Skip to content

chore(deps): refresh dependencies and base image, drop dead packages - #119

Merged
albanm merged 9 commits into
masterfrom
chore-deps-refresh
Oct 7, 2026
Merged

albanm merged 9 commits into
masterfrom
chore-deps-refresh

Conversation

@albanm

@albanm albanm commented Oct 7, 2026

Copy link
Copy Markdown
Member

Routine dependency refresh, security first, taking only majors proven behaviour-neutral.

  • In-range updates clear the critical proxy-addr advisory and the nodemailer, multer, fast-uri, source-map-js and serialize-javascript ones; nodemailer floor raised to 10.0.15.
  • Base image node:24.21.0-alpine3.24, npm inside the image upgraded to 11.21.0 (still needed at runtime: lib-node-registry runs npm rebuild on plugins with native modules). Alpine 3.24 split the ADBC/AVIF gdal drivers into their own packages, installed so the worker keeps the same driver set (+5 new ones).
  • Dead deps removed: memoizee, multer, semver, tmp-promise and their types. Undeclared deps declared: @data-fair/lib-validation (imported by the generated validators), @types/express (came only through @types/multer), @data-fair/lib-express in ui (imported by the dev vite config). tmp-promise replaced by fs.mkdtemp, keeping cleanup on process exit.
  • typescript 6 and commitlint 21: tsc/vue-tsc/eslint pass unchanged, commitlint gives identical verdicts.
  • e2e: exact password locator on login; warmup closes menus with their cancel button, since Vuetify can ignore an early Escape (flaky on master too).
before (6.3.0) after
npm audit 13 (1 critical) 6 high, all GHSA-vfj7 braces in dev/build tooling, no fix released
api image (trivy) 1 C / 8 H 0 C / 4 H
worker image (trivy) 1 C / 24 H 0 C / 4 H

The remaining image highs are in npm's own bundled packages, with no npm release fixing them yet.

Held back: @data-fair/lib-node stays on ~2.13.3 (with lib-express ~1.25.0, lib-node-registry 0.7.1). lib-node 2.14 blocks requests to private addresses by default (SSRF protection); adopting it is done in fix-ssrf, and whichever branch merges second keeps fix-ssrf's ranges and regenerates the lockfile.

Declined majors: croner 10 (throws on the 0/10 steps toCRON emits), neostandard 0.13 (silently drops 6 import-x rules), @vueuse/core 15 (lib-vuetify pins ^14), mongodb 7 / tough-cookie 6 (lib-node peers), typescript 7 (typescript-eslint <6.1), dotenv 18 (its dotenv bin clashes with dotenv-cli).

Heads-up: the worker now runs GDAL 3.13, Python 3.14 and gcc 15, so plugins with native addons get rebuilt with a new toolchain. Worth a staging run with such a plugin.

albanm and others added 9 commits October 7, 2026 12:22
… 11.21

- in-range npm update: clears proxy-addr (critical), nodemailer, multer,
  fast-uri, source-map-js, serialize-javascript and brace-expansion advisories
- raise the nodemailer floor to the first non-vulnerable release
- base image node:24.21.0-alpine3.24; upgrade the npm bundled with node to
  11.21.0, it is still needed at runtime as lib-node-registry runs
  "npm rebuild" on plugins with native modules
- alpine 3.24 split the ADBC and AVIF gdal drivers into their own packages,
  install them so the worker keeps exactly the same ogr/gdal drivers
- hold @data-fair/lib-node at ~2.13.3 (and lib-express ~1.25.0,
  lib-node-registry 0.7.1 that depend on it): lib-node 2.14 refuses non
  public addresses by default (SSRF protection), which breaks the calls to
  privateDataFairUrl / privateRegistryUrl until callers opt into the private
  agents; adopting it is left to a dedicated change

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… tmp-promise

- remove memoizee, multer, semver, tmp-promise (api) and semver (worker) with
  their @types, unused since the v6 registry integration
- declare @data-fair/lib-validation, imported at runtime by the generated
  api/types/*/.type validators but only resolved through lib-node's copy
- declare @types/express, it was only reaching the api through @types/multer
- replace tmp-promise (unmaintained since 2022) with fs.mkdtemp, keeping the
  removal on process exit that setGracefulCleanup provided when a SIGTERM
  outlasts the grace period

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Both verified behaviour-neutral: tsc, vue-tsc and eslint pass unchanged with
typescript 6.0.3 (still inside @typescript-eslint/parser's <6.1.0, the
generated types do not depend on it), and commitlint 21 gives identical
verdicts to 20 over a corpus of valid and invalid messages.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
simple-directory added a show-password button whose label also matches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ui/vite.config.ts imports it dynamically to inject the ui config in
development. It only resolved through the copy hoisted for api and worker,
and the dev server fails to find it once npm nests those copies instead.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Vuetify only honors Escape once the overlay is flagged top of the global
stack, which happens in a setTimeout after opening: an Escape pressed as soon
as the menu content is visible is sometimes ignored and the overlay stays
active. Seen on master too (1/5 runs), more often with the refreshed deps
(6/10); 10/10 green with the cancel button.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	api/package.json
#	package-lock.json
@albanm
albanm merged commit 90e6489 into master Oct 7, 2026
4 checks passed
@albanm
albanm deleted the chore-deps-refresh branch October 7, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant