• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

safe-global / safe-client-gateway / 35859601423
89%

Build:
DEFAULT BRANCH: main
Ran 23 Sep 2026 12:20PM UTC
Jobs 2
Files 1015
Run time 3min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

23 Sep 2026 12:17PM UTC coverage: 89.226% (+0.01%) from 89.216%
35859601423

push

github

web-flow
feat: update Nest to 12 (#3443)

* refactor: import Inject from the @nestjs/common root

Nest 12 ships an exports map with no directory-index fallback, so
`@nestjs/common/decorators` resolves to a non-existent `decorators.js`.
The root re-export is the identical function reference.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* ci: group every Nest package into one dependabot PR

The group covered four packages and named `@nestjs/platform-express`,
which the repo dropped when it migrated to Fastify. The other nine
`@nestjs/*` packages were bumped individually, which cannot go green
across a major.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* feat: update Nest to 12

Nest 12 is ESM with a strict exports map, so directory deep imports no
longer resolve: `Inject` and `ConfigFactory` now come from the package
roots. @nestjs/swagger 12 requires the Nest 12 line, which is why the
whole line moves together.

platform-fastify 12 pins fastify 5.12.1, which disables the numeric
`trustProxy` hop count (CVE-2026-16732). A hop count cannot validate the
immediate peer, so `parseTrustProxy` now rejects it instead of letting
`request.ip` fall back to the socket address and key every client onto
the same rate-limit bucket.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* refactor: rename EXPRESS_* config to HTTP_SERVER_*

Express is gone and the value no longer accepts Express hop-count
semantics, so `express.*` was doubly misleading. `httpServer.*` pairs
with the existing `httpClient.*` for outbound requests.

`jsonLimit` becomes `bodyLimit`: it sets Fastify's `bodyLimit` and
applies to the urlencoded parser too, so it was never JSON-only.

Nothing sets either variable in Argo, so no deploy change is needed.
Configuration throws on the old names rather than ignoring them, since
a silent fallback would drop `request.ip` to the socket address.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* refactor: drop the renamed env var g... (continued)

4364 of 5135 branches covered (84.99%)

Branch coverage included in aggregate %.

6 of 6 new or added lines in 1 file covered. (100.0%)

11122 of 12221 relevant lines covered (91.01%)

514.24 hits per line

Jobs
ID Job ID Ran Files Coverage
1 run-integration-tests - 35859601423.1 23 Sep 2026 12:24PM UTC 1015
64.02
GitHub Action Run
2 run-unit-tests - 35859601423.2 23 Sep 2026 12:20PM UTC 1015
66.12
GitHub Action Run
Source Files on build 35859601423
  • Tree
  • List 1015
  • Changed 14
  • Source Changed 8
  • Coverage Changed 11
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #35859601423
  • 653b609d on github
  • Prev Build on main (#35747228439)
  • Next Build on main (#35863524366)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc