Skip to content

chore(deps): update chromedp/headless-shell docker tag to v157 - #707

Merged
yxtay merged 1 commit into
mainfrom
renovate/chromedp-headless-shell-157.x
Oct 4, 2026
Merged

yxtay merged 1 commit into
mainfrom
renovate/chromedp-headless-shell-157.x

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
chromedp/headless-shell major 155.0.8059.26 → 157.0.8081.0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from yxtay as a code owner October 4, 2026 05:28
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ BASH shellcheck 11 0 0 0.21s
✅ BASH shfmt 11 0 0 0 0.02s
⚠️ COPYPASTE jscpd yes 1 no 0.61s
✅ JSON prettier 2 0 0 0 0.4s
✅ JSON v8r 2 0 0 1.92s
✅ REPOSITORY betterleaks yes no no 0.79s
✅ REPOSITORY git_diff yes no no 0.01s
⚠️ REPOSITORY osv-scanner yes no 1 0.71s
✅ REPOSITORY secretlint yes no no 0.97s
✅ REPOSITORY syft yes no no 1.72s
✅ REPOSITORY trivy yes no no 8.67s
✅ REPOSITORY trivy-sbom yes no no 0.13s
✅ REPOSITORY trufflehog yes no no 2.95s
✅ YAML prettier 50 0 0 0 0.33s
✅ YAML v8r 50 0 0 11.21s
✅ YAML yamllint 50 0 0 1.2s

Detailed Issues

⚠️ COPYPASTE / jscpd - 1 error
error: Duplicated code block (51 tokens), duplicated at [bin/oci-rm-stack-update.sh:12](0)
   ┌─ bin/oci-rm-stack-create.sh:32:1
   │  
32 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
33 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
34 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
35 │ │ 
   · │
39 │ │ 
40 │ │ echo "Creating stack ${STACK_NAME} in ${REGION}..."
   │ ╰────^
   │  
   ┌─ bin/oci-rm-stack-update.sh:12:1
   │  
12 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
13 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
14 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
15 │ │ 
   · │
19 │ │ 
20 │ │ echo "Updating stack ${STACK_ID}..."
   │ ╰────' Duplicated at bin/oci-rm-stack-update.sh:12

error: 1 errors emitted
⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 9.405417ms elapsed, 9.405798ms wall time
No package sources found, --help for usage information.


[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
  - Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
  - If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,JSON_V8R,JSON_PRETTIER,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

✅MegaLinter analysis: Success

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ BASH shfmt 11 0 0 0 0.01s
✅ JSON prettier 2 0 0 0 0.24s
✅ MARKDOWN markdownlint 5 0 0 0 0.32s
✅ MARKDOWN markdown-table-formatter 5 0 0 0 0.1s
✅ TERRAFORM terraform-fmt 7 0 0 0 0.25s
✅ YAML prettier 50 0 0 0 0.23s

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_SHFMT,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,TERRAFORM_TERRAFORM_FMT,YAML_PRETTIER

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 4 0 0 0.01s
⚠️ ACTION zizmor 4 0 0 1 0.36s
✅ BASH bash-exec 11 0 0 0.04s
✅ BASH shellcheck 11 0 0 0.18s
✅ BASH shfmt 11 0 0 0 0.01s
⚠️ COPYPASTE jscpd yes 1 no 0.74s
✅ EDITORCONFIG editorconfig-checker 110 0 0 0.06s
✅ JSON prettier 2 0 0 0 0.31s
✅ JSON v8r 2 0 0 2.56s
✅ MARKDOWN markdownlint 5 0 0 0 0.56s
✅ MARKDOWN markdown-table-formatter 5 0 0 0 0.23s
✅ REPOSITORY betterleaks yes no no 0.97s
✅ REPOSITORY git_diff yes no no 0.01s
⚠️ REPOSITORY osv-scanner yes no 1 0.7s
✅ REPOSITORY secretlint yes no no 0.88s
✅ REPOSITORY syft yes no no 1.6s
✅ REPOSITORY trivy yes no no 10.9s
✅ REPOSITORY trivy-sbom yes no no 0.08s
✅ REPOSITORY trufflehog yes no no 2.6s
⚠️ SPELL lychee 58 37 0 1.47s
✅ YAML prettier 50 0 0 0 0.29s
✅ YAML v8r 50 0 0 10.01s
✅ YAML yamllint 50 0 0 1.4s

Detailed Issues

⚠️ COPYPASTE / jscpd - 1 error
error: Duplicated code block (51 tokens), duplicated at [bin/oci-rm-stack-update.sh:12](0)
   ┌─ bin/oci-rm-stack-create.sh:32:1
   │  
32 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
33 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
34 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
35 │ │ 
   · │
39 │ │ 
40 │ │ echo "Creating stack ${STACK_NAME} in ${REGION}..."
   │ ╰────^
   │  
   ┌─ bin/oci-rm-stack-update.sh:12:1
   │  
12 │ ╭ OCI_RM_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/oci-rm
13 │ │ WORK_DIR=$(mktemp -d "${TMPDIR:-/tmp}/oci-rm.XXXXXX")
14 │ │ STACK_ZIP="${WORK_DIR}/stack.zip"
15 │ │ 
   · │
19 │ │ 
20 │ │ echo "Updating stack ${STACK_ID}..."
   │ ╰────' Duplicated at bin/oci-rm-stack-update.sh:12

error: 1 errors emitted
⚠️ SPELL / lychee - 37 errors
📝 Summary
---------------------
🔍 Total...........66
🔗 Unique..........57
✅ Successful......22
⏳ Timeouts.........0
🔀 Redirected.......0
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors..........37
⛔ Unsupported.....37

Errors in agent/bifrost/config.json
[404] https://api.commandcode.ai/provider (at 23:22) | Rejected status code: 404 Not Found

Errors in agent/compose.yaml
[ERROR] http://localhost:2375/_ping (at 91:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8080/healthz (at 240:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9119/api/status (at 49:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9377/health (at 151:33) | Connection refused - server may be down or port blocked
[ERROR] https://hermes/ (at 9:67) | Connection failed. Check network connectivity and firewall settings
[ERROR] https://searxng/ (at 227:45) | Connection failed. Check network connectivity and firewall settings

Errors in arcane/compose.yaml
[ERROR] http://localhost:3552/ (at 6:27) | Connection refused - server may be down or port blocked

Errors in homeassistant/compose.yaml
[ERROR] http://localhost:10000/health (at 148:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:6052/version (at 107:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8095/ (at 66:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8123/ (at 27:33) | Connection refused - server may be down or port blocked

Errors in immich/compose.yaml
[ERROR] http://localhost:8080/api/status (at 164:32) | Connection refused - server may be down or port blocked

Errors in infra/compose.yaml
[ERROR] http://localhost:2375/_ping (at 62:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9002/healthz (at 99:36) | Connection refused - server may be down or port blocked

Errors in monitoring/compose.yaml
[ERROR] http://localhost:8090/ (at 73:44) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8090/ (at 94:27) | Connection refused - server may be down or port blocked

Errors in pangolin/compose.yaml
[ERROR] http://gerbil:3004/ (at 63:23) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://localhost/ping (at 126:32) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3001/api/v1/ (at 51:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:3004/healthz (at 87:32) | Connection refused - server may be down or port blocked
[ERROR] http://pangolin:3001/api/v1/ (at 65:24) | Connection failed. Check network connectivity and firewall settings

Errors in pangolin/traefik/dynamic/config.yml
[ERROR] http://pangolin:3000/ (at 80:18) | Connection failed. Check network connectivity and firewall settings
[ERROR] http://pangolin:3002/ (at 85:18) | Connection failed. Check network connectivity and firewall settings

Errors in pangolin/traefik/traefik.template.yml
[ERROR] http://pangolin:3001/api/v1/traefik-config (at 7:15) | Connection failed. Check network connectivity and firewall settings

Errors in proxy/compose.yaml
[ERROR] http://localhost/healthz (at 36:32) | Connection refused - server may be down or port blocked
[ERROR] https://tinyauth/ (at 50:24) | Connection failed. Check network connectivity and firewall settings

Errors in security/compose.yaml
[ERROR] http://localhost:8080/ (at 52:16) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8080/health (at 34:32) | Connection refused - server may be down or port blocked

Errors in torrent/compose.yaml
[ERROR] http://localhost:6868/ (at 219:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:7878/ping (at 139:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8191/health (at 15:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:8989/ping (at 181:33) | Connection refused - server may be down or port blocked
[ERROR] http://localhost:9696/ping (at 44:33) | Connection refused - server may be down or port blocked
[ERROR] https://profilarr/ (at 204:15) | Connection failed. Check network connectivity and firewall settings

Errors in usenet/compose.yaml
[ERROR] http://localhost:7000/health (at 21:32) | Connection refused - server may be down or port blocked
[ERROR] https://aiostreams/ (at 57:18) | Connection failed. Check network connectivity and firewall settings

Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 7.948035ms elapsed, 7.948247ms wall time
No package sources found, --help for usage information.


[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
  - Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
  - If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.
⚠️ ACTION / zizmor - 1 warning
INFO zizmor: 🌈 zizmor v1.25.0
 INFO audit: zizmor: 🌈 completed .github/workflows/automerge.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/megalinter.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/ossf.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/pr.yml
{
  "$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/schemas/sarif-schema-2.1.0.json",
  "runs": [
    {
      "invocations": [
        {
          "executionSuccessful": true
        }
      ],
      "results": [],
      "tool": {
        "driver": {
          "downloadUri": "https://github.com/zizmorcore/zizmor",
          "informationUri": "https://docs.zizmor.sh",
          "name": "zizmor",
          "rules": [],
          "semanticVersion": "1.25.0",
          "version": "1.25.0"
        }
      }
    }
  ],
  "version": "2.1.0"
No fixes available to apply.
}

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,BASH_EXEC,BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,EDITORCONFIG_EDITORCONFIG_CHECKER,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ BASH bash-exec 11 0 0 0.03s
✅ BASH shellcheck 11 0 0 0.18s
✅ REPOSITORY betterleaks yes no no 0.72s
✅ REPOSITORY dustilock yes no no 0.02s
⚠️ REPOSITORY osv-scanner yes no 1 0.69s
✅ REPOSITORY secretlint yes no no 0.95s
✅ REPOSITORY syft yes no no 1.53s
✅ REPOSITORY trivy yes no no 10.13s
✅ REPOSITORY trivy-sbom yes no no 0.55s
✅ REPOSITORY trufflehog yes no no 2.89s
✅ TERRAFORM tflint yes no no 6.19s

Detailed Issues

⚠️ REPOSITORY / osv-scanner - 1 warning
Scanning dir .
Starting filesystem walk for root: /
End status: 47 dirs visited, 157 inodes visited, 0 Extract calls, 6.511816ms elapsed, 6.512007ms wall time
No package sources found, --help for usage information.


[REPOSITORY_OSV_SCANNER_ERROR_NO_PACKAGE_SOURCES] osv-scanner found no lockfiles, manifests, or SBOMs to scan in the repository.
This is a configuration/scope issue, not a vulnerability finding.
Resolutions:
  - Verify the repository actually contains a supported lockfile (package-lock.json, go.sum, Gemfile.lock, Pipfile.lock, etc.) at the scanned path.
  - If this is expected for some sub-projects, disable osv-scanner for the affected paths or mark it non-blocking via `DISABLE_ERRORS_LINTERS`.

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS, TERRAFORM_TERRASCAN. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters BASH_EXEC,BASH_SHELLCHECK,REPOSITORY_DUSTILOCK,REPOSITORY_BETTERLEAKS,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,TERRAFORM_TFLINT

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@renovate
renovate Bot force-pushed the renovate/chromedp-headless-shell-157.x branch from 27b4c34 to 6b4db46 Compare October 4, 2026 05:30
@yxtay
yxtay enabled auto-merge (squash) October 4, 2026 06:03
@yxtay
yxtay merged commit 7a1ad3b into main Oct 4, 2026
25 checks passed
@yxtay
yxtay deleted the renovate/chromedp-headless-shell-157.x branch October 4, 2026 06:03
@yxtay

yxtay commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Risk assessment: 157.0.8081.0 (PR #707) — safe for fastcrw-only use

Investigated because this stack consumes chromedp/headless-shell only through
[[fastcrw]]'s chrome render rung (renderer:"chrome" → ws://chrome:9222/), and
Renovate flagged 157.0.8081.0 as a major bump.

Verdict: no functional risk found. The one real caveat is that 157 is the
dev-channel build, not stable — so it is a supportability risk, not a
correctness risk.
Merged as-is is fine; the pin can revert if you prefer
stability. Details and evidence below.


1. What actually changed on the CDP wire

Diffed the authoritative source of truth — third_party/blink/public/devtools_protocol/domains/*.pdl
at the two release tags on chromium.googlesource.com (not the release notes, which are
intent-only):

155.0.8059.26 157.0.8081.0
CDP domains 52 53
Domains removed — none
Domains added — FindInPage (new experimental)

Commands/events removed in 157, across the whole protocol:

Storage.getRelatedWebsiteSets        <- the ONLY removal

Commands/events added in 157: Page.getSiblingSubApps, Page.getSubApps,
Storage.{clear,delete,get,getIssuerConfigs,set}PrivateVerificationToken(s),
Storage.privateVerificationTokensUpdated.

Nothing in that list touches fastcrw. fastcrw's renderer
(crates/crw-renderer/src/) references exactly these CDP domains:
Page, Runtime, Target, Network, DOM, Emulation, Fetch, Browser,
Inspector, Accessibility. It never calls Storage.getRelatedWebsiteSets
(verified by grep over the whole crates/*/src tree — the only Storage. hit is a
doc comment in crw-browse/src/tools/storage.rs).

Chrome's own CDP contract is explicit that this is expected: "CDP is not a public or
supported API for Chrome, and we do not guarantee backwards compatibility. Direct use of
CDP by third-party applications is unsupported."
So a 1-command removal per 2 majors is
normal cadence, and 157 happens to be a tiny one.

2. Live functional A/B — 155 vs 156 vs 157, all through fastcrw

Ran a second fastcrw instance (crw:0.37.2, identical config.docker.toml, chrome tier
pointed at a candidate container) against the same 4 URLs × 3 reps + a 6-way concurrent
burst. Prod agent-chrome-1 was never touched. Markdown byte-length and PNG
dimensions are the fidelity check — a silent regression in DOM extraction would show up as
shortened markdown, and a screenshot regression as a missing/invalid PNG.

URL 155 (PR #705) 156 (PR #706) 157 (PR #707)
example.com 200 · 976 md · 800×600 200 · 976 md · 800×600 200 · 976 md · 800×600
news.ycombinator.com 200 · 10939 md 200 · 10939 md 200 · 10939 md
wikipedia/Chromium 200 · ~662k md 200 · ~662k md 200 · ~662k md
httpbin.org/html 200 · 3597 md 200 · 3597 md 200 · 3597 md
burst ×6 concurrent 6/6 ok, 1.1–5.7s 6/6 ok, 1.2–5.8s 6/6 ok, 1.0–5.8s
container restarts 0 0 0

Markdown length is byte-identical across all three versions on every URL, and every
screenshot decoded to a valid 800×600 PNG. Latency is indistinguishable (155 p50 1.42s /
156 1.27s / 157 1.34s on wikipedia; spread well inside noise). No version crashed, no
context leaked, no Inspector.detached.

Note: the first request after each container swap returned 500 CDP connection closed.
That is my harness, not the browsers — fastcrw caches the browser-level
ws:// URL, which embeds a per-process UUID, so swapping the container invalidates it
and only the internal retry succeeds. I added a discarded warmup request per version to
compensate. It is not a version-specific defect and does not affect a normal pinned
deploy where the container identity is stable.

3. The actual caveat: 157 is the dev channel, not stable

This is the part worth your attention, and it is a Renovate/channel question rather than a
Chrome one.

155.0.8059.26  ==  chromedp/headless-shell:stable   ==  :latest    (sha256:47e3a0c0…)
156.0.8078.4   ==  chromedp/headless-shell:beta
157.0.8081.0   ==  chromedp/headless-shell:dev     ==  PR #707     (sha256:8bc58579…)

Chrome for Testing last-known-good, 2026-10-04:

Channel Version
Stable 154.0.8037.92
Beta 156.0.8078.4
Dev 157.0.8081.0
Canary 157.0.8083.0

So the stack went 154 → 155 → 157, i.e. it skipped stable 154→ it is now running a
dev-channel browser in production, two milestones ahead of stable. Renovate treated
stable → dev as just another major bump, which hides that distinction.

Why this matters even though the CDP diff is clean:

  • dev builds are pre-release. Chrome's release notes for a dev build are a partial
    list of changes
    — regressions get landed and reverted within the milestone, so a
    regression present in 157.0.8081.0 is one that never reached stable.
  • No point releases. 151.0.7922.109 (your previous pin) and 157.0.8081.0 are both
    single builds. Patch-level fixes only arrive on the stable channel, so a dev-channel
    image is a frozen snapshot — if 157.0.8081.0 has a rendering bug, there is no
    157.0.8081.1 to bump to. The next thing Renovate can offer is 158.x/canary.
  • Upgrade cadence changes. Chrome moves major every 2 weeks. On dev you get whatever
    milestone is current; on stable you trail by ~6 weeks.

The upside: dev is the earliest channel to carry CDP fixes, and per the diff above that
genuinely is a benefit here — 157 is additive over 155 in every domain fastcrw uses.

4. Recommendation

Accept 157 as merged. The CDP surface fastcrw depends on is intact, functional output
is byte-identical to 155, and it is stable under concurrency. Nothing here justifies
holding the merge.

If you want to close the supportability gap without giving up the render fixes, the cheap
move is to pin to 156.0.8078.4 (beta, one milestone of lead over stable, already
digest-verified: sha256:7c1809255e25a77a464ed1c205c4ad0ce5d9f4f8c25e119afc11eaf7d41b3f1b).
If you'd rather be conservative, 155.0.8059.26 is :stable/:latest and is a strict
subset of what you have now.

Suggested guard so this doesn't silently recur — a Renovate packageRules entry matching
chromedp/headless-shell:

{
  "packageNames": ["docker.io/chromedp/headless-shell"],
  "allowedVersions": "/^1(5[4-6])\\./",   // stable + beta only, no dev/canary
  "description": "chrome render tier feeds fastcrw only; stay on stable/beta, not dev/canary"
}

Also worth noting separately

155.0.8059.26 is the digest behind stable, latest, and the PR #707 title's
predecessor — and it is still what agent-chrome-1 is running in this stack right now,
despite the compose file on main saying 157.0.8081.0. So the merged PR is not reflected
in the running container. If that is unexpected, the deploy path for agent/compose.yaml
has drifted from main; worth checking before the next Renovate round decides whether 158
is a no-op.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant