Skip to content

Run the tronbrowser.dev container's API on Bun - #132

Merged
ralyodio merged 3 commits into
mainfrom
bun-runtime
Oct 1, 2026
Merged

ralyodio merged 3 commits into
mainfrom
bun-runtime

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Fleet Node -> Bun migration, batch 3. This PR changes only the dev2 container's runtime. Desktop, mobile, extension and release builds are untouched, and the repo stays a pnpm workspace on Node 24.

Changes

  • Dockerfile: the final stage moves from node:24-bookworm-slim to debian:bookworm-slim plus the bun binary from oven/bun:1.4.0-slim. The pnpm build stage, the engines stage (ungoogled-chromium + Obscura), Caddy and tor are unchanged.
  • start.sh: the migration runner and the API run with bun instead of node. Caddy is still PID 1, so stop behaviour is the same.
  • .dockerignore: excludes .git and node_modules.
  • ci.yml: a new api-bun job. It runs the API's portable tests (12 files; those using vitest-only vi.stub* are skipped) under bun test, then migrates a Postgres service and boots bun services/api/dist/index.js. vitest stays the gate.

Verified locally from the commit (git archive, built image, throwaway Postgres, dummy env)

  • docker top shows bun /api/dist/index.js. Migrations apply and skip under Bun.
  • Every static page, /api/healthz, /api/1/push, /mcp/tron, /api/auth/me, the 404 page and the www redirect are byte-identical to live.
  • MCP relay: fetch_page (Obscura) and screenshot_page (spawned Chromium) both work.
  • Web Push: subscribe, then WebSocket /api/1/push/connect hello, a VAPID push delivered live over the socket, and ping/pong after 65 s idle.
  • Auth: signup, login, wrong password, bearer /me, settings round-trip. A scrypt hash made on Node verifies under Bun.
  • docker stop takes 0.4 s, and the logs are clean.
  • Image size goes from 2.0 to 1.9 GB.

No tag: a v* tag ships the desktop release and the package managers.

🤖 Generated with Claude Code

ralyodio and others added 2 commits October 1, 2026 13:06
The dev2 image's final stage moves from node:24-bookworm-slim to
debian:bookworm-slim plus the bun binary from oven/bun:1.4.0-slim, and
start.sh runs the API and the boot-time migration runner with bun. The
repo stays a pnpm workspace on Node 24 (desktop, mobile, extension and
release builds depend on it), so pnpm still builds and deploys the API in
the build stage; only the container runtime changes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Comment thread .github/workflows/ci.yml Fixed
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

ThreatCrush Security Scan

52 finding(s)

HIGH/CRITICAL: 3 | MEDIUM: 28 | LOW: 21

Severity Rule Location
HIGH py-ssrf-outbound-request apps/desktop/launcher/tron-tor-helper:303
HIGH py-ssrf-outbound-request apps/desktop/launcher/tron-tor-helper:437
HIGH sh-remote-script-execution apps/web/public/install.sh:879
MEDIUM js-open-redirect apps/desktop/extensions/ai-sidebar/install-helper.js:156
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/media.js:34
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/media.js:57
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/newtab.js:237
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/newtab.js:266
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/newtab.js:336
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/options.js:306
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/sidepanel.js:78
MEDIUM js-unescaped-html-sink apps/desktop/extensions/ai-sidebar/sidepanel.js:166
MEDIUM js-unescaped-html-sink apps/extensions/public/store.js:77
MEDIUM js-unescaped-html-sink apps/extensions/public/store.js:227
MEDIUM js-unescaped-html-sink apps/extensions/public/store.js:569
MEDIUM js-unescaped-html-sink apps/web/public/app.js:29
MEDIUM js-unescaped-html-sink apps/web/public/dns.js:54
MEDIUM sh-remote-script-execution apps/web/public/install.sh:164
MEDIUM sh-remote-script-execution apps/web/public/install.sh:169
MEDIUM sh-remote-script-execution apps/web/public/install.sh:404
MEDIUM sh-remote-script-execution apps/web/public/install.sh:422
MEDIUM sh-remote-script-execution apps/web/public/install.sh:935
MEDIUM sh-remote-script-execution apps/web/public/install.sh:986
MEDIUM js-unescaped-html-sink apps/web/public/settings.js:96
MEDIUM js-unescaped-html-sink apps/web/public/settings.js:168
MEDIUM js-dynamic-code-execution packages/sdk/src/mcp/tools.ts:125
MEDIUM js-dynamic-code-execution packages/sdk/src/page.ts:68
MEDIUM js-dynamic-code-execution packages/sdk/src/page.ts:73
MEDIUM sql-template-interpolation services/api/src/store/db.ts:116
MEDIUM js-dynamic-code-execution services/api/src/store/scanner.ts:44
MEDIUM sh-predictable-temp-path start.sh:25
LOW js-dynamic-code-execution apps/desktop/extensions/ai-sidebar/pit-proxy.test.js:8
LOW js-dynamic-code-execution packages/agent-runtime/src/analyze/form-script.test.ts:6
LOW js-unescaped-html-sink packages/agent-runtime/src/analyze/form-script.test.ts:26
LOW js-unescaped-html-sink packages/agent-runtime/src/analyze/form-script.test.ts:49
LOW js-dynamic-code-execution packages/browser-core/src/automation/extract-script.test.ts:6
LOW js-unescaped-html-sink packages/browser-core/src/automation/extract-script.test.ts:16
LOW js-unescaped-html-sink packages/browser-core/src/automation/extract-script.test.ts:45
LOW js-unescaped-html-sink packages/browser-core/src/automation/extract-script.test.ts:57
LOW js-unescaped-html-sink packages/browser-core/src/automation/extract-script.test.ts:80
LOW js-unescaped-html-sink packages/browser-core/src/automation/extract-script.test.ts:99
LOW js-dynamic-code-execution packages/browser-core/src/automation/snapshot-script.test.ts:11
LOW js-unescaped-html-sink packages/browser-core/src/automation/snapshot-script.test.ts:62
LOW js-unescaped-html-sink packages/browser-core/src/automation/snapshot-script.test.ts:101
LOW js-unescaped-html-sink packages/provenance/src/scan.test.ts:47
LOW js-unescaped-html-sink packages/provenance/src/scan.test.ts:170
LOW js-unescaped-html-sink packages/provenance/src/scan.test.ts:216
LOW js-dynamic-code-execution packages/sdk/src/mcp/automate.test.ts:261
LOW secret-generic-api-key packages/storage/src/config.ts:51
LOW secret-generic-credential packages/storage/src/config.ts:51

…and 2 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@ralyodio
ralyodio merged commit 8c7cbd2 into main Oct 1, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants