Skip to content

Bump lyhu/tunnel to 0.3.3 - #158

Open
github-actions[bot] wants to merge 2 commits into
mainfrom
bump/lyhu/tunnel-0.3.3
Open

github-actions[bot] wants to merge 2 commits into
mainfrom
bump/lyhu/tunnel-0.3.3

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

lyhu/tunnel: {"kind":"npm","package":"paseo-plugin-tunnel","version":"0.3.2","resolved":"https://registry.npmjs.org/paseo-plugin-tunnel/-/paseo-plugin-tunnel-0.3.2.tgz","integrity":"sha512-y+L4gbLnYE8qCA3BQEr2sPlVk3+zcAqSRPs6skY6lHzF5gLMaFINLJSod+4zzTTyHp0sNcJodk0G7QsHDb8+Qw=="} -> {"kind":"npm","package":"paseo-plugin-tunnel","version":"0.3.3","resolved":"https://registry.npmjs.org/paseo-plugin-tunnel/-/paseo-plugin-tunnel-0.3.3.tgz","integrity":"sha512-xoCAoTnhMn2B6GXnWFIz+iKlI+4h+XBFwWK7tFErpGUi5od7PgLNEupcFYL8SI3unpN3c91d537z+R88OWKBjA=="}
No npm provenance for this version. Review the tarball diff below, not the repository.
Submitted by @lyhu.

Merging approves this version. The published index keeps pointing at the previous one until then.

Artifact diff
diff -ruN a/package/README.md b/package/README.md
--- a/package/README.md	1985-10-26 08:15:00.000000000 +0000
+++ b/package/README.md	1985-10-26 08:15:00.000000000 +0000
@@ -24,7 +24,7 @@
 
 ## Install
 
-On each Ingress and Egress host, use the bundled Paseo CLI and daemon **0.8.0 or newer**, matching the manifest's `requirements.paseo`. The host must support **Git plugin sources, manifest build commands, and the v0.8 runtime entries** (`index.server.ts` / `index.client.tsx`). Git, Node.js 22+, and npm must be available to the daemon process, with access to GitHub and the npm registry. If installation stops after the trust notice, see [network troubleshooting](docs/installation.md#troubleshooting).
+On each Ingress and Egress host, use the bundled Paseo CLI and daemon **0.10.3 or newer**, matching the manifest's `requirements.paseo`. The host must support **Git plugin sources, manifest build commands, and the v0.8 runtime entries** (`index.server.ts` / `index.client.tsx`). Git, Node.js 22+, and npm must be available to the daemon process, with access to GitHub and the npm registry. If installation stops after the trust notice, see [network troubleshooting](docs/installation.md#troubleshooting).
 
 Paseo 0.9 and newer install from npm:
 
@@ -34,7 +34,7 @@
 paseo plugin status http-tunnel --json

-Paseo 0.8 installs from GitHub:
+Paseo 0.10.3 installs from GitHub:

paseo plugin install lyhu/paseo-plugin-tunnel
@@ -58,7 +58,7 @@

Use your local Paseo UI to manage connected hosts, including remote hosts running only the daemon. Install and enable `http-tunnel` on each host first.

-The **Host picker is in the upper-right corner of the HTTP Tunnel page**. When multiple connected hosts have the plugin installed, open this picker to switch the host currently being managed. The Ingresses, Egresses, forms, status checks, and quick tests shown on the page all belong to the selected host. Switching the Host picker changes the RPC destination; it does not copy rules between hosts. If the picker contains only one host, verify that the other host is connected and has `http-tunnel` installed and running. After upgrading to Paseo 0.8, every managed host must run HTTP Tunnel **0.3.1 or later** — a host still on the pre-0.8 plugin is rejected by Paseo 0.8 and drops out of the picker. See [remote host setup](docs/installation.md#remote-hosts).
+The **Host picker is in the upper-right corner of the HTTP Tunnel page**. When multiple connected hosts have the plugin installed, open this picker to switch the host currently being managed. The Ingresses, Egresses, forms, status checks, and quick tests shown on the page all belong to the selected host. Switching the Host picker changes the RPC destination; it does not copy rules between hosts. If the picker contains only one host, verify that the other host is connected and has `http-tunnel` installed and running. After upgrading to Paseo 0.10.3, every managed host must run a matching HTTP Tunnel release **0.3.3 or later** — a host still on an older plugin is rejected by the host version requirement and drops out of the picker. See [remote host setup](docs/installation.md#remote-hosts).

1. **Step 1 (Select Service Host)**: Open **HTTP Tunnel** from Paseo's left sidebar. In the **upper-right Host picker**, select the machine that can reach the private service.
2. **Step 2 (Add Ingress)**: Select **Add ingress**. Enter a name and an origin reachable from the selected host, such as `http://127.0.0.1:3000` (where `127.0.0.1` refers to the selected host). An origin contains only a scheme, hostname, and optional port.
diff -ruN a/package/npm-shrinkwrap.json b/package/npm-shrinkwrap.json
--- a/package/npm-shrinkwrap.json	1985-10-26 08:15:00.000000000 +0000
+++ b/package/npm-shrinkwrap.json	1985-10-26 08:15:00.000000000 +0000
@@ -1,22 +1,22 @@
{
  "name": "paseo-plugin-tunnel",
-  "version": "0.3.2",
+  "version": "0.3.3",
  "lockfileVersion": 3,
  "requires": true,
  "packages": {
    "": {
      "name": "paseo-plugin-tunnel",
-      "version": "0.3.2",
+      "version": "0.3.3",
      "license": "AGPL-3.0-only",
      "dependencies": {
-        "@getpaseo/relay": "0.8.0",
+        "@getpaseo/relay": "0.10.3",
        "ws": "^8.18.0",
        "zod": "^4.4.3"
      },
      "devDependencies": {
        "@biomejs/biome": "^2.4.0",
-        "@getpaseo/client": "0.8.0",
-        "@getpaseo/plugin": "0.8.0",
+        "@getpaseo/client": "0.10.3",
+        "@getpaseo/plugin": "0.10.3",
        "@tanstack/react-query": "^5.90.11",
        "@types/node": "^22.0.0",
        "@types/react": "~19.2.0",
@@ -1258,28 +1258,28 @@
      }
    },
    "node_modules/@getpaseo/client": {
-      "version": "0.8.0",
-      "resolved": "https://registry.npmmirror.com/@getpaseo/client/-/client-0.8.0.tgz",
-      "integrity": "sha512-sX0PPR47a9MoK4cUpZXo4vrZLSfP39/l9jlxYslQTGTiXE/9g6EDr6XlRQZVlTkgZZ47xGRVJZ/wxhE37nLWkw==",
+      "version": "0.10.3",
+      "resolved": "https://registry.npmmirror.com/@getpaseo/client/-/client-0.10.3.tgz",
+      "integrity": "sha512-As65uU9zPFueDwrWo+gR8mEomY2rRh/I+ggPSi3rQAcDJONReXvQiZaovl+jUpY01VJvLmwo5vuE4r6YBu94YA==",
      "dev": true,
      "dependencies": {
-        "@getpaseo/protocol": "0.8.0",
-        "@getpaseo/relay": "0.8.0",
+        "@getpaseo/protocol": "0.10.3",
+        "@getpaseo/relay": "0.10.3",
        "zod": "^4.4.3"
      }
    },
    "node_modules/@getpaseo/plugin": {
-      "version": "0.8.0",
-      "resolved": "https://registry.npmmirror.com/@getpaseo/plugin/-/plugin-0.8.0.tgz",
-      "integrity": "sha512-VWdqMuYhv6oVrbNr+phDkSkMd4qfjb55UkFB0S4u4sHgo66UtJwvn8U9bwp1zU5wktW2LdXEa4OpcEGFDSkdVw==",
+      "version": "0.10.3",
+      "resolved": "https://registry.npmmirror.com/@getpaseo/plugin/-/plugin-0.10.3.tgz",
+      "integrity": "sha512-OUlrUlKwyzK4qvgt15mKjou1pY9ZYnBPjvuafLCY1KIGUK6efJ55cH8gpNUuvAmYlyFWzi9XliYLWqQNc+4akw==",
      "dev": true,
      "dependencies": {
        "@agentclientprotocol/sdk": "^1.4.0",
        "use-sync-external-store": "^1.6.0"
      },
      "peerDependencies": {
-        "@getpaseo/client": "0.8.0",
-        "@getpaseo/protocol": "0.8.0",
+        "@getpaseo/client": "0.10.3",
+        "@getpaseo/protocol": "0.10.3",
        "react": "~19.1.0",
        "react-native": ">=0.81.5",
        "zod": "^4.4.3"
@@ -1291,9 +1291,9 @@
      }
    },
    "node_modules/@getpaseo/protocol": {
-      "version": "0.8.0",
-      "resolved": "https://registry.npmmirror.com/@getpaseo/protocol/-/protocol-0.8.0.tgz",
-      "integrity": "sha512-SytigneLVG61useJ9yU400WFVWlqluwwUeWF/giRs0+ZOmgMSBZvYduqPAJdTRMAvJlrj62T/uVBH8gzMuHYLw==",
+      "version": "0.10.3",
+      "resolved": "https://registry.npmmirror.com/@getpaseo/protocol/-/protocol-0.10.3.tgz",
+      "integrity": "sha512-t9Ca9EbYgQMdKGNIFtHrYSJFQZdM/1YbSdCoevaklVGEhijN87PEgiQh+Po0rw6zEQ6uXs5l4GGLsnYEG7ecJQ==",
      "dev": true,
      "dependencies": {
        "semver": "^7.8.5",
@@ -1301,9 +1301,9 @@
      }
    },
    "node_modules/@getpaseo/relay": {
-      "version": "0.8.0",
-      "resolved": "https://registry.npmmirror.com/@getpaseo/relay/-/relay-0.8.0.tgz",
-      "integrity": "sha512-YBCMAI3WOx7HgEToryyB94Mnugb7o2opuxN6ZycVK+K2wk2T25aV0sG3enzlKVM1oyiFVoJxJrAZyGDWfWpxpQ==",
+      "version": "0.10.3",
+      "resolved": "https://registry.npmmirror.com/@getpaseo/relay/-/relay-0.10.3.tgz",
+      "integrity": "sha512-ACAcS6s4dDv26pfz+3V2dk7v6q7UAU2uapZMRn9smSem/tpcfQqvNWqEwn5b3Bz78zDvHnLvjcZxKbAtX8XrTg==",
      "dependencies": {
        "base64-js": "^1.5.1",
        "tweetnacl": "^1.0.3",
@@ -7125,474 +7125,6 @@
        }
      }
    },
-    "node_modules/vitest/node_modules/@esbuild/aix-ppc64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/aix-ppc64/-/aix-ppc64-0.28.2.tgz",
-      "integrity": "sha512-XExcO+dvLKvVtNTibSTBej1NCAbaGhWn9Ww1ZPx80qsahhPFe/8jgWP0IchNe0F3HwkU7n8ejhH8bjonqht8mQ==",
-      "cpu": [
-        "ppc64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "aix"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/android-arm": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/android-arm/-/android-arm-0.28.2.tgz",
-      "integrity": "sha512-kXXoiPVVGQcnIYGOeaovwOURpniDBpSq4A03qkQ+BMQqtGG6HYap3xne9C1O1yo4TR3qxlCX5IqqmX6fFo2Lqg==",
-      "cpu": [
-        "arm"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "android"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/android-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/android-arm64/-/android-arm64-0.28.2.tgz",
-      "integrity": "sha512-5YfKeeI8qWfBZIX+u2xZC3Zlb3Os/gLS2sbEKM+I4ZOcsWmHS2WLysCcQZDAFRslDUU5Oiq44gf6PYN1vGwG5A==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "android"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/android-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/android-x64/-/android-x64-0.28.2.tgz",
-      "integrity": "sha512-O387ite7SzUyCcy3JQX4P4bLtEA7bLLkx+esve5JHnyYfNTxcVpXZo9jhdB0lTKN44gztELTdU7nS8Nr16Fs1Q==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "android"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/darwin-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/darwin-arm64/-/darwin-arm64-0.28.2.tgz",
-      "integrity": "sha512-n4KqkOQrraxHJcgjM1RvwbigfQKIKJVpM7xp+KsxiyUSrRdIXnt73VhrPAx0fV44hgfmIVKjxMN9J1t5jySVkw==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "darwin"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/darwin-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/darwin-x64/-/darwin-x64-0.28.2.tgz",
-      "integrity": "sha512-uq6suIWYP37qzGddBKPw5QEQPi6HiLGsO7UmkpfyaYNQ3D+rN6w6WfwH+nuqcGXWvawGwxOEroO4YGnFh95azw==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "darwin"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/freebsd-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/freebsd-arm64/-/freebsd-arm64-0.28.2.tgz",
-      "integrity": "sha512-n+I0BTSRIoy+d6RPKnEVwql5UwBJolytvY4mAOIEJorKlqgPII8ix6slVVrfZ5Tnj7glIZvloylbB/EJPMWEXw==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "freebsd"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/freebsd-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/freebsd-x64/-/freebsd-x64-0.28.2.tgz",
-      "integrity": "sha512-78XJTJkvPs0kz2w61301PJjXl4g7q3JqiYMZ/M/yVI73EHBrCRTgkhu9oqG7vPqq+a/yadEW8aD+agKlk5xrmg==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "freebsd"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-arm": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-arm/-/linux-arm-0.28.2.tgz",
-      "integrity": "sha512-XlDnu2q5yoqems+xay6wSAcg9DDD7K9RLKZEBOMZm3ckNpJBvOX20tSfby8KfrrhINDyv9V2YVZKY/SpoGJI8w==",
-      "cpu": [
-        "arm"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-arm64/-/linux-arm64-0.28.2.tgz",
-      "integrity": "sha512-pW4AC0P3it8c7do9MVM4p51FzHzdM/TZrerurgRcHJ2WTa1VQ1CIq18xncfpBJw4ojkiZZrKW2yIBWBP92j6Ug==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-ia32": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-ia32/-/linux-ia32-0.28.2.tgz",
-      "integrity": "sha512-CYbnj78HsIeA+DhgUKgFCfvNsTHFhMMrinUrMZpDXJXKN8T3XViTZ/+wtHeVxEWY8ewSzTFN+nRmSwO2tZaLUQ==",
-      "cpu": [
-        "ia32"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-loong64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-loong64/-/linux-loong64-0.28.2.tgz",
-      "integrity": "sha512-buwkd8nsph4R+ajRvw0qM5Hja/TXQow3ptzWO2EbG/cqcIkHloRrdlBtQlshyYGTNFvfkfJ5tpPLVkY4DtsPfQ==",
-      "cpu": [
-        "loong64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-mips64el": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-mips64el/-/linux-mips64el-0.28.2.tgz",
-      "integrity": "sha512-ZVykbDyk7519VwiNb9Lcj9m8XM6v5V9uKPvrEMkkEedVewf+0itkhahp4HDpgERXhwLRpWFypsGbG/J8s0QjJA==",
-      "cpu": [
-        "mips64el"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-ppc64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-ppc64/-/linux-ppc64-0.28.2.tgz",
-      "integrity": "sha512-CAXl+Dtd9UUuJd8pKKdwh6MLm3MUMiqMPmhZ3tTSXPqfyQ3vDl6R5hZdZ/kYojK4ofXtdfSv1tFq8XzWx3heNQ==",
-      "cpu": [
-        "ppc64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-riscv64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-riscv64/-/linux-riscv64-0.28.2.tgz",
-      "integrity": "sha512-GeXCej4IQtU1B+QlDV8W/RRvbzI3O/Stss+/bCXv4lZls5WGRtu2a+3JkA3i4qIUlMXpcHebWpF8AkJhATowuA==",
-      "cpu": [
-        "riscv64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-s390x": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-s390x/-/linux-s390x-0.28.2.tgz",
-      "integrity": "sha512-3H1weTYZPxt/WOhByszQZybS9w5lKzUn1FDMsgEChbHWQwHYQQRfBxgCcZvPhjHfKyJjIievvMmEUawJrdY9Dg==",
-      "cpu": [
-        "s390x"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/linux-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/linux-x64/-/linux-x64-0.28.2.tgz",
-      "integrity": "sha512-4xTZr1FUmSoQW4XIWmit3tzQrUTZM+N3P0XV8xROKYF50XfI7xeO90+1bZvNwxIufQ9hDQVRJH5YhgPVF8A/HQ==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "linux"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/netbsd-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/netbsd-arm64/-/netbsd-arm64-0.28.2.tgz",
-      "integrity": "sha512-sSATRjPeDBg3pdgHoQfoYBob11Kk1FGa9lui5RIHZCoCkJa9QKlvl3/vKz2usCmYYjs7ymJR/2Nnsqe+Hjt5nw==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "netbsd"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/netbsd-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/netbsd-x64/-/netbsd-x64-0.28.2.tgz",
-      "integrity": "sha512-lqnzCV+mM0gIADaKihiCg6ifgfU2L3h5E33rNQBN1Y4MaVGnzryzmvvf7UHxprpQdE8hpqLolJ9Rl+SkIRDpyw==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "netbsd"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/openbsd-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/openbsd-arm64/-/openbsd-arm64-0.28.2.tgz",
-      "integrity": "sha512-AL2qJILH7lNjrDmCQDvdxMfAUIv8KMNZOvrwAQ8i8//ntL9FflhOyMJ8OZSMBb8/AWXe3/5v5S20y3zCoZWKoQ==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "openbsd"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/openbsd-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/openbsd-x64/-/openbsd-x64-0.28.2.tgz",
-      "integrity": "sha512-QtiuPytchRyC4rwUKhexJdQKvDuZ6hWloi3igqPQNUJCS1/v9EiO3UTOXR6A3FoMo4fnAKbWJdqaIwhOzh8qEw==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "openbsd"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/openharmony-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/openharmony-arm64/-/openharmony-arm64-0.28.2.tgz",
-      "integrity": "sha512-WkhYDmpTjLvGlScA1rwjRUmhl4k8oXR3cIbtqWmELgU/dFeHHlEllxDvdWcNJV9rbzCexB5vz8gtNewWLgCT7Q==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "openharmony"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/sunos-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/sunos-x64/-/sunos-x64-0.28.2.tgz",
-      "integrity": "sha512-GPMSkTOtMnv2U2F8gxe4Io6qmVs+YKyp832Etqqxr0hFngmXQ3rzwytelm3GIn7T4VviRUlf3sOgBOiTdvaf7g==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "sunos"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/win32-arm64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/win32-arm64/-/win32-arm64-0.28.2.tgz",
-      "integrity": "sha512-PIhhEkE9uPBleRBrQEJpUn7MBnibZzbGzYWPmY3x+YoVg/95zbjB4CxPPOQ8l5tYYM4mMaCthF8/1DIfBQQyWQ==",
-      "cpu": [
-        "arm64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "win32"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/win32-ia32": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/win32-ia32/-/win32-ia32-0.28.2.tgz",
-      "integrity": "sha512-YmJbfTlvU7Sdn9BB+4PRES4oB6pxgS37MAONj+hBr/cpXS1aBPKXxNnDbu+QCWPj0o9dgyxeq79g6c5P8KeuYA==",
-      "cpu": [
-        "ia32"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "win32"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
-    "node_modules/vitest/node_modules/@esbuild/win32-x64": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/@esbuild/win32-x64/-/win32-x64-0.28.2.tgz",
-      "integrity": "sha512-5ebpxr3nWMzrL/rnUI755Jkuee0bHL/Gq0WTF9lvcpv73wAp5eu8MfBUgWK9bhWvZjj7yX8etf/8tI8Ney695g==",
-      "cpu": [
-        "x64"
-      ],
-      "dev": true,
-      "license": "MIT",
-      "optional": true,
-      "os": [
-        "win32"
-      ],
-      "peer": true,
-      "engines": {
-        "node": ">=18"
-      }
-    },
    "node_modules/vitest/node_modules/@vitest/mocker": {
      "version": "4.1.11",
      "resolved": "https://registry.npmmirror.com/@vitest/mocker/-/mocker-4.1.11.tgz",
@@ -7620,50 +7152,6 @@
        }
      }
    },
-    "node_modules/vitest/node_modules/esbuild": {
-      "version": "0.28.2",
-      "resolved": "https://registry.npmmirror.com/esbuild/-/esbuild-0.28.2.tgz",
-      "integrity": "sha512-HKVLS8dvII+xoKW9kmqxbRKrnWEXfJJr/FZhhJmiqIB0e053QNYFqOBouTMO/k5sID4MvCiUCvv8b9M4h32wIA==",
-      "dev": true,
-      "hasInstallScript": true,
-      "license": "MIT",
-      "optional": true,
-      "peer": true,
-      "bin": {
-        "esbuild": "bin/esbuild"
-      },
-      "engines": {
-        "node": ">=18"
-      },
-      "optionalDependencies": {
-        "@esbuild/aix-ppc64": "0.28.2",
-        "@esbuild/android-arm": "0.28.2",
-        "@esbuild/android-arm64": "0.28.2",
-        "@esbuild/android-x64": "0.28.2",
-        "@esbuild/darwin-arm64": "0.28.2",
-        "@esbuild/darwin-x64": "0.28.2",
-        "@esbuild/freebsd-arm64": "0.28.2",
-        "@esbuild/freebsd-x64": "0.28.2",
-        "@esbuild/linux-arm": "0.28.2",
-        "@esbuild/linux-arm64": "0.28.2",
-        "@esbuild/linux-ia32": "0.28.2",
-        "@esbuild/linux-loong64": "0.28.2",
-        "@esbuild/linux-mips64el": "0.28.2",
-        "@esbuild/linux-ppc64": "0.28.2",
-        "@esbuild/linux-riscv64": "0.28.2",
-        "@esbuild/linux-s390x": "0.28.2",
-        "@esbuild/linux-x64": "0.28.2",
-        "@esbuild/netbsd-arm64": "0.28.2",
-        "@esbuild/netbsd-x64": "0.28.2",
-        "@esbuild/openbsd-arm64": "0.28.2",
-        "@esbuild/openbsd-x64": "0.28.2",
-        "@esbuild/openharmony-arm64": "0.28.2",
-        "@esbuild/sunos-x64": "0.28.2",
-        "@esbuild/win32-arm64": "0.28.2",
-        "@esbuild/win32-ia32": "0.28.2",
-        "@esbuild/win32-x64": "0.28.2"
-      }
-    },
    "node_modules/vitest/node_modules/picomatch": {
      "version": "4.0.7",
      "resolved": "https://registry.npmmirror.com/picomatch/-/picomatch-4.0.7.tgz",
diff -ruN a/package/package.json b/package/package.json
--- a/package/package.json	1985-10-26 08:15:00.000000000 +0000
+++ b/package/package.json	1985-10-26 08:15:00.000000000 +0000
@@ -1,6 +1,6 @@
{
  "name": "paseo-plugin-tunnel",
-  "version": "0.3.2",
+  "version": "0.3.3",
  "type": "module",
  "license": "AGPL-3.0-only",
  "description": "Controlled, end-to-end encrypted HTTP service connections for trusted Paseo hosts",
@@ -52,14 +52,14 @@
    "benchmark:sse": "node benchmark/anthropic-sse.mjs"
  },
  "dependencies": {
-    "@getpaseo/relay": "0.8.0",
+    "@getpaseo/relay": "0.10.3",
    "ws": "^8.18.0",
    "zod": "^4.4.3"
  },
  "devDependencies": {
    "@biomejs/biome": "^2.4.0",
-    "@getpaseo/client": "0.8.0",
-    "@getpaseo/plugin": "0.8.0",
+    "@getpaseo/client": "0.10.3",
+    "@getpaseo/plugin": "0.10.3",
    "@tanstack/react-query": "^5.90.11",
    "@types/node": "^22.0.0",
    "@types/react": "~19.2.0",
diff -ruN a/package/paseo-plugin.json b/package/paseo-plugin.json
--- a/package/paseo-plugin.json	1985-10-26 08:15:00.000000000 +0000
+++ b/package/paseo-plugin.json	1985-10-26 08:15:00.000000000 +0000
@@ -1,7 +1,7 @@
{
  "id": "http-tunnel",
  "requirements": {
-    "paseo": ">=0.8.0"
+    "paseo": ">=0.10.3"
  },
  "build": [
    ["npm", "ci", "--omit=dev", "--ignore-scripts", "--no-audit", "--no-fund"]
diff -ruN a/package/shared/version.ts b/package/shared/version.ts
--- a/package/shared/version.ts	1985-10-26 08:15:00.000000000 +0000
+++ b/package/shared/version.ts	1985-10-26 08:15:00.000000000 +0000
@@ -1,4 +1,4 @@
// Paseo 0.8 rejects a plugin whose bundle resolves any module at the plugin
// root, so the client cannot import `package.json`. The version is mirrored
// here and guarded against drift by `version.test.ts`.
-export const PLUGIN_VERSION = "0.3.2";
+export const PLUGIN_VERSION = "0.3.3";

This version has no OVERVIEW.md. The registry requires one to update a listing; the bump cannot merge until the repository adds it.

Inline validation failed. See the Bump workflow log.

@github-actions github-actions Bot added the bump Pinned artifact update label Oct 7, 2026

@paseo-bot paseo-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs from you: nothing, changes requested

@lyhu, paseo-plugin-tunnel 0.3.3 can't merge yet. The code change is fine; the next release needs these four changes, and the bump workflow opens a fresh pull request when it is published:

  1. Add OVERVIEW.md next to paseo-plugin.json. The registry requires one for every new version, and yours replaces the registry copy plugins/lyhu/tunnel.md. You can start from that copy without its last "imported from paseo.cafe" line, but change "Paseo 0.8.0 or newer" to 0.10.3, which is what 0.3.3 requires. The shape is in REVIEW.md: what it is and does, how it works if needed, setup, then what it reads or sends and where and known limits, with no installation steps.
  2. Regenerate npm-shrinkwrap.json so the manifest's build command works on npm 10 (the npm that ships with Node 22). On npm 10.9.3 it fails today:
    npm ci --omit=dev --ignore-scripts --no-audit --no-fund
    npm error code EUSAGE
    npm error Missing: esbuild@0.28.2 from lock file
    
    The 0.3.3 lockfile dropped the vitest/node_modules/esbuild and @esbuild/* 0.28.2 entries that npm 10 still expects. 0.3.2 installs on npm 10.
  3. Point every lockfile entry's resolved at https://registry.npmjs.org/. All 520 entries resolve on registry.npmmirror.com today. Their integrity values match the public registry, but the registry requires resolved on it.
  4. Add at least one screenshot as a media array in paseo-plugin.json, for example "media": ["images/ingress-list.png", "images/egress-list.png"] from your main branch, included in the package files. The plugin adds a sidebar item and a page, and REVIEW.md requires an image for any plugin with UI.

Nothing else needs to change.

Review data

  • Artifact: npm paseo-plugin-tunnel 0.3.3 (from 0.3.2), https://registry.npmjs.org/paseo-plugin-tunnel/-/paseo-plugin-tunnel-0.3.3.tgz. npm gitHead is f557f7996f82d279bd5e2f3623540cece45befe1, tag v0.3.3. No npm provenance.
  • Integrity: SHA-512 of both tarballs matches the record (old and new pin) and npm's dist.integrity for 0.3.3.
  • Validation: npm test passes (140/140). node scripts/validate.ts --online --changed fails with one error: lyhu/tunnel/OVERVIEW.md is required.
  • Extracted and inspected: both tarballs, extracted and diffed locally. Five files change: paseo-plugin.json:4 raises requirements.paseo from >=0.8.0 to >=0.10.3; package.json moves @getpaseo/relay, @getpaseo/client, and @getpaseo/plugin from 0.8.0 to 0.10.3; npm-shrinkwrap.json follows and drops 27 nested esbuild 0.28.2 entries; README.md updates version text; shared/version.ts:4 sets PLUGIN_VERSION to 0.3.3. No other source changes.
  • Install-time commands: paseo-plugin.json build is npm ci --omit=dev --ignore-scripts --no-audit --no-fund, which installs the shrinkwrap's production entries and runs no scripts. No manifest install. package.json has no preinstall, install, postinstall, or prepare. The command fails on npm 10.9.3 (above) and succeeds on npm 11.
  • Dependencies: runtime @getpaseo/relay 0.10.3 (relay end-to-end encryption), ws 8.21.3 (relay WebSocket), zod 4.5.4 (config and RPC validation), plus tweetnacl and base64-js through the relay. Only the relay version changes. Shrinkwrap: 520 entries, each with integrity, all resolved on registry.npmmirror.com. Entries with install scripts (esbuild, fsevents, workerd) are dev only and skipped by --omit=dev --ignore-scripts.
  • Hosts: relay.paseo.sh:443 by default or the relay from the config file (server/handlers.ts:14), the relay endpoint from an imported route offer (server/offer.ts:7-10), the user's ingress origin (server/ingress-runtime.ts:6-7), 127.0.0.1 for the self-test (server/probe.ts:61-64), and the egress listener (server/egress-runtime.ts:119,134). All serve the tunnel's purpose; none change in this bump.
  • Credentials and environment: PASEO_HOME, falling back to the Paseo home directory (server/storage.ts:28), and the machine hostname as the ingress label (server/subsystem.ts:263). Unchanged.
  • Filesystem: writes only tunnel/config.json under the Paseo home, directory mode 0700 and file 0600, written atomically (server/storage.ts:37-70). Unchanged.
  • Execution: no child_process, eval, new Function, or dynamic import().
  • Runtime installs: none.
  • Source match: all 49 tarball files are byte-identical to lyhu/paseo-plugin-tunnel at f557f79.
  • Listing media: none in the record or manifest. The plugin adds the "HTTP Tunnel" sidebar item and page (index.client.tsx:5-11).
  • Overview: missing in the 0.3.3 package and in the repository at f557f79. The registry copy states Paseo 0.8.0 as the minimum.
  • Decision: changes requested.
  • Reviewed commit: f159169c5a43b66d7727790c7402f3eb2645beaa

@paseo-bot paseo-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added your existing ingress/egress screenshots and corrected the registry overview to require Paseo 0.10.3. Publication remains blocked only on the installation lockfile. The earlier requests for an artifact overview, new screenshots and npm-only dependency URLs no longer apply.

Please regenerate npm-shrinkwrap.json with npm 10, publish a new package version containing it, and update this PR’s artifact pin. Confirm that npm ci --omit=dev --ignore-scripts --no-audit --no-fund succeeds with Node 22/npm 10 before publishing. The unchanged 0.3.3 lockfile lacks the nested esbuild version expected by npm 10, so the declared preparation command stops before the plugin loads. See the publishing guide’s build guidance.

Optional next release: ship your own OVERVIEW.md for the listing page, where installation is already shown; the registry page remains usable meanwhile. Overview format.

Review data
  • Reviewed PR head: eb97f886a0e425425c3b5b591f83c64b74a24eef; original artifact-bearing head: f159169c5a43b66d7727790c7402f3eb2645beaa. REVIEW.md blob: 7268134d240de9e474c52480f4937af4e369a6e2.
  • Downloaded npm paseo-plugin-tunnel 0.3.2 and 0.3.3 tarballs from their pinned registry.npmjs.org URLs. Both SHA-512 values match their records and npm version metadata. No provenance reported. Archive paths were checked before extraction; 49 regular files each.
  • Independently compared the artifacts: README, manifest version requirement, package version/SDK dependencies, shrinkwrap and shared version constant change. Runtime tunnel source is unchanged.
  • Preparation: manifest invokes npm ci --omit=dev --ignore-scripts --no-audit --no-fund; no package lifecycle scripts. Shrinkwrap has 520 locked registry.npmmirror.com entries with integrity. Five production packages: relay 0.10.3, ws 8.21.3, zod 4.5.4, tweetnacl 1.0.3, base64-js 1.5.1. Mirror origins alone are not a policy blocker.
  • Packaging evidence: the prior review recorded npm 10.9.3 failing with Missing: esbuild@0.28.2 from lock file. Fresh integrity verification identifies the same artifact; static inspection confirms Vite’s nested esbuild peer range ^0.27.0 || ^0.28.0, root esbuild 0.25.12 and no nested lock entry. Installation was not rerun because plugin/dependency execution is forbidden.
  • Access scope checked: configured relay and ingress origins, imported offer secrets, owner-only tunnel configuration selected through PASEO_HOME. Existing HTTP forwarding is purposeful and unchanged. Production dependency internals were not re-audited because installation remains blocked; this is not a completed security approval.
  • Registry edits: added two pinned HTTPS PNG screenshots, visually inspected and checked as image/png; updated the existing overview’s version requirement. Trusted current-main online validation passes.
  • No plugin, dependency, install or build code executed. Not approved or merged. No linked submission issue was found.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bump Pinned artifact update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants