Skip to content

fix(update): avoid GitHub release rate limits - #1069

Merged
benvinegar merged 2 commits into
mainfrom
fix/default-release-proxy
Sep 9, 2026
Merged

benvinegar merged 2 commits into
mainfrom
fix/default-release-proxy

Conversation

@benvinegar

Copy link
Copy Markdown
Member

Summary

  • refresh the latest stable curl-install release once per minute from an authenticated Cloudflare Worker cron and store validated metadata in Workers KV
  • serve release checks from global KV with bounded staleness, last-known-good preservation, and direct GitHub fallback
  • route curl installer, startup, hunk update --check, and hunk update release discovery through the endpoint by default while preserving HUNK_DISABLE_ANALYTICS and DO_NOT_TRACK
  • document the deployment resources and add coverage for storage, timeout, malformed metadata, fallback, and opt-out behavior

Why

Anonymous requests to GitHub's latest-release API can exhaust its shared-IP rate limit. User-driven release checks should not scale GitHub API traffic linearly or fail merely because another process consumed that quota.

Release archives still download directly from GitHub. The Worker only publishes normalized latest-version metadata.

Validation

  • cd workers/release-proxy && npm test — 11 passed
  • cd workers/release-proxy && npm run typecheck
  • cd workers/release-proxy && npx wrangler deploy --dry-run
  • bun run test — 2,049 passed, 2 skipped
  • bun run typecheck
  • bun run lint
  • bun run check:docs
  • HUNK_DISABLE_UPDATE_NOTICE=1 bun run packages/hunk/src/main.tsx update --method curl --check
  • production Worker deployed and verified at https://updates.hunk.dev/v1/curl/latest; authenticated cron logs showed successful updated and unchanged refreshes

Tested on Linux. No terminal UI behavior changed, so visual evidence is not applicable.

Operational notes

  • the production KV namespace is bound in workers/release-proxy/wrangler.jsonc
  • GITHUB_TOKEN is a required Worker-scoped secret and is not stored in the repository
  • metadata older than six hours returns an endpoint error so clients use the existing direct-GitHub fallback

This PR description was generated by Pi using gpt-5.6-sol

@vercel

vercel Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
hunk-web Ignored Ignored Preview Sep 9, 2026 1:38am UTC

Request Review

@greptile-apps

greptile-apps Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR makes the first-party release endpoint the default for curl-managed release discovery and replaces request-driven GitHub lookups with authenticated cron refreshes stored in Workers KV.

  • Adds minute-by-minute Worker refreshes, hourly metadata heartbeats, six-hour freshness enforcement, last-known-good preservation, and bounded structured logging.
  • Retains direct-GitHub fallback in the installer and CLI and respects HUNK_DISABLE_ANALYTICS and DO_NOT_TRACK.
  • Expands Worker, installer, update, timeout, malformed-metadata, storage-failure, fallback, and opt-out coverage.
  • Documents the production KV namespace, required Worker secret, deployment process, and client behavior.

Confidence Score: 5/5

The PR appears safe to merge, with no concrete correctness, security, or repository-rule violations identified.

The Worker validates and freshness-bounds stored metadata, preserves last-known-good state on refresh failures, requires the deployment secret, and leaves clients with bounded direct-GitHub fallback and functioning opt-outs.

Important Files Changed

Filename Overview
workers/release-proxy/src/index.ts Moves release discovery to scheduled authenticated refreshes backed by validated, freshness-bounded KV metadata.
workers/release-proxy/wrangler.jsonc Configures the production KV binding, every-minute cron trigger, and required GitHub secret.
packages/hunk/src/core/install/latestRelease.ts Enables the first-party endpoint by default for curl installs while retaining opt-outs, validation, timeouts, and direct fallback.
install.sh Routes default release resolution through the bounded proxy attempt while preserving opt-out and GitHub fallback behavior.
workers/release-proxy/src/index.test.ts Adds broad coverage for KV serving, refresh lifecycle, malformed data, storage failures, timeouts, and bounded logs.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Cron[Cloudflare cron every minute] --> Worker[Release proxy scheduled handler]
  Worker -->|Bearer GITHUB_TOKEN| GitHub[GitHub latest-release API]
  Worker -->|validated version and checkedAt| KV[Workers KV]
  Client[Installer or curl-managed Hunk] --> Endpoint[GET /v1/curl/latest]
  Endpoint -->|fresh metadata| KV
  Endpoint -->|normalized version| Client
  Endpoint -->|missing or older than six hours| Failure[503 metadata_unavailable]
  Failure --> Fallback[Direct GitHub fallback]
  OptOut[HUNK_DISABLE_ANALYTICS or DO_NOT_TRACK] --> Fallback
Loading

Reviews (1): Last reviewed commit: "fix(update): avoid GitHub release rate l..." | Re-trigger Greptile

@benvinegar
benvinegar merged commit f5b8b24 into main Sep 9, 2026
24 of 25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant