Replace pnpm-lock.yaml with package-lock.json. allowBuilds and
pnpm.onlyBuiltDependencies collapse into package.json#allowScripts, which npm
11 gates the same way; sharp is omitted because it is not in the tree.
cloudflare-worker/.github/workflows/ci.yml is updated for consistency even
though it never runs: GitHub only reads workflows from the repository root.
The three deployment variants now live in one repository: GitHub Actions
at the root, the Go daemon under self-hosted/, the Worker under
cloudflare-worker/. Update comparison tables, clone instructions, and the
Go module path (binary builds as 'self-hosted'); GHCR image name is
unchanged.
sharp was pinned transitively via wrangler -> miniflare below the
0.35.0 security fix. Bumping wrangler resolves the advisory without
any source change.
Commenting out [triggers] left stale schedules visible in the CF
dashboard — Wrangler only pushes declared config, never removes
implicitly. An empty array is the explicit "clear schedules" signal.
Sample schedule preserved as a comment above the empty array so
re-enabling is a single-line edit.
Comment out [triggers].crons in wrangler.toml — migrated this routine to
cron-job.org (free, verified) to keep the CF cron-trigger free-tier quota
available for other workers. Worker code, secrets, and observability
config stay intact so re-enabling is one toml uncomment + redeploy.
README restructured: lead with cron-job.org setup (signup → headers → JSON
body), demote CF Worker setup to a secondary path under "Using Cloudflare
Workers" for users who specifically want CF infra.
Add top-of-README notice that the author now uses Claude Code's
built-in routine cron trigger instead of this GitHub Actions
workflow. Repo kept as reference for external-scheduler users.
Add warning about GitHub cron delays at minute 0 (observed ~1h46m
late in this repo), recommend scattered off-hour minutes.