Checkpoint: security dependency upgrades

This commit is contained in:
Avi 2026-08-24 11:01:18 -05:00
commit 48efaad0d9

View file

@ -1,4 +1,87 @@
# Checkpoint — Updates card (2026-08-24) # Checkpoint — Security dependency upgrades (2026-08-24)
A stopping point you can return to if this session is closed. Everything below was
verified green at the moment this file was written.
## Where things are
- Project: `/home/avi/Projects/Nostr_Keynctr`
- Git repo: `master` @ `c11ab9f` ("Security: major dependency upgrades clearing
all npm advisories; show per-advisory fix paths"). Before it: `8bce428`
(updates card), `a1915bb` (checkpoint), `55a49b4` (feed filter), `b001b3c`
(publish latency).
- Working tree is **clean** apart from this checkpoint update, which is committed right after.
## What was completed
1. **All npm security advisories cleared (2026-08-24, `c11ab9f`).** The user
ran *Install updates*, but 20 advisories remained — `npm audit fix` only
applies semver-compatible fixes, and npm's own `fixAvailable` data showed
every remaining issue needed one of four **major** upgrades. All applied and
verified:
- `vite` ^5.4 → **^8.2.2** (fixes vite path traversal, esbuild dev-server)
- `vitest` ^2.1 → **^4.1.11** (fixes critical vitest/@vitest/mocker/vite-node)
- `electron` ^33.2 → **^43.4.1** (fixes ~30 runtime CVEs incl. ASAR bypass)
- `electron-builder` ^25.1 → **^26.15.3** (fixes critical tar chain,
node-gyp/cacache/make-fetch-happen/builder-util cluster)
- `npm audit` now reports **0 vulnerabilities**.
2. **Updates card now explains residual advisories (`c11ab9f`).** Each advisory
can show a fix-path hint from npm (e.g. "Needs electron@43.4.1, a major
upgrade — not auto-installed."), or "No fix has been published yet." Hints
only appear when *Install updates* cannot clear the item by itself.
3. Full toolchain verified on the new majors: vitest 4, vite 8, plugin-react 6,
electron 43 all pass the existing suite with no config changes.
## Commits added most recently
- `c11ab9f` Security: major dependency upgrades clearing all npm advisories; show per-advisory fix paths
## Verification commands run (all green)
Frontend (`frontend/`):
```
npm audit # found 0 vulnerabilities
npm test # 14 files, 91 tests passed
npm run typecheck # clean
npm run lint # 0 errors
npm run format:check # clean
npm run build # vite 8 build success
npm run electron:build # tsc electron main success
npx electron --version # v43.4.1
```
Rust (repo root):
```
cargo test # 113 passed; 0 failed (new fix-path parser test)
cargo clippy --all-targets # only pre-existing warnings in src/profiles.rs
cargo fmt --check # clean
cargo build --release # success
```
## How to use / reproduce
```bash
cd ~/Projects/Nostr_Keynctr/frontend && npm start
```
Settings → Updates → Check for updates should show "No known security
advisories". If new ones appear later, Install handles compatible fixes;
anything left lists exactly what major upgrade it needs.
## Notes & next steps
- Electron jumped 10 majors (33 → 43): compile-level checks and the renderer
test suite pass, but give the app one manual smoke test (launch, unlock,
publish, feed) when convenient.
- The Updates card's Install button remains deliberately conservative: majors
are never auto-applied; they are surfaced as explicit hints instead.
- Relay health (earlier today): damus.io 503, nostr.band WS handshake timing out.
---
# Older checkpoint — Updates card (2026-08-24)
A stopping point you can return to if this session is closed. Everything below was A stopping point you can return to if this session is closed. Everything below was
verified green at the moment this file was written. verified green at the moment this file was written.