fix: add automatic deployment skew protection
CI / check (push) Successful in 37s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m28s

This commit is contained in:
Simo committed 2026-08-01 21:52:28 +02:00
1 parent 0dc16e832d
commit d173dd3194
2 files changed
+31

No files matched your search

+16
View File
@@ -1,8 +1,23 @@
import { execFileSync } from "node:child_process";
import withBundleAnalyzer from "@next/bundle-analyzer";
import { withSentryConfig } from "@sentry/nextjs";
import type { NextConfig } from "next";
import createNextIntlPlugin from "next-intl/plugin";
function resolveDeploymentId(): string | undefined {
const configuredId = process.env.NEXT_DEPLOYMENT_ID?.trim();
if (configuredId) return configuredId;
try {
return execFileSync("git", ["rev-parse", "HEAD"], {
encoding: "utf8",
stdio: ["ignore", "pipe", "ignore"],
}).trim();
} catch {
return process.env.APP_VERSION?.trim() || undefined;
}
}
const securityHeaders = [
{ key: "X-DNS-Prefetch-Control", value: "on" },
{
@@ -20,6 +35,7 @@ const securityHeaders = [
];
const nextConfig: NextConfig = {
deploymentId: resolveDeploymentId(),
turbopack: {},
serverExternalPackages: ["mariadb", "lzma", "sharp", "pino", "pino-pretty"],
+15
View File
@@ -0,0 +1,15 @@
import { execFileSync } from "node:child_process";
import { describe, expect, it } from "vitest";
import nextConfig from "../../next.config";
describe("deployment version skew protection", () => {
it("uses an explicit deployment ID or the current Git commit", () => {
const gitCommit = execFileSync("git", ["rev-parse", "HEAD"], {
encoding: "utf8",
}).trim();
expect(nextConfig.deploymentId).toBe(
process.env.NEXT_DEPLOYMENT_ID?.trim() || gitCommit,
);
});
});