Skip to content

Commit 5d32fa2

Browse files
authored
chore(release): v1.39.0 dependency maintenance (#83)
* chore(release): prepare v1.39.0 and runtime compatibility matrix Document the five dependency groups, SDK migration and container runtime changes. Keep package, widget, chart, security policy and Python versions synchronized. Exercise minimum and container runtime lines before publication. * ci: validate Python requirement floors against the hash lock
1 parent 6fdac72 commit 5d32fa2

12 files changed

Lines changed: 73 additions & 19 deletions

File tree

‎.github/workflows/unit-tests.yml‎

Lines changed: 30 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,21 @@ on:
2222
pull_request:
2323

2424
jobs:
25+
node:
26+
name: Node (${{ matrix.node }})
27+
runs-on: ubuntu-latest
28+
strategy:
29+
fail-fast: false
30+
matrix:
31+
node: ['22', '24', '26']
32+
steps:
33+
- uses: actions/checkout@v7
34+
- uses: actions/setup-node@v7
35+
with:
36+
node-version: ${{ matrix.node }}
37+
- run: npm ci && npm audit --omit=dev && npm test
38+
working-directory: server-node
39+
2540
browser:
2641
name: Browser lifecycle and dependency audit
2742
runs-on: ubuntu-latest
@@ -40,16 +55,20 @@ jobs:
4055
working-directory: test/browser
4156

4257
go:
43-
name: Go
58+
name: Go (${{ matrix.go }})
4459
runs-on: ubuntu-latest
60+
strategy:
61+
fail-fast: false
62+
matrix:
63+
go: ['1.26.8', '1.27.1']
4564
steps:
4665
- uses: actions/checkout@v7
4766

4867
- uses: actions/setup-go@v7
4968
with:
5069
# crypto/tls only exposes ClientHelloInfo.Extensions from 1.24, which
5170
# native JA4 needs. go.mod says so; keep this in step with it.
52-
go-version: '1.26.8'
71+
go-version: ${{ matrix.go }}
5372
cache-dependency-path: server-go/go.sum
5473

5574
- name: Vet
@@ -67,20 +86,26 @@ jobs:
6786
govulncheck ./...
6887
6988
python:
70-
name: Python
89+
name: Python (${{ matrix.python }})
7190
runs-on: ubuntu-latest
91+
strategy:
92+
fail-fast: false
93+
matrix:
94+
python: ['3.12', '3.14']
7295
steps:
7396
- uses: actions/checkout@v7
7497

7598
- uses: actions/setup-python@v7
7699
with:
77-
python-version: '3.12'
100+
python-version: ${{ matrix.python }}
78101
cache: pip
79102
cache-dependency-path: server-python/requirements.lock
80103

81104
- name: Install dependencies
82105
working-directory: server-python
83-
run: pip install --require-hashes -r requirements.lock
106+
# Resolve both files together so a requirements-only update cannot
107+
# silently leave CI exercising an incompatible older lockfile.
108+
run: pip install --require-hashes -r requirements.lock -r requirements.txt
84109

85110
# Discovery, not a loop over files: a file that stops being discoverable
86111
# should show up as a drop in the count rather than as silence. It used to

‎CHANGELOG.md‎

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,32 @@ the project uses [Semantic Versioning](https://semver.org/) — with the caveat
1313
that pre-2.0 it has used minor bumps for behaviour changes that a stricter
1414
reading would call major. Read the **Breaking** entries rather than the number.
1515

16+
## [1.39.0] — 2026-09-14
17+
18+
### Dependencies and compatibility
19+
- Merge the five grouped maintenance updates: Go, Python, containers,
20+
JavaScript, and GitHub Actions (#78–#82).
21+
- The bundled Node server now uses Express 5.2 and Redis client 6.2. Express
22+
middleware consumers may continue using Express 4; the peer declaration now
23+
also accepts Express 5. Node 22 remains the minimum supported runtime.
24+
- Upgrade Node Web Bot Auth to 0.2 and Go Web Bot Auth to 0.4.1. Migrate the
25+
Node adapter to the new request-descriptor and verifier-object API. Resolve
26+
keys and report verified identity from the signed dictionary member, not an
27+
unrelated first member. Discovery failures remain unverified presence signals;
28+
only an actual cryptographic rejection counts as forgery.
29+
- Keep Go's stricter signed-agent identity requirement; update its cryptographic
30+
fixture and retain a regression check for missing agent identity.
31+
- Raise Python requirement floors to match the supported dependency baseline;
32+
the existing hash lock already satisfies them. Update Playwright to 1.63.
33+
- Update pinned container bases to Go 1.27.1, Alpine 3.24.1, Node 26, and Python
34+
3.14.7. Container runtime upgrades can affect custom images or extensions:
35+
validate those before deployment. Go source builds still support 1.26.8.
36+
- Update GitHub Actions and test the minimum and container runtime lines:
37+
Node 22/24/26, Go 1.26.8/1.27.1, and Python 3.12/3.14.
38+
39+
Token format, admission limits, and browser verification behavior are unchanged
40+
from 1.38.0. Older deployments should still read [HARDENING.md](HARDENING.md).
41+
1642
## [1.38.0] — 2026-09-14
1743

1844
Read [HARDENING.md](HARDENING.md) before upgrading. This release follows the

‎HARDENING.md‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,10 @@ uses `requirements.lock` with mandatory hashes. Refresh the Python lock with:
9191
uv pip compile --python-version 3.12 --generate-hashes server-python/requirements.txt -o server-python/requirements.lock
9292
```
9393

94-
Go builds use 1.26.8, and CI runs `govulncheck`. Dependency-update automation and
94+
Go source builds require at least 1.26.8; the Go containers build with 1.27.1.
95+
The Node and Python containers use Node 26 and Python 3.14. CI covers Node
96+
22/24/26, Go 1.26.8/1.27.1, and Python 3.12/3.14, including `govulncheck`.
97+
Dependency-update automation and
9598
Docker provenance/SBOM generation are enabled in the repository workflows.
9699

97100
The fast-JavaScript detector was removed from every scoring implementation and

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -135,7 +135,7 @@ Two options, and the tradeoff is real:
135135

136136
<!-- CDN widget: still requires a running FCaptcha API. -->
137137
<script
138-
src="https://cdn.jsdelivr.net/npm/@webdecoy/fcaptcha-client@1.38.0/dist/fcaptcha.min.js"
138+
src="https://cdn.jsdelivr.net/npm/@webdecoy/fcaptcha-client@1.39.0/dist/fcaptcha.min.js"
139139
integrity="sha384-…"
140140
crossorigin="anonymous"></script>
141141
```

‎SECURITY.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -81,8 +81,8 @@ is, older lines are not maintained — upgrade rather than expect a backport.
8181

8282
| Version | Supported |
8383
|---------|-----------|
84-
| 1.38.x | Yes |
85-
| < 1.38 | No |
84+
| 1.39.x | Yes |
85+
| < 1.39 | No |
8686

8787
## Deployment notes that are security-relevant
8888

‎charts/fcaptcha/Chart.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@ description: Open source CAPTCHA with proof of work, behavioural biometrics, and
44
type: application
55
# Chart version moves independently of the app: a fix to a template is a chart
66
# release, not an FCaptcha release.
7-
version: 0.1.18
8-
appVersion: "1.38.0"
7+
version: 0.1.19
8+
appVersion: "1.39.0"
99
home: https://github.com/WebDecoy/FCaptcha
1010
sources:
1111
- https://github.com/WebDecoy/FCaptcha

‎client/fcaptcha.js‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
// Keep in sync with server-node/package.json when cutting a release; this
1515
// string ships to integrators. server-node/version.test.js enforces it
1616
// across every file that carries the version, and lists them.
17-
version: '1.38.0',
17+
version: '1.39.0',
1818
widgets: new Map(),
1919
serverUrl: '',
2020
// Site-wide language default. Per-widget `lang` still wins; leaving both

‎client/package-lock.json‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎client/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@webdecoy/fcaptcha-client",
3-
"version": "1.38.0",
3+
"version": "1.39.0",
44
"description": "Browser widget for FCaptcha — proof of work, behavioural signals, and AI-agent detection",
55
"main": "fcaptcha.js",
66
"browser": "fcaptcha.js",

‎server-node/package-lock.json‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)