Checkpoint: security dependency upgrades
This commit is contained in:
parent
c11ab9f735
commit
48efaad0d9
1 changed files with 84 additions and 1 deletions
|
|
@ -1,4 +1,87 @@
|
||||||
# Checkpoint — Updates card (2026-08-24)
|
# Checkpoint — Security dependency upgrades (2026-08-24)
|
||||||
|
|
||||||
|
A stopping point you can return to if this session is closed. Everything below was
|
||||||
|
verified green at the moment this file was written.
|
||||||
|
|
||||||
|
## Where things are
|
||||||
|
|
||||||
|
- Project: `/home/avi/Projects/Nostr_Keynctr`
|
||||||
|
- Git repo: `master` @ `c11ab9f` ("Security: major dependency upgrades clearing
|
||||||
|
all npm advisories; show per-advisory fix paths"). Before it: `8bce428`
|
||||||
|
(updates card), `a1915bb` (checkpoint), `55a49b4` (feed filter), `b001b3c`
|
||||||
|
(publish latency).
|
||||||
|
- Working tree is **clean** apart from this checkpoint update, which is committed right after.
|
||||||
|
|
||||||
|
## What was completed
|
||||||
|
|
||||||
|
1. **All npm security advisories cleared (2026-08-24, `c11ab9f`).** The user
|
||||||
|
ran *Install updates*, but 20 advisories remained — `npm audit fix` only
|
||||||
|
applies semver-compatible fixes, and npm's own `fixAvailable` data showed
|
||||||
|
every remaining issue needed one of four **major** upgrades. All applied and
|
||||||
|
verified:
|
||||||
|
- `vite` ^5.4 → **^8.2.2** (fixes vite path traversal, esbuild dev-server)
|
||||||
|
- `vitest` ^2.1 → **^4.1.11** (fixes critical vitest/@vitest/mocker/vite-node)
|
||||||
|
- `electron` ^33.2 → **^43.4.1** (fixes ~30 runtime CVEs incl. ASAR bypass)
|
||||||
|
- `electron-builder` ^25.1 → **^26.15.3** (fixes critical tar chain,
|
||||||
|
node-gyp/cacache/make-fetch-happen/builder-util cluster)
|
||||||
|
- `npm audit` now reports **0 vulnerabilities**.
|
||||||
|
2. **Updates card now explains residual advisories (`c11ab9f`).** Each advisory
|
||||||
|
can show a fix-path hint from npm (e.g. "Needs electron@43.4.1, a major
|
||||||
|
upgrade — not auto-installed."), or "No fix has been published yet." Hints
|
||||||
|
only appear when *Install updates* cannot clear the item by itself.
|
||||||
|
3. Full toolchain verified on the new majors: vitest 4, vite 8, plugin-react 6,
|
||||||
|
electron 43 all pass the existing suite with no config changes.
|
||||||
|
|
||||||
|
## Commits added most recently
|
||||||
|
|
||||||
|
- `c11ab9f` Security: major dependency upgrades clearing all npm advisories; show per-advisory fix paths
|
||||||
|
|
||||||
|
## Verification commands run (all green)
|
||||||
|
|
||||||
|
Frontend (`frontend/`):
|
||||||
|
|
||||||
|
```
|
||||||
|
npm audit # found 0 vulnerabilities
|
||||||
|
npm test # 14 files, 91 tests passed
|
||||||
|
npm run typecheck # clean
|
||||||
|
npm run lint # 0 errors
|
||||||
|
npm run format:check # clean
|
||||||
|
npm run build # vite 8 build success
|
||||||
|
npm run electron:build # tsc electron main success
|
||||||
|
npx electron --version # v43.4.1
|
||||||
|
```
|
||||||
|
|
||||||
|
Rust (repo root):
|
||||||
|
|
||||||
|
```
|
||||||
|
cargo test # 113 passed; 0 failed (new fix-path parser test)
|
||||||
|
cargo clippy --all-targets # only pre-existing warnings in src/profiles.rs
|
||||||
|
cargo fmt --check # clean
|
||||||
|
cargo build --release # success
|
||||||
|
```
|
||||||
|
|
||||||
|
## How to use / reproduce
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd ~/Projects/Nostr_Keynctr/frontend && npm start
|
||||||
|
```
|
||||||
|
|
||||||
|
Settings → Updates → Check for updates should show "No known security
|
||||||
|
advisories". If new ones appear later, Install handles compatible fixes;
|
||||||
|
anything left lists exactly what major upgrade it needs.
|
||||||
|
|
||||||
|
## Notes & next steps
|
||||||
|
|
||||||
|
- Electron jumped 10 majors (33 → 43): compile-level checks and the renderer
|
||||||
|
test suite pass, but give the app one manual smoke test (launch, unlock,
|
||||||
|
publish, feed) when convenient.
|
||||||
|
- The Updates card's Install button remains deliberately conservative: majors
|
||||||
|
are never auto-applied; they are surfaced as explicit hints instead.
|
||||||
|
- Relay health (earlier today): damus.io 503, nostr.band WS handshake timing out.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Older checkpoint — Updates card (2026-08-24)
|
||||||
|
|
||||||
A stopping point you can return to if this session is closed. Everything below was
|
A stopping point you can return to if this session is closed. Everything below was
|
||||||
verified green at the moment this file was written.
|
verified green at the moment this file was written.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue