Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
version: 2
updates:
- package-ecosystem: npm
directory: '/'
schedule:
interval: weekly
groups:
non-major:
update-types:
- minor
- patch
15 changes: 10 additions & 5 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ jobs:
validate:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
node-version: ['22.22', '24']
steps:
Expand All @@ -22,8 +23,12 @@ jobs:
cache: npm
- run: npm install --global npm@11.6.0
- run: npm ci
- run: npm run lint
- run: npm run typecheck
- run: npm test
- run: npm audit --omit=dev
- run: npm run check-package
- run: npm run validate
- name: Record full dependency audit
if: always()
run: npm audit --json > dependency-audit.json || test -s dependency-audit.json
- uses: actions/upload-artifact@v4
if: always()
with:
name: dependency-audit-${{ matrix.node-version }}
path: dependency-audit.json
16 changes: 9 additions & 7 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,11 +3,15 @@ name: Publish
on:
push:
tags:
- '*.*.*'
- 'v*.*.*'

permissions:
contents: read

concurrency:
group: npm-publish
cancel-in-progress: false

jobs:
publish:
runs-on: ubuntu-latest
Expand All @@ -16,16 +20,14 @@ jobs:
id-token: write
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0
- uses: actions/setup-node@v5
with:
node-version: '24'
cache: npm
registry-url: https://registry.npmjs.org
- run: npm install --global npm@11.6.0
- run: npm ci
- run: npm run lint
- run: npm run typecheck
- run: npm test
- run: npm run check-package
- name: Publish with provenance
run: npm publish --provenance --access public
- name: Validate and publish with provenance
run: npm run release
5 changes: 5 additions & 0 deletions .prettierignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
node_modules/
dist/
.agent/
package-lock.json
*.tsbuildinfo
2 changes: 1 addition & 1 deletion .prettierrc.js
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,4 @@ module.exports = {
quoteProps: 'as-needed',
endOfLine: 'lf',
printWidth: 100,
};
};
49 changes: 49 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,3 +28,52 @@ Tests use Node's built-in test runner against clean compiled output. Add contrac
## Pull requests

Explain the user impact, compatibility boundary, and validation performed. Distinguish fixture/schema validation from authenticated live API validation. Do not publish a package from a pull-request branch.

## Release checks

Run `npm run validate` for the same checks as CI. Run `npm run release:rehearse`
to execute validation and publish lifecycle hooks without writing to npm. The
local package checker deliberately performs real temporary pack/install operations
even during this rehearsal. It also loads every declared node and credential.

After an independent PR review, both CI jobs and the required Eng approval, merge
through the normal GitHub process. Finish the sequential dependency queue and
rerun the audit on final main before choosing an unpublished package version.
Update package.json and package-lock.json together if a version change is needed.
The reviewed release tag must be `v` followed by that version, on the tested main
commit. Never move a published tag or reuse a published version.

Publishing runs only through `.github/workflows/publish.yml`, with npm trusted
publishing configured for this repository and workflow. An npm package owner must
verify that trust and accept any remaining development-tool security exposure.
A local npm login is not required by trusted publishing, but GitHub write access
alone does not establish npm publishing authority. Do not bypass lifecycle checks
or repository approval rules. Verify npm provenance, tarball integrity and a fresh
registry install after publishing. Rehearsal does not prove OIDC permission.

The current dependency queue is #23, #20, #21, then #22. Refresh and test each PR
after the preceding merge. #22 subsumes the vulnerable brace-expansion path;
verify the final lockfile rather than assuming an overlapping PR is unnecessary.
Use `npm audit --json` to inspect the full tooling tree as well as the production
audit in validate. CI retains that report. Require a full-tree high/critical audit
gate once the existing queue clears; do not hide advisories or force unsupported
major overrides to produce a green audit.

### Unresolved development dependency findings

As of September 14, 2026, the production audit is clean but development tooling
still brings vulnerable `uuid@10.0.0`, `qs@6.15.2` and `stream-json@1.9.1`.
Track GHSA-w5hq-g745-h8pq, GHSA-x5fp-wj9c-mxmx, GHSA-4mjr-xmp4-gh2g and
GHSA-528h-pc64-c93x in the full audit report. The latest inspected n8n backend
packages still pin the affected qs and stream-json versions. This repository's
package validator prohibits overrides, including scoped overrides. A tested qs
6.16.0 override therefore cannot be shipped under the current package contract.

The stream-json consumer imports its parser and `stream-json/Assembler` through
CommonJS; forcing version 3 would change the module/export contract. The uuid
consumers include LangChain v1/v4 usage in both CommonJS and ESM. These packages
are development dependencies, not libraries shipped in this node's tarball;
the separately installed n8n host has its own dependency tree. This distinction
is not risk acceptance. The release owner must disposition these findings or
wait for compatible upstream repairs before publishing. Reevaluate when the
n8n tooling updates its pinned dependencies; retain audit evidence in the PR.
34 changes: 34 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,3 +81,37 @@ Releases are published only by the tag-triggered GitHub Actions workflow. Config
- [Monitor API](https://docs.parallel.ai/monitor-api/monitor-quickstart)
- [Chat API](https://docs.parallel.ai/chat-api/chat-quickstart)
- [n8n community-node documentation](https://docs.n8n.io/integrations/community-nodes/)

## Upgrading from 0.2.0

Back up your n8n database and exported workflows before updating. Test the upgrade
in a disposable instance first, using Node 22.22 or newer. Existing node,
credential and operation identifiers remain unchanged.

- Search defaults to Basic, equivalent to the previous Base setting. Explicit
Base and Pro values still map to Basic and Advanced.
- Webhook signature validation defaults to enabled. Workflows that omitted the
old default now require the Parallel webhook secret in their credentials.
Configure it before reactivating callbacks. An explicitly saved disabled setting
remains disabled. Both Standard and legacy signing formats are supported.
- Monitor callbacks retain `event_group_id` at the top level. Fetch failures still
emit `event_group_error` by default. Enable **Retry on Fetch Failure** to return
a retryable HTTP failure instead. Accepted events may be delivered repeatedly;
use the additive `webhook_id` to identify redelivery. With signature validation
disabled, this header is untrusted caller input.
- The GA Monitor events endpoint returns an `events` array and `next_cursor`.
Update expressions that consumed the old alpha event-group response accordingly.
Saved **Lookback Period** options are rejected explicitly because the current
API cannot guarantee that historical window. Remove that option and use cursor
pagination, handling unavailable older history in your workflow.
- Synchronous Tasks have a configurable total result-wait budget of 1–120 minutes,
defaulting to 75 minutes to accommodate the old 15 four-minute polls plus
backoff. This is now a hard local bound; host execution limits can be shorter.
A timeout does not cancel the Task. Use the reported run ID with **Get Task Run
Result**, rather than submitting another Task. Prefer Async for long processors.
- Authenticated events excluded by a trigger's filter receive HTTP 200 without
starting the workflow. Malformed matching events receive 400; invalid signatures
receive 401. Task result fetch failures and opted-in Monitor fetch failures
receive 503. Enrichment requests have a five-second local timeout.

See [CONTRIBUTING.md](CONTRIBUTING.md) for validation and the reviewed release process.
3 changes: 2 additions & 1 deletion credentials/ParallelApi.credentials.ts
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,8 @@ export class ParallelApi implements ICredentialType {
},
default: '',
required: false,
description: 'Optional webhook secret for validating webhook signatures. Find this in Settings → Webhooks at https://platform.parallel.ai/settings',
description:
'Optional webhook secret for validating webhook signatures. Find this in Settings → Webhooks at https://platform.parallel.ai/settings',
hint: 'Webhook validation ensures secure communication. Get your secret from platform.parallel.ai/settings',
},
];
Expand Down
Loading
Loading