Repository navigation
Commit ad26830
authored
fix(api): clear dependency findings and stabilize notification tests (#2077)
## Summary
Clear the production dependency audit and fix the notification test race
that stopped the 4.37.4 release workflow.
## Why This Exists
Work intent: repair [release CI run
34372873045](https://github.com/unraid/api/actions/runs/34372873045) and
ship a follow-up release. The audit reported 19 high and 15 moderate
findings. The notification traversal test failed because a watcher
changed the overview during its assertion.
## Resolution
Update direct dependencies and scoped transitive overrides to patched
versions. Wait for notification service initialization before closing
the watcher in test setup, so initialization cannot create a replacement
watcher after cleanup.
## Reviewer Considerations
- Keep the Tiptap package family aligned and supply its required
y-tiptap peer.
- Upgrade Stylus to remove its vulnerable decoder chain without forcing
an ESM decoder into an older CommonJS caller.
- Use csv-parse 7.0.2 with override syntax shared by pnpm and the npm
release packager. Casbin is its only dependency path, and authorization
and policy tests cover compatibility.
- Keep audit exclusions and production notification behavior unchanged.
## Behavior Changes
Production packages use patched routing, parsing, and editor
dependencies. Notification tests no longer leave a watcher running after
initialization.
## Implementation Summary
Fastify, Undici, DOMPurify, Tiptap, and vulnerable transitive packages
are updated. The latest audit additions are js-yaml 4.3.2 and csv-parse
7.0.2. Both notification test suites wait for initialization before
watcher cleanup, with a regression check for the watcher state.
## Verification
Node 22.18.0 and pnpm 10.15.0:
- Production dependency audit: zero findings.
- Watcher regression: failed before the setup fix and passed afterward.
- Notification suite: 34 passed.
- Focused authentication, authorization, notification, log, and
path-validation suites: 461 passed across 15 files.
- API type check and lint: passed.
- Git diff whitespace check: passed.
- Full builds and cross-package tests run in CI on the updated PR head.
## Risk
Dependency changes affect routing, parsing, and editor code. The
csv-parse override crosses major versions, so authorization tests and
the full CI build are required before release.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Maintenance**
- Updated underlying libraries across the application and shared
packages to newer versions.
- Improved dependency coverage and compatibility for web content
handling, networking, routing, parsing, and UI functionality.
- Added support for collaborative editor functionality in the web
application.
- **Tests**
- Strengthened notification watcher initialization and shutdown coverage
to help ensure reliable notification behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->1 parent db3257f commit ad26830
8 files changed
Lines changed: 752 additions & 689 deletions
File tree
- api
- src/unraid-api/graph/resolvers/notifications
- packages
- unraid-api-plugin-connect
- unraid-ui
- web
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
108 | 108 | | |
109 | 109 | | |
110 | 110 | | |
111 | | - | |
| 111 | + | |
112 | 112 | | |
113 | 113 | | |
114 | 114 | | |
| |||
146 | 146 | | |
147 | 147 | | |
148 | 148 | | |
149 | | - | |
| 149 | + | |
150 | 150 | | |
151 | 151 | | |
152 | 152 | | |
| |||
Lines changed: 18 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
58 | | - | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
59 | 63 | | |
60 | 64 | | |
61 | 65 | | |
| |||
88 | 92 | | |
89 | 93 | | |
90 | 94 | | |
91 | | - | |
| 95 | + | |
92 | 96 | | |
93 | 97 | | |
94 | 98 | | |
| |||
218 | 222 | | |
219 | 223 | | |
220 | 224 | | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
221 | 230 | | |
222 | 231 | | |
223 | 232 | | |
| |||
620 | 629 | | |
621 | 630 | | |
622 | 631 | | |
623 | | - | |
| 632 | + | |
624 | 633 | | |
625 | 634 | | |
626 | 635 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
33 | | - | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
34 | 35 | | |
35 | 36 | | |
36 | | - | |
| 37 | + | |
37 | 38 | | |
38 | 39 | | |
39 | 40 | | |
| |||
45 | 46 | | |
46 | 47 | | |
47 | 48 | | |
48 | | - | |
| 49 | + | |
49 | 50 | | |
50 | 51 | | |
51 | 52 | | |
52 | 53 | | |
53 | 54 | | |
54 | 55 | | |
55 | | - | |
56 | | - | |
| 56 | + | |
| 57 | + | |
57 | 58 | | |
58 | 59 | | |
59 | | - | |
| 60 | + | |
60 | 61 | | |
61 | 62 | | |
62 | 63 | | |
63 | 64 | | |
64 | 65 | | |
65 | | - | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
66 | 73 | | |
67 | 74 | | |
68 | 75 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
65 | | - | |
| 65 | + | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| |||
97 | 97 | | |
98 | 98 | | |
99 | 99 | | |
100 | | - | |
| 100 | + | |
101 | 101 | | |
102 | 102 | | |
103 | 103 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
0 commit comments