Upstream Modernization Watch — 2026-08-23
All four tracked pins are already the newest available release (no version-bump opportunity; Renovate owns bumps regardless). Findings below are config/feature opportunities available at or below the currently pinned version.
router-for-me/CLIProxyAPI (pinned v7.2.140)
- Finding:
/v0/management/reset-quota endpoint (available pre-v7.2.60) clears quota/cooldown state per auth record — an operational recovery hook not currently exposed via packages/cli/src/commands/cliproxy/.
- Non-findings (checked, not applicable):
fingerprint-profile: claude-code-cli only applies to claude-api-key entries (we're OAuth-only — N/A). claude-cloak-mode toggle exists but changing it risks breaking OAuth acceptance (high-risk/subjective — not recommended). Persistent cooldown state (.cds file) is automatic via the existing cliproxy_auth volume — no config change needed.
- Classification: Report-only — wiring the reset-quota endpoint requires new CLI source code (a new
cliproxy subcommand), not a docker-compose/config-only change. Out of scope for an automated draft PR.
caddyserver/caddy (pinned v2.11.4-alpine)
- Finding:
apps/cliproxy/config/Caddyfile's reverse_proxy cli-proxy-api:8317 has no active health check. Caddy supports health_uri /healthz + health_interval (cli-proxy-api already serves /healthz), giving Caddy first-class upstream health awareness inspectable via the admin API's /reverse_proxy/upstreams endpoint.
- Classification: Mechanical/low-risk — touches only
apps/cliproxy/config/Caddyfile. Normally PR-able per policy, but this daily-autoheal run is operating in working-dir delivery mode (branch/PR creation forbidden for this invocation), and a production reverse-proxy routing change to the live cliproxy.fro.bot edge deserves an explicit reviewed PR rather than being silently folded into an unrelated working-tree diff. Documented here for a human-directed PR; not applied automatically.
fro-bot/agent (pinned v0.104.0, matches .github/workflows/fro-bot.yaml)
- Finding:
trusted-head-sha input enables "brokered push" delivery for trusted same-repo issue_comment mention runs (commits via Git Data API without exposing the push credential to the model). Our fro-bot job intentionally holds contents: read only; adopting this needs a permissions bump plus a step to capture/pass the SHA.
- Classification: Subjective/security-permission tradeoff — report-only, touches
.github/workflows/fro-bot.yaml.
bfra-me/.github (pinned v4.19.0, renovate-changesets@0.2.44)
- Finding:
renovate-changesets action exposes update-grouped-prs (default false) to generate changesets across all PRs in a Renovate group, not just the first. .github/renovate.json5 extends group:allNonMajor, so most updates land grouped — this input is directly relevant but unused. Minor cosmetic sort/emoji inputs also unused.
- Classification: Report-only — touches
.github/workflows/renovate-changesets.yaml (workflow file).
Summary
No fully mechanical adopt-now PR was opened this run (the one config-only candidate — the Caddy healthcheck — is deliberately left for a human-directed PR given the production-routing blast radius and this run's working-dir delivery constraints). All other findings require workflow or new-source-code changes and are report-only by policy.
Managed by daily autoheal. Do not edit this issue manually — it is overwritten in place on the next Sunday scan.
Upstream Modernization Watch — 2026-08-23
All four tracked pins are already the newest available release (no version-bump opportunity; Renovate owns bumps regardless). Findings below are config/feature opportunities available at or below the currently pinned version.
router-for-me/CLIProxyAPI(pinnedv7.2.140)/v0/management/reset-quotaendpoint (available pre-v7.2.60) clears quota/cooldown state per auth record — an operational recovery hook not currently exposed viapackages/cli/src/commands/cliproxy/.fingerprint-profile: claude-code-clionly applies toclaude-api-keyentries (we're OAuth-only — N/A).claude-cloak-modetoggle exists but changing it risks breaking OAuth acceptance (high-risk/subjective — not recommended). Persistent cooldown state (.cdsfile) is automatic via the existingcliproxy_authvolume — no config change needed.cliproxysubcommand), not a docker-compose/config-only change. Out of scope for an automated draft PR.caddyserver/caddy(pinnedv2.11.4-alpine)apps/cliproxy/config/Caddyfile'sreverse_proxy cli-proxy-api:8317has no active health check. Caddy supportshealth_uri /healthz+health_interval(cli-proxy-api already serves/healthz), giving Caddy first-class upstream health awareness inspectable via the admin API's/reverse_proxy/upstreamsendpoint.apps/cliproxy/config/Caddyfile. Normally PR-able per policy, but this daily-autoheal run is operating inworking-dirdelivery mode (branch/PR creation forbidden for this invocation), and a production reverse-proxy routing change to the livecliproxy.fro.botedge deserves an explicit reviewed PR rather than being silently folded into an unrelated working-tree diff. Documented here for a human-directed PR; not applied automatically.fro-bot/agent(pinnedv0.104.0, matches.github/workflows/fro-bot.yaml)trusted-head-shainput enables "brokered push" delivery for trusted same-repoissue_commentmention runs (commits via Git Data API without exposing the push credential to the model). Ourfro-botjob intentionally holdscontents: readonly; adopting this needs a permissions bump plus a step to capture/pass the SHA..github/workflows/fro-bot.yaml.bfra-me/.github(pinnedv4.19.0,renovate-changesets@0.2.44)renovate-changesetsaction exposesupdate-grouped-prs(defaultfalse) to generate changesets across all PRs in a Renovate group, not just the first..github/renovate.json5extendsgroup:allNonMajor, so most updates land grouped — this input is directly relevant but unused. Minor cosmeticsort/emojiinputs also unused..github/workflows/renovate-changesets.yaml(workflow file).Summary
No fully mechanical adopt-now PR was opened this run (the one config-only candidate — the Caddy healthcheck — is deliberately left for a human-directed PR given the production-routing blast radius and this run's working-dir delivery constraints). All other findings require workflow or new-source-code changes and are report-only by policy.
Managed by daily autoheal. Do not edit this issue manually — it is overwritten in place on the next Sunday scan.