diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index c42a2a7..0407a61 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,4 +1,87 @@ -# Checkpoint — Updates card (2026-08-24) +# Checkpoint — Security dependency upgrades (2026-08-24) + +A stopping point you can return to if this session is closed. Everything below was +verified green at the moment this file was written. + +## Where things are + +- Project: `/home/avi/Projects/Nostr_Keynctr` +- Git repo: `master` @ `c11ab9f` ("Security: major dependency upgrades clearing + all npm advisories; show per-advisory fix paths"). Before it: `8bce428` + (updates card), `a1915bb` (checkpoint), `55a49b4` (feed filter), `b001b3c` + (publish latency). +- Working tree is **clean** apart from this checkpoint update, which is committed right after. + +## What was completed + +1. **All npm security advisories cleared (2026-08-24, `c11ab9f`).** The user + ran *Install updates*, but 20 advisories remained — `npm audit fix` only + applies semver-compatible fixes, and npm's own `fixAvailable` data showed + every remaining issue needed one of four **major** upgrades. All applied and + verified: + - `vite` ^5.4 → **^8.2.2** (fixes vite path traversal, esbuild dev-server) + - `vitest` ^2.1 → **^4.1.11** (fixes critical vitest/@vitest/mocker/vite-node) + - `electron` ^33.2 → **^43.4.1** (fixes ~30 runtime CVEs incl. ASAR bypass) + - `electron-builder` ^25.1 → **^26.15.3** (fixes critical tar chain, + node-gyp/cacache/make-fetch-happen/builder-util cluster) + - `npm audit` now reports **0 vulnerabilities**. +2. **Updates card now explains residual advisories (`c11ab9f`).** Each advisory + can show a fix-path hint from npm (e.g. "Needs electron@43.4.1, a major + upgrade — not auto-installed."), or "No fix has been published yet." Hints + only appear when *Install updates* cannot clear the item by itself. +3. Full toolchain verified on the new majors: vitest 4, vite 8, plugin-react 6, + electron 43 all pass the existing suite with no config changes. + +## Commits added most recently + +- `c11ab9f` Security: major dependency upgrades clearing all npm advisories; show per-advisory fix paths + +## Verification commands run (all green) + +Frontend (`frontend/`): + +``` +npm audit # found 0 vulnerabilities +npm test # 14 files, 91 tests passed +npm run typecheck # clean +npm run lint # 0 errors +npm run format:check # clean +npm run build # vite 8 build success +npm run electron:build # tsc electron main success +npx electron --version # v43.4.1 +``` + +Rust (repo root): + +``` +cargo test # 113 passed; 0 failed (new fix-path parser test) +cargo clippy --all-targets # only pre-existing warnings in src/profiles.rs +cargo fmt --check # clean +cargo build --release # success +``` + +## How to use / reproduce + +```bash +cd ~/Projects/Nostr_Keynctr/frontend && npm start +``` + +Settings → Updates → Check for updates should show "No known security +advisories". If new ones appear later, Install handles compatible fixes; +anything left lists exactly what major upgrade it needs. + +## Notes & next steps + +- Electron jumped 10 majors (33 → 43): compile-level checks and the renderer + test suite pass, but give the app one manual smoke test (launch, unlock, + publish, feed) when convenient. +- The Updates card's Install button remains deliberately conservative: majors + are never auto-applied; they are surfaced as explicit hints instead. +- Relay health (earlier today): damus.io 503, nostr.band WS handshake timing out. + +--- + +# Older checkpoint — Updates card (2026-08-24) A stopping point you can return to if this session is closed. Everything below was verified green at the moment this file was written.