From 6d061e33ba2ff1bbfe4bada5185466eb853fc976 Mon Sep 17 00:00:00 2001 From: Denis Pianelli Date: Mon, 1 Jun 2026 14:18:33 +0200 Subject: [PATCH] fix: require Node 22+ to match the runtime and dev toolchain The transport uses AbortSignal.any (Node 20.3+), so the advertised "Node 18+" was wrong. Node 20 is EOL and the dev toolchain (@commitlint/cli) requires Node 22.12+, so target Node 22+ consistently: engines >=22, CI on 22/24, README updated. Also rounds out the open-source contribution setup: a Conventional-Commits PR-title note in CONTRIBUTING (squash merges make the PR title the release input), issue/PR templates, CODE_OF_CONDUCT, and SECURITY. --- .github/ISSUE_TEMPLATE/bug_report.md | 30 +++++++++++++++++++++++ .github/ISSUE_TEMPLATE/feature_request.md | 20 +++++++++++++++ .github/PULL_REQUEST_TEMPLATE.md | 16 ++++++++++++ CODE_OF_CONDUCT.md | 18 ++++++++++++++ CONTRIBUTING.md | 4 +++ README.md | 4 +-- SECURITY.md | 24 ++++++++++++++++++ package.json | 2 +- 8 files changed, 115 insertions(+), 3 deletions(-) create mode 100644 .github/ISSUE_TEMPLATE/bug_report.md create mode 100644 .github/ISSUE_TEMPLATE/feature_request.md create mode 100644 .github/PULL_REQUEST_TEMPLATE.md create mode 100644 CODE_OF_CONDUCT.md create mode 100644 SECURITY.md diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md new file mode 100644 index 0000000..9338e8e --- /dev/null +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -0,0 +1,30 @@ +--- +name: Bug report +about: Something doesn't work as documented +title: "fix: " +labels: bug +--- + +## What happened + + + +## Reproduction + +```ts +// Minimal code that triggers it +``` + +## Expected vs actual + +- **Expected:** +- **Actual:** + +## Environment + +- `@dpianelli/chesscom` version: +- Runtime + version (Node / Deno / Bun / browser): + +## Extra context + + diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md new file mode 100644 index 0000000..72cd29e --- /dev/null +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -0,0 +1,20 @@ +--- +name: Feature request +about: Suggest a new endpoint, helper, or improvement +title: "feat: " +labels: enhancement +--- + +## What + + + +## Why + + + +## Proposed shape + +```ts +// How you'd expect to call it, if you have an idea +``` diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..e2287ed --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,16 @@ + + +## What + + + +## Checklist + +- [ ] PR title follows [Conventional Commits](https://www.conventionalcommits.org/) +- [ ] `npm run check` passes (lint, format, typecheck, tests) +- [ ] Tests added or updated for the change +- [ ] README / docs updated if the public API changed diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..8ce8984 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,18 @@ +# Code of Conduct + +This project adopts the [Contributor Covenant](https://www.contributor-covenant.org), +version 2.1. The full text is available at +. + +## In short + +We want a welcoming, harassment-free experience for everyone. Be respectful and +constructive; assume good faith. Unacceptable behavior includes harassment, +personal attacks, and other conduct that a reasonable person would find +inappropriate in a professional setting. + +## Reporting + +Report unacceptable behavior to the maintainer at **denis.pianelli@gmail.com**. +Reports are handled confidentially. Maintainers may remove, edit, or reject +contributions and comments that violate this Code of Conduct. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 3504d6a..01ee9f1 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -63,6 +63,10 @@ bumps the minor version, a `fix` the patch; mark breaking changes with `!` or a ## Pull requests - Branch from `main`, open a PR back to `main`. +- **The PR title must follow [Conventional Commits](https://www.conventionalcommits.org/).** + PRs are **squash-merged**, so the PR title becomes the commit message on `main` — + it is what `release-please` reads to build the changelog and choose the next + version. A non-conventional title is silently dropped from the release notes. - CI must pass (lint, format, typecheck, test, build on Node 22 and 24). - Match the surrounding code; see [`STYLE.md`](./STYLE.md) for conventions and [`SPEC.md`](./SPEC.md) for the architecture. diff --git a/README.md b/README.md index 11b0a2f..47fdac8 100644 --- a/README.md +++ b/README.md @@ -14,7 +14,7 @@ rate limiting, ETag caching, runtime response validation, and lazy pagination. - ✅ Serial rate limiting + backoff (respects the Chess.com "be serial" rule) - ✅ Transparent ETag caching (`304 Not Modified` aware) - ✅ Lazy async iteration over monthly game archives -- ✅ Isomorphic — native `fetch`, runs in Node 18+, Deno, Bun, the browser +- ✅ Isomorphic — native `fetch`, runs in Node 22+, Deno, Bun, the browser - ✅ One dependency (`zod`) > ✅ Stable since `1.0.0`. The public API follows [semver](https://semver.org) — @@ -247,7 +247,7 @@ const client = new ChessComClient({ ## Requirements -- The published library runs on **Node 18+**, Deno, Bun, and browsers (anything +- The published library runs on **Node 22+**, Deno, Bun, and browsers (anything with a global `fetch`). - Contributing to this repo requires **Node 22+** (the dev toolchain). diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..fa9f6dc --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,24 @@ +# Security Policy + +## Supported versions + +This project follows [semantic versioning](https://semver.org). Security fixes +land on the latest released line; please upgrade to the most recent version +before reporting. + +| Version | Supported | +| ------- | --------- | +| `1.x` | ✅ | +| `< 1.0` | ❌ | + +## Reporting a vulnerability + +**Please do not open a public issue for security problems.** + +Use GitHub's private vulnerability reporting: +[**Report a vulnerability**](https://github.com/denispianelli/chesscom/security/advisories/new), +or email **denis.pianelli@gmail.com**. + +Include a description, affected versions, and a minimal reproduction if possible. +You can expect an initial acknowledgement within a few days. Once a fix is ready, +a patched release is published and the advisory is disclosed. diff --git a/package.json b/package.json index 69c118c..b47a46c 100644 --- a/package.json +++ b/package.json @@ -42,7 +42,7 @@ ], "sideEffects": false, "engines": { - "node": ">=18" + "node": ">=22" }, "scripts": { "build": "tsup",