHA
    b0544be View commit details
    Browse the repository at this point in the history
  3. ci: configure monthly Dependabot updates (daquinoaldo#125)

    ## Summary
    
    Configure Dependabot to open monthly grouped update PRs for:
    
    - npm dependencies (`package.json` / `pnpm-lock.yaml`)
    - GitHub Actions
    
    Both group all updates into one PR and limit open Dependabot PRs to one
    per ecosystem.
    
    Note: all Actions in this repo are already pinned to commit SHAs;
    Dependabot updates the SHA (and the version comment) for each pinned
    action.
    
    🤖 Generated with [OpenCode](https://opencode.ai)
    daquinoaldo authored Sep 16, 2026
    Configuration menu
    Copy the full SHA
    177899e View commit details
    Browse the repository at this point in the history
Loading