Repository navigation
fix(update): avoid GitHub release rate limits - #1069
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
Contributor
Greptile SummaryThis PR makes the first-party release endpoint the default for curl-managed release discovery and replaces request-driven GitHub lookups with authenticated cron refreshes stored in Workers KV.
Confidence Score: 5/5The PR appears safe to merge, with no concrete correctness, security, or repository-rule violations identified. The Worker validates and freshness-bounds stored metadata, preserves last-known-good state on refresh failures, requires the deployment secret, and leaves clients with bounded direct-GitHub fallback and functioning opt-outs. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart LR
Cron[Cloudflare cron every minute] --> Worker[Release proxy scheduled handler]
Worker -->|Bearer GITHUB_TOKEN| GitHub[GitHub latest-release API]
Worker -->|validated version and checkedAt| KV[Workers KV]
Client[Installer or curl-managed Hunk] --> Endpoint[GET /v1/curl/latest]
Endpoint -->|fresh metadata| KV
Endpoint -->|normalized version| Client
Endpoint -->|missing or older than six hours| Failure[503 metadata_unavailable]
Failure --> Fallback[Direct GitHub fallback]
OptOut[HUNK_DISABLE_ANALYTICS or DO_NOT_TRACK] --> Fallback
Reviews (1): Last reviewed commit: "fix(update): avoid GitHub release rate l..." | Re-trigger Greptile |
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
hunk update --check, andhunk updaterelease discovery through the endpoint by default while preservingHUNK_DISABLE_ANALYTICSandDO_NOT_TRACKWhy
Anonymous requests to GitHub's latest-release API can exhaust its shared-IP rate limit. User-driven release checks should not scale GitHub API traffic linearly or fail merely because another process consumed that quota.
Release archives still download directly from GitHub. The Worker only publishes normalized latest-version metadata.
Validation
cd workers/release-proxy && npm test— 11 passedcd workers/release-proxy && npm run typecheckcd workers/release-proxy && npx wrangler deploy --dry-runbun run test— 2,049 passed, 2 skippedbun run typecheckbun run lintbun run check:docsHUNK_DISABLE_UPDATE_NOTICE=1 bun run packages/hunk/src/main.tsx update --method curl --checkhttps://updates.hunk.dev/v1/curl/latest; authenticated cron logs showed successfulupdatedandunchangedrefreshesTested on Linux. No terminal UI behavior changed, so visual evidence is not applicable.
Operational notes
workers/release-proxy/wrangler.jsoncGITHUB_TOKENis a required Worker-scoped secret and is not stored in the repositoryThis PR description was generated by Pi using gpt-5.6-sol