From 45c23d2012c6fcd19a11e2811f8d3b1b2c343672 Mon Sep 17 00:00:00 2001 From: AI Agent Date: Tue, 29 Sep 2026 20:54:22 +0000 Subject: [PATCH 1/6] Don't cap signed URL zip uploads at 10 MB (#14) The `--next` upload PUTs the zip with a bare axios.put, so it inherited axios's default body limit. On axios 0.x (the 0.2.1 release) that is 10 MB, and larger bundles failed with "Request body larger than maxBodyLength limit". Set maxBodyLength/maxContentLength to Infinity, as RollbarAPI already does, so the size doesn't depend on axios defaults. Also restore the axios.put stub the existing upload test leaked. Co-Authored-By: Claude Opus 5.5 --- src/sourcemaps/signed-url-uploader.js | 3 +++ test/sourcemaps/signed-url-uploader.test.js | 26 +++++++++++++++++++++ 2 files changed, 29 insertions(+) diff --git a/src/sourcemaps/signed-url-uploader.js b/src/sourcemaps/signed-url-uploader.js index 6113587..101daf8 100644 --- a/src/sourcemaps/signed-url-uploader.js +++ b/src/sourcemaps/signed-url-uploader.js @@ -63,6 +63,9 @@ class SignedUrlUploader { headers: { 'Content-Type': 'application/octet-stream', }, + // Don't cap the zip size client side; the signed URL decides what it accepts. + maxContentLength: Infinity, + maxBodyLength: Infinity, }); if (resp.status === 200) { output.status('Success', 'Uploaded zip file successfully'); diff --git a/test/sourcemaps/signed-url-uploader.test.js b/test/sourcemaps/signed-url-uploader.test.js index 7ab8f84..6bb173e 100644 --- a/test/sourcemaps/signed-url-uploader.test.js +++ b/test/sourcemaps/signed-url-uploader.test.js @@ -5,6 +5,7 @@ const expect = require('chai').expect; const sinon = require('sinon'); const axios = require('axios') +const http = require('http'); const SignedUrlUploader = require('../../src/sourcemaps/signed-url-uploader'); const Scanner = require('../../src/sourcemaps/scanner'); @@ -70,5 +71,30 @@ describe('.upload()', function() { await signedUrlUploader.upload(false, files); expect(stub.callCount).to.equal(1); + stub.restore(); + }); + + it('should upload zips larger than 10 MB', async function() { + let received = 0; + const server = http.createServer((req, res) => { + req.on('data', (chunk) => { received += chunk.length; }); + req.on('end', () => { res.writeHead(200); res.end(); }); + }); + await new Promise((resolve) => server.listen(0, '127.0.0.1', resolve)); + + const size = 11 * 1024 * 1024; + const signedUrlUploader = new SignedUrlUploader(); + signedUrlUploader.zipFiles = function() { this.zipBuffer = Buffer.alloc(size); }; + const spy = sinon.spy(axios, 'put'); + + try { + await signedUrlUploader.upload(false, [], `http://127.0.0.1:${server.address().port}/`); + } finally { + spy.restore(); + server.close(); + } + + expect(spy.firstCall.args[2].maxBodyLength).to.equal(Infinity); + expect(received).to.equal(size); }); }); From 6b2f4dced8804242ed68dacccc71cc0fe8316044 Mon Sep 17 00:00:00 2001 From: AI Agent Date: Tue, 29 Sep 2026 20:54:46 +0000 Subject: [PATCH 2/6] Bump axios from 1.15.0 to 1.20.0 (#23) 1.15.0 already clears GHSA-wf5p-g6vw-rhxx from #23, but still has open advisories fixed in 1.15.1, 1.15.2, 1.16.0 and 1.18.0. 1.20.0 is the current release; npm audit reports no axios advisories. Co-Authored-By: Claude Opus 5.5 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 0da7b31..0048b8d 100644 --- a/package.json +++ b/package.json @@ -11,7 +11,7 @@ }, "dependencies": { "adm-zip": "^0.5.2", - "axios": "1.15.0", + "axios": "1.20.0", "chalk": "^4.1.0", "form-data": "^3.0.0", "glob": "^7.1.6", From 06f7a4fbf34b739842a5396644c15aba23567fb6 Mon Sep 17 00:00:00 2001 From: AI Agent Date: Tue, 29 Sep 2026 20:54:46 +0000 Subject: [PATCH 3/6] Version 0.2.2 Co-Authored-By: Claude Opus 5.5 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 0048b8d..46838c1 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "rollbar-cli", - "version": "0.2.1", + "version": "0.2.2", "license": "MIT", "bin": { "rollbar-cli": "bin/rollbar" From 07e29ec8485c5c41426babe79d9579cdc8e81f3c Mon Sep 17 00:00:00 2001 From: AI Agent Date: Wed, 30 Sep 2026 05:33:29 +0000 Subject: [PATCH 4/6] Drop the 0.2.2 version bump Version bumps go in their own PR. This reverts commit 06f7a4fbf34b739842a5396644c15aba23567fb6. Co-Authored-By: Claude Opus 5.5 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 46838c1..0048b8d 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "rollbar-cli", - "version": "0.2.2", + "version": "0.2.1", "license": "MIT", "bin": { "rollbar-cli": "bin/rollbar" From 05cf2bec8b953ff5a5e0137526298e2dadb9c72a Mon Sep 17 00:00:00 2001 From: AI Agent Date: Wed, 30 Sep 2026 05:33:37 +0000 Subject: [PATCH 5/6] Add AGENTS.md (and CLAUDE.md symlink) with the versioning rule Co-Authored-By: Claude Opus 5.5 --- AGENTS.md | 5 +++++ CLAUDE.md | 1 + 2 files changed, 6 insertions(+) create mode 100644 AGENTS.md create mode 120000 CLAUDE.md diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..3f2eb16 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,5 @@ +# Agent Instructions + +## Versioning + +Don't change the `version` in `package.json` in a PR that makes other changes. Version bumps go in their own separate PR. diff --git a/CLAUDE.md b/CLAUDE.md new file mode 120000 index 0000000..47dc3e3 --- /dev/null +++ b/CLAUDE.md @@ -0,0 +1 @@ +AGENTS.md \ No newline at end of file From b040d59655e30fe179f8805e418da22b2b3c0c51 Mon Sep 17 00:00:00 2001 From: AI Agent Date: Wed, 30 Sep 2026 05:34:27 +0000 Subject: [PATCH 6/6] Clarify the axios size comment and always restore the put stub maxContentLength caps the response, not the upload, so say what each option does. Restore the axios.put stub in a finally so a failed assertion doesn't leak it into the next test. Co-Authored-By: Claude Opus 5.5 --- src/sourcemaps/signed-url-uploader.js | 3 ++- test/sourcemaps/signed-url-uploader.test.js | 9 ++++++--- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/src/sourcemaps/signed-url-uploader.js b/src/sourcemaps/signed-url-uploader.js index 101daf8..dd047d0 100644 --- a/src/sourcemaps/signed-url-uploader.js +++ b/src/sourcemaps/signed-url-uploader.js @@ -63,7 +63,8 @@ class SignedUrlUploader { headers: { 'Content-Type': 'application/octet-stream', }, - // Don't cap the zip size client side; the signed URL decides what it accepts. + // maxBodyLength: don't cap the upload size client side; the signed URL + // decides what it accepts. maxContentLength (response size) matches RollbarAPI. maxContentLength: Infinity, maxBodyLength: Infinity, }); diff --git a/test/sourcemaps/signed-url-uploader.test.js b/test/sourcemaps/signed-url-uploader.test.js index 6bb173e..3278303 100644 --- a/test/sourcemaps/signed-url-uploader.test.js +++ b/test/sourcemaps/signed-url-uploader.test.js @@ -69,9 +69,12 @@ describe('.upload()', function() { statusText: 'Success', }); - await signedUrlUploader.upload(false, files); - expect(stub.callCount).to.equal(1); - stub.restore(); + try { + await signedUrlUploader.upload(false, files); + expect(stub.callCount).to.equal(1); + } finally { + stub.restore(); + } }); it('should upload zips larger than 10 MB', async function() {