Repository navigation
chore(deps): refresh dependencies and base image, drop dead packages - #119
Merged
Merged
Conversation
… 11.21 - in-range npm update: clears proxy-addr (critical), nodemailer, multer, fast-uri, source-map-js, serialize-javascript and brace-expansion advisories - raise the nodemailer floor to the first non-vulnerable release - base image node:24.21.0-alpine3.24; upgrade the npm bundled with node to 11.21.0, it is still needed at runtime as lib-node-registry runs "npm rebuild" on plugins with native modules - alpine 3.24 split the ADBC and AVIF gdal drivers into their own packages, install them so the worker keeps exactly the same ogr/gdal drivers - hold @data-fair/lib-node at ~2.13.3 (and lib-express ~1.25.0, lib-node-registry 0.7.1 that depend on it): lib-node 2.14 refuses non public addresses by default (SSRF protection), which breaks the calls to privateDataFairUrl / privateRegistryUrl until callers opt into the private agents; adopting it is left to a dedicated change Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… tmp-promise - remove memoizee, multer, semver, tmp-promise (api) and semver (worker) with their @types, unused since the v6 registry integration - declare @data-fair/lib-validation, imported at runtime by the generated api/types/*/.type validators but only resolved through lib-node's copy - declare @types/express, it was only reaching the api through @types/multer - replace tmp-promise (unmaintained since 2022) with fs.mkdtemp, keeping the removal on process exit that setGracefulCleanup provided when a SIGTERM outlasts the grace period Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Both verified behaviour-neutral: tsc, vue-tsc and eslint pass unchanged with typescript 6.0.3 (still inside @typescript-eslint/parser's <6.1.0, the generated types do not depend on it), and commitlint 21 gives identical verdicts to 20 over a corpus of valid and invalid messages. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
simple-directory added a show-password button whose label also matches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ui/vite.config.ts imports it dynamically to inject the ui config in development. It only resolved through the copy hoisted for api and worker, and the dev server fails to find it once npm nests those copies instead. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Vuetify only honors Escape once the overlay is flagged top of the global stack, which happens in a setTimeout after opening: an Escape pressed as soon as the menu content is visible is sometimes ignored and the overlay stays active. Seen on master too (1/5 runs), more often with the refreshed deps (6/10); 10/10 green with the cancel button. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # api/package.json # package-lock.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Routine dependency refresh, security first, taking only majors proven behaviour-neutral.
node:24.21.0-alpine3.24, npm inside the image upgraded to 11.21.0 (still needed at runtime: lib-node-registry runsnpm rebuildon plugins with native modules). Alpine 3.24 split the ADBC/AVIF gdal drivers into their own packages, installed so the worker keeps the same driver set (+5 new ones).@data-fair/lib-validation(imported by the generated validators),@types/express(came only through@types/multer),@data-fair/lib-expressin ui (imported by the dev vite config). tmp-promise replaced byfs.mkdtemp, keeping cleanup on process exit.bracesin dev/build tooling, no fix releasedThe remaining image highs are in npm's own bundled packages, with no npm release fixing them yet.
Held back:
@data-fair/lib-nodestays on ~2.13.3 (with lib-express ~1.25.0, lib-node-registry 0.7.1). lib-node 2.14 blocks requests to private addresses by default (SSRF protection); adopting it is done infix-ssrf, and whichever branch merges second keeps fix-ssrf's ranges and regenerates the lockfile.Declined majors: croner 10 (throws on the
0/10stepstoCRONemits), neostandard 0.13 (silently drops 6 import-x rules), @vueuse/core 15 (lib-vuetify pins ^14), mongodb 7 / tough-cookie 6 (lib-node peers), typescript 7 (typescript-eslint <6.1), dotenv 18 (itsdotenvbin clashes with dotenv-cli).Heads-up: the worker now runs GDAL 3.13, Python 3.14 and gcc 15, so plugins with native addons get rebuilt with a new toolchain. Worth a staging run with such a plugin.