Skip to content

fix(deps): refresh vulnerable API and web packages - #2098

Merged
Eli Bosley (elibosley) merged 5 commits into
mainfrom
codex/dependency-refresh
Oct 6, 2026
Merged

Eli Bosley (elibosley) merged 5 commits into
mainfrom
codex/dependency-refresh

Conversation

@SimonFair

@SimonFair SimonFair commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Refreshes the existing dependency update for newly published advisories, reducing the production audit from 30 findings to three while preserving the existing audit policy.

Updates the affected API/Web/UI packages and transitive resolutions, including GraphQL Tools utilities 12.0.1, Fastify 5.12.5, NestJS Fastify adapter 11.2.4, DOMPurify 3.4.16, Vue 3.5.42, axios, gRPC, basic-ftp, source-map-js and fast-copy. Root and workspace overrides stay consistent. Removes unused API load-files dependency; braces still arrives through NestJS.

The Vue update exposes a dialog class check that assumed string input. Normalizing Vue class values preserves fullscreen animations for strings, arrays and objects; six regressions cover reactive updates. Web test fixtures now use a stable timezone and dispose component/store scopes.

Validation at commit 176ee2cb634e7106b1475d920568df44a1ec343b: Node 22 frozen installation, API/UI/Web type checks and builds pass. Current CI run 37464232518 passes the full Linux test suites, API/Web/UI builds and final TXZ pkgtools validation. CodeQL, Codecov project/patch and CodeRabbit pass. Audit Dependencies is advisory and retains the three findings below.

The exact CI TXZ (SHA-256 4d74dee6f4b3433e0c0a42a9bf0e60b9390901ac521bff277f78cd55dfa4dd60) passed managed Unraid 7.3.2 smoke testing: upgrade and reinstall preserve all 150 component files byte-for-byte; obsolete component cleanup, API restart, temporary VIEWER key creation, authenticated GraphQL through the API socket and nginx, internal CLI report, and HTTP component bytes pass. The managed reservation was restored and released. This smoke test does not cover full Connect cloud callbacks or browser visual E2E.

Residual audit findings remain visible: http-cache-semantics, braces and sprintf-js (two high, one moderate) currently have no patched versions. Source inspection found no enabled Got HTTP cache and static global-agent log formats; this is limited evidence, not a claim that those advisories are fixed or unreachable. No suppressions or lower thresholds were added.

Linear issue: CLD-1208

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 99db7988-8f48-4e7d-acd7-dec960cbf875
📥 Commits

Reviewing files that changed from the base of the PR and between ad700c4 and 176ee2c.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (10)
  • api/package.json
  • package.json
  • packages/unraid-shared/package.json
  • pnpm-workspace.yaml
  • unraid-ui/package.json
  • unraid-ui/src/components/ui/dialog/DialogContent.test.ts
  • unraid-ui/src/components/ui/dialog/DialogContent.vue
  • web/__test__/components/KeyActions.test.ts
  • web/__test__/components/Onboarding/OnboardingCoreSettingsStep.test.ts
  • web/package.json

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


Walkthrough

The pull request updates workspace dependency overrides and package versions. It changes dialog animation selection to use normalized class input and adjusts UI test setup for cleanup and timezone consistency.

Changes

Dependency Updates

Layer / File(s) Summary
Workspace dependency overrides
package.json, pnpm-workspace.yaml
The root package and workspace configuration update dependency pins and version ranges.
Package dependency declarations
api/package.json, packages/unraid-api-plugin-connect/package.json, packages/unraid-shared/package.json
The API and shared package manifests update GraphQL tools, Fastify, and undici declarations.
UI dependency declarations
unraid-ui/package.json, web/package.json
The UI and web manifests update Vue, Vue compiler, and DOMPurify versions.

Dialog Animation Selection

Layer / File(s) Summary
Fullscreen detection and animation tests
unraid-ui/src/components/ui/dialog/DialogContent.vue, unraid-ui/src/components/ui/dialog/DialogContent.test.ts
DialogContent checks the normalized class for the exact min-h-screen token and selects the corresponding animation classes. Tests cover class variants and reactive updates.

Web Test Setup

Layer / File(s) Summary
Test lifecycle and environment setup
web/__test__/components/KeyActions.test.ts, web/__test__/components/Onboarding/OnboardingCoreSettingsStep.test.ts
KeyActions tests dispose Pinia and automatically unmount components. Onboarding tests automatically unmount components, restore mocks, and set the timezone to UTC.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 176ee

This change refreshes dependency versions and adjusts a dialog animation check and some test setup. No concrete merge-blocking issue was identified.

Architecture Summary

Architecture risk: 🔵 Low · up to ad700

The change affects 5 systems.

Changed systems: api, package.json, packages/unraid-api-plugin-connect, packages/unraid-shared, pnpm-workspace.yaml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — api (service) was modified; 1 changed file maps to changed impact.
  • observed — package.json (service) was modified; 1 changed file maps to changed impact.
  • observed — packages/unraid-api-plugin-connect (library) was modified; 1 changed file maps to changed impact.
  • observed — packages/unraid-shared (library) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in api/package.json: Updated the undici dependency version from 7.29.0 to 7.29.1.
  • observed — Modified behavior in package.json: The brace-expansion override ranges now pin to 1.1.19 for versions below 1.1.19 and 5.0.12 for versions from 3.0.0 up to (but excluding) 5.0.13, replacing the prior thresholds and pins. The fast-uri pin changes from 3.1.6 to 3.1.8.
  • observed — Modified behavior in package.json: The ip-address override changes from applying only to versions >=10.0.0 <10.3.1 at 10.3.1 to an unconditional 10.7.1 pin. The brace-expansion range from >=2.0.0 <2.1.4 at 2.1.4 is replaced with >=2.0.0 <2.1.8 at 2.1.7.
  • observed — Modified behavior in packages/unraid-api-plugin-connect/package.json: The undici version in devDependencies changed from 7.29.0 to 7.29.1.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 3…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the dependency refresh and its security focus, which match the pull request’s main changes.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the dialog's class,
And watches fullscreen slides pass.
New versions hop into place,
While tests clean up with care and grace.
UTC keeps time in a steady embrace.

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 53.49%. Comparing base (89b1395) to head (176ee2c).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2098      +/-   ##
==========================================
+ Coverage   53.43%   53.49%   +0.05%     
==========================================
  Files        1044     1044              
  Lines       72705    72706       +1     
  Branches     8422     8422              
==========================================
+ Hits        38852    38896      +44     
+ Misses      33726    33683      -43     
  Partials      127      127              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

Copy link
Copy Markdown
Contributor

This plugin has been deployed to Cloudflare R2 and is available for testing.
Download it at this URL:

https://preview.dl.unraid.net/unraid-api/tag/PR2098/dynamix.unraid.net.plg

@elibosley Eli Bosley (elibosley) changed the title chore(deps): refresh resolved packages fix(deps): refresh vulnerable API and web packages Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev

@elibosley
Eli Bosley (elibosley) merged commit 64eac12 into main Oct 6, 2026
14 of 15 checks passed
@elibosley
Eli Bosley (elibosley) deleted the codex/dependency-refresh branch October 6, 2026 14:26
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🔄 PR Merged - Plugin Redirected to Staging

This PR has been merged and the preview plugin has been updated to redirect to the staging version.

For users testing this PR:

  • Your plugin will automatically update to the staging version on the next update check
  • The staging version includes all merged changes from this PR
  • No manual intervention required

Staging URL:

https://preview.dl.unraid.net/unraid-api/dynamix.unraid.net.plg

Thank you for testing! 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants