Skip to content

Upstream Modernization Watch — 2026-08-23 #1162

Description

@fro-bot

Upstream Modernization Watch — 2026-08-23

All four tracked pins are already the newest available release (no version-bump opportunity; Renovate owns bumps regardless). Findings below are config/feature opportunities available at or below the currently pinned version.

router-for-me/CLIProxyAPI (pinned v7.2.140)

  • Finding: /v0/management/reset-quota endpoint (available pre-v7.2.60) clears quota/cooldown state per auth record — an operational recovery hook not currently exposed via packages/cli/src/commands/cliproxy/.
  • Non-findings (checked, not applicable): fingerprint-profile: claude-code-cli only applies to claude-api-key entries (we're OAuth-only — N/A). claude-cloak-mode toggle exists but changing it risks breaking OAuth acceptance (high-risk/subjective — not recommended). Persistent cooldown state (.cds file) is automatic via the existing cliproxy_auth volume — no config change needed.
  • Classification: Report-only — wiring the reset-quota endpoint requires new CLI source code (a new cliproxy subcommand), not a docker-compose/config-only change. Out of scope for an automated draft PR.

caddyserver/caddy (pinned v2.11.4-alpine)

  • Finding: apps/cliproxy/config/Caddyfile's reverse_proxy cli-proxy-api:8317 has no active health check. Caddy supports health_uri /healthz + health_interval (cli-proxy-api already serves /healthz), giving Caddy first-class upstream health awareness inspectable via the admin API's /reverse_proxy/upstreams endpoint.
  • Classification: Mechanical/low-risk — touches only apps/cliproxy/config/Caddyfile. Normally PR-able per policy, but this daily-autoheal run is operating in working-dir delivery mode (branch/PR creation forbidden for this invocation), and a production reverse-proxy routing change to the live cliproxy.fro.bot edge deserves an explicit reviewed PR rather than being silently folded into an unrelated working-tree diff. Documented here for a human-directed PR; not applied automatically.

fro-bot/agent (pinned v0.104.0, matches .github/workflows/fro-bot.yaml)

  • Finding: trusted-head-sha input enables "brokered push" delivery for trusted same-repo issue_comment mention runs (commits via Git Data API without exposing the push credential to the model). Our fro-bot job intentionally holds contents: read only; adopting this needs a permissions bump plus a step to capture/pass the SHA.
  • Classification: Subjective/security-permission tradeoff — report-only, touches .github/workflows/fro-bot.yaml.

bfra-me/.github (pinned v4.19.0, renovate-changesets@0.2.44)

  • Finding: renovate-changesets action exposes update-grouped-prs (default false) to generate changesets across all PRs in a Renovate group, not just the first. .github/renovate.json5 extends group:allNonMajor, so most updates land grouped — this input is directly relevant but unused. Minor cosmetic sort/emoji inputs also unused.
  • Classification: Report-only — touches .github/workflows/renovate-changesets.yaml (workflow file).

Summary

No fully mechanical adopt-now PR was opened this run (the one config-only candidate — the Caddy healthcheck — is deliberately left for a human-directed PR given the production-routing blast radius and this run's working-dir delivery constraints). All other findings require workflow or new-source-code changes and are report-only by policy.

Managed by daily autoheal. Do not edit this issue manually — it is overwritten in place on the next Sunday scan.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions