Replace pnpm-lock.yaml with package-lock.json. Both overrides move to
package.json#overrides, including the request -> @cypress/request alias.
allowBuilds for es5-ext becomes package.json#allowScripts.
The deploy script chained "pnpm register", which would have failed once pnpm
was gone; it now calls npm run register.
- alias legacy request transitive to maintained @cypress/request fork
- pin undici to 7.28.0 for GHSA batch affecting < 7.28.0
- drop form-data/qs/tough-cookie overrides now satisfied upstream
- bump @vercel/functions to 3.7.5 and google-play-scraper to 10.1.3
- bump actions/checkout and actions/setup-node to v7
src/bot/commands/index.js owns the canonical catalog (name, description,
adminOnly, build factory). bot.js builds dispatch from it; future menu
registration reads it. Drops the 14 explicit factory imports + the inline
/info handler from bot.js. Prevents the dispatch-vs-menu drift that bit
us with /setdayswarning (commit 0131206 → 49726f1 backfill).
- remove MONGODB_URI from .env.example (Atlas migration done; deleted from
Vercel cloud env too)
- trim .env.deploy.example to vars actually consumed by deploy scripts
(Upstash creds were only needed by the now-deleted migration script)
- README config table: drop ENV / SOURCE_COMMIT / SCHEDULE_CHECK_APP_TIME
(never read by code; Java-era leftovers)
- check-secret-leaks: drop MONGODB_URI; add UPSTASH/KV/CRON tokens; widen
scan roots to include api/
- add scripts/list-upstash-keys.js read-only ops helper
- pin form-data/qs/tough-cookie via package.json overrides; clears 3 of 4
Dependabot alerts (request SSRF risk-accepted, no upstream fix)
- add GitHub Actions CI (lint + syntax check) on push/PR
- add /settings and /setdayswarning to setMyCommands
- new npm run describe sets bot profile description via Bot API
- README: drop stale preview warning, add Operations section
Java repo renamed legacy-store-scraper-bot → java-store-scraper-bot for symmetry with go-store-scraper-bot. Status (deprecated/maintained) belongs in README banners, not URLs.
GitHub repo rename: js-store-scraper-bot becomes the canonical store-scraper-bot. The Java reference impl is renamed to legacy-store-scraper-bot in parallel.
Updates: package.json name + description, README header + reference link, wrangler.toml worker name (file slated for removal in cleanup phase but kept consistent in the interim).
Operator runs `npm run migrate` (reads admin + group docs from Atlas)
followed by `npm run migrate:bulk` (uploads via wrangler kv bulk put).
Cache collections are skipped by default since they auto-rebuild from
upstream APIs; --include-cache flag migrates them with TTL preserved.
- mongodb is added as a devDependency only — never enters the Worker
bundle, the Worker still talks to KV exclusively.
- scripts/.atlas-export.json is gitignored (contains exported state).
- README documents the one-time runbook.