Repository navigation
fix(deps): refresh vulnerable API and web packages - #2098
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (10)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. WalkthroughThe pull request updates workspace dependency overrides and package versions. It changes dialog animation selection to use normalized class input and adjusts UI test setup for cleanup and timezone consistency. ChangesDependency Updates
Dialog Animation Selection
Web Test Setup
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to This change refreshes dependency versions and adjusts a dialog animation check and some test setup. No concrete merge-blocking issue was identified. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 5 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the dialog's class, Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2098 +/- ##
==========================================
+ Coverage 53.43% 53.49% +0.05%
==========================================
Files 1044 1044
Lines 72705 72706 +1
Branches 8422 8422
==========================================
+ Hits 38852 38896 +44
+ Misses 33726 33683 -43
Partials 127 127 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
This plugin has been deployed to Cloudflare R2 and is available for testing. |
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
🔄 PR Merged - Plugin Redirected to StagingThis PR has been merged and the preview plugin has been updated to redirect to the staging version. For users testing this PR:
Staging URL: Thank you for testing! 🚀 |
Refreshes the existing dependency update for newly published advisories, reducing the production audit from 30 findings to three while preserving the existing audit policy.
Updates the affected API/Web/UI packages and transitive resolutions, including GraphQL Tools utilities 12.0.1, Fastify 5.12.5, NestJS Fastify adapter 11.2.4, DOMPurify 3.4.16, Vue 3.5.42, axios, gRPC, basic-ftp, source-map-js and fast-copy. Root and workspace overrides stay consistent. Removes unused API load-files dependency; braces still arrives through NestJS.
The Vue update exposes a dialog class check that assumed string input. Normalizing Vue class values preserves fullscreen animations for strings, arrays and objects; six regressions cover reactive updates. Web test fixtures now use a stable timezone and dispose component/store scopes.
Validation at commit
176ee2cb634e7106b1475d920568df44a1ec343b: Node 22 frozen installation, API/UI/Web type checks and builds pass. Current CI run 37464232518 passes the full Linux test suites, API/Web/UI builds and final TXZ pkgtools validation. CodeQL, Codecov project/patch and CodeRabbit pass. Audit Dependencies is advisory and retains the three findings below.The exact CI TXZ (SHA-256
4d74dee6f4b3433e0c0a42a9bf0e60b9390901ac521bff277f78cd55dfa4dd60) passed managed Unraid 7.3.2 smoke testing: upgrade and reinstall preserve all 150 component files byte-for-byte; obsolete component cleanup, API restart, temporary VIEWER key creation, authenticated GraphQL through the API socket and nginx, internal CLI report, and HTTP component bytes pass. The managed reservation was restored and released. This smoke test does not cover full Connect cloud callbacks or browser visual E2E.Residual audit findings remain visible: http-cache-semantics, braces and sprintf-js (two high, one moderate) currently have no patched versions. Source inspection found no enabled Got HTTP cache and static global-agent log formats; this is limited evidence, not a claim that those advisories are fixed or unreachable. No suppressions or lower thresholds were added.
Linear issue: CLD-1208