mirror of
https://github.com/tiennm99/store-scraper-bot.git
synced 2026-10-11 03:13:50 +00:00
- pin form-data/qs/tough-cookie via package.json overrides; clears 3 of 4 Dependabot alerts (request SSRF risk-accepted, no upstream fix) - add GitHub Actions CI (lint + syntax check) on push/PR - add /settings and /setdayswarning to setMyCommands - new npm run describe sets bot profile description via Bot API - README: drop stale preview warning, add Operations section
1.6 KiB
1.6 KiB
title, description, status, priority, created
| title | description | status | priority | created |
|---|---|---|---|---|
| backlog cleanup: dependabot, CI, bot description | Knock out the small/concrete items in plans/todo.md. Tests + observability remain out of scope. | completed | P2 | 2026-05-10T00:00:00.000Z |
backlog cleanup: dependabot, CI, bot description
Overview
Four small, independent items from plans/todo.md bundled into one plan because each is too small to justify its own. Phases are independent — can be merged separately or together.
Goals & Non-Goals
Goals
- Resolve all 4 open Dependabot alerts (1 critical + 3 medium) where a fix exists
- Add minimal GitHub Actions CI (lint + syntax) on PR and push
- Set Telegram bot description / short-description via Bot API
- Document quarterly Upstash credential rotation
Non-Goals (separate future plans)
- Tests — needs framework choice (vitest vs node:test), conventions, fixtures. Treat as its own multi-phase plan.
- Observability dashboard — Vercel + Upstash already provide built-in dashboards. Custom-built dashboard is YAGNI until a real ops question arises that the built-ins can't answer.
Phases
| Phase | Name | Status |
|---|---|---|
| 1 | Dependabot overrides + audit | Completed |
| 2 | CI workflow on PR/push | Completed |
| 3 | Bot description script | Completed |
| 4 | Docs + ops reminders | Completed |
Dependencies
Phases are independent. No cross-plan dependencies.