Checkpoint: updates card

This commit is contained in:
Avi 2026-08-24 09:55:00 -05:00
commit a1915bb1c1

View file

@ -1,4 +1,103 @@
# Checkpoint — Feed "My notes" profile filter (2026-08-24) # Checkpoint — Updates card (2026-08-24)
A stopping point you can return to if this session is closed. Everything below was
verified green at the moment this file was written.
## Where things are
- Project: `/home/avi/Projects/Nostr_Keynctr`
- Git repo: `master` @ `8bce428` ("Updates card: scan npm/cargo deps, surface
security advisories, install compatible updates"). Before it: `55a49b4`
(feed profile filter), `3dfd15f` (checkpoint), `b001b3c` (publish latency).
- Working tree is **clean** apart from this checkpoint update, which is committed right after.
## What was completed
1. **Updates card in Settings (2026-08-24, `8bce428`).** New **Updates** section
on the Settings screen with two buttons:
- **Check for updates** — scans without changing anything:
`npm outdated --json` + `npm audit --json` (frontend) and
`cargo update --dry-run` (Rust). Known security advisories are listed
first with severity badges (critical/high → danger, moderate → warning);
outdated npm packages and Rust crates are listed with current → available
versions.
- **Install updates** — applies compatible (non-breaking) updates:
`npm audit fix`, then `npm update`, then `cargo update`. Reports what was
applied and reminds that a **rebuild + restart** is required to load them.
- First real scan found 20 advisories (2 critical: tar, vitest; several high
in the Electron build chain), 18 outdated npm packages, 42 outdated crates.
2. **Backend:** new `src/updates.rs` module (parsers unit-tested; commands run
with timeouts and never touch secret material). IPC methods `update_check`
and `update_apply`, dispatched outside the state lock so slow installs never
block other requests. Electron allowlist extended; backend round-trip cap
raised 120 s → 300 s to fit cold-cache installs.
3. Optional hardening noted in-app: installing `cargo-audit` adds RustSec
advisory scanning for the Rust side (currently not installed on this machine;
the app says so under Notes when absent).
## Commits added most recently
- `8bce428` Updates card: scan npm/cargo deps, surface security advisories, install compatible updates
## Verification commands run (all green)
Rust (repo root):
```
cargo test # 112 passed; 0 failed (8 new updates tests)
cargo clippy --all-targets # only pre-existing warnings in src/profiles.rs
cargo fmt --check # clean
cargo build --release # success
# end-to-end: echo '{"id":1,"method":"update_check"}' | ./target/release/keynectr serve
# returned real advisories/outdated lists for this machine
```
Frontend (`frontend/`):
```
npm test # 14 files, 91 tests passed (4 new Settings tests)
npm run typecheck # clean
npm run lint # 0 errors
npm run format:check # clean
npm run build # vite build success
npm run electron:build # tsc electron main success
```
## How to use / reproduce
GUI: `cd ~/Projects/Nostr_Keynctr/frontend && npm start` → **Settings →
Updates → Check for updates**, review the list (security first), then
**Install updates**. Afterwards rebuild and relaunch:
```bash
cd ~/Projects/Nostr_Keynctr && cargo build --release
cd frontend && npm run build && npm start
```
CLI equivalent:
```bash
cd frontend && npm audit fix && npm update
cd .. && cargo update
```
## Notes & next steps
- `Install updates` only applies semver-compatible bumps. Major version jumps
shown by the check (e.g. electron 33 → 43, eslint 9 → 10) still need manual
attention — deliberate, to avoid breaking the app silently.
- Consider running the first real "Install updates" soon: 2 critical npm
advisories were found (tar, vitest dev chain) plus high-severity Electron
packaging tools.
- Install `cargo-audit` (`cargo install cargo-audit`) for RustSec coverage; the
card picks it up automatically once present.
- Possible follow-ups: CLI `updates` subcommand; auto-check on startup behind a
setting.
- Relay health (earlier today): damus.io 503, nostr.band WS handshake timing out.
---
# Older checkpoint — Feed "My notes" profile filter (2026-08-24)
A stopping point you can return to if this session is closed. Everything below was A stopping point you can return to if this session is closed. Everything below was
verified green at the moment this file was written. verified green at the moment this file was written.