Skip to content

Commit ad26830

Browse files
authored
fix(api): clear dependency findings and stabilize notification tests (#2077)
## Summary Clear the production dependency audit and fix the notification test race that stopped the 4.37.4 release workflow. ## Why This Exists Work intent: repair [release CI run 34372873045](https://github.com/unraid/api/actions/runs/34372873045) and ship a follow-up release. The audit reported 19 high and 15 moderate findings. The notification traversal test failed because a watcher changed the overview during its assertion. ## Resolution Update direct dependencies and scoped transitive overrides to patched versions. Wait for notification service initialization before closing the watcher in test setup, so initialization cannot create a replacement watcher after cleanup. ## Reviewer Considerations - Keep the Tiptap package family aligned and supply its required y-tiptap peer. - Upgrade Stylus to remove its vulnerable decoder chain without forcing an ESM decoder into an older CommonJS caller. - Use csv-parse 7.0.2 with override syntax shared by pnpm and the npm release packager. Casbin is its only dependency path, and authorization and policy tests cover compatibility. - Keep audit exclusions and production notification behavior unchanged. ## Behavior Changes Production packages use patched routing, parsing, and editor dependencies. Notification tests no longer leave a watcher running after initialization. ## Implementation Summary Fastify, Undici, DOMPurify, Tiptap, and vulnerable transitive packages are updated. The latest audit additions are js-yaml 4.3.2 and csv-parse 7.0.2. Both notification test suites wait for initialization before watcher cleanup, with a regression check for the watcher state. ## Verification Node 22.18.0 and pnpm 10.15.0: - Production dependency audit: zero findings. - Watcher regression: failed before the setup fix and passed afterward. - Notification suite: 34 passed. - Focused authentication, authorization, notification, log, and path-validation suites: 461 passed across 15 files. - API type check and lint: passed. - Git diff whitespace check: passed. - Full builds and cross-package tests run in CI on the updated PR head. ## Risk Dependency changes affect routing, parsing, and editor code. The csv-parse override crosses major versions, so authorization tests and the full CI build are required before release. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Maintenance** - Updated underlying libraries across the application and shared packages to newer versions. - Improved dependency coverage and compatibility for web content handling, networking, routing, parsing, and UI functionality. - Added support for collaborative editor functionality in the web application. - **Tests** - Strengthened notification watcher initialization and shutdown coverage to help ensure reliable notification behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
1 parent db3257f commit ad26830

8 files changed

Lines changed: 752 additions & 689 deletions

File tree

‎api/package.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,7 @@
108108
"execa": "9.6.0",
109109
"exit-hook": "4.0.0",
110110
"fast-xml-parser": "5.8.0",
111-
"fastify": "5.8.5",
111+
"fastify": "5.12.1",
112112
"filenamify": "7.0.0",
113113
"fs-extra": "11.3.1",
114114
"glob": "11.1.0",
@@ -146,7 +146,7 @@
146146
"semver": "7.7.2",
147147
"strftime": "0.10.3",
148148
"systeminformation": "5.31.7",
149-
"undici": "7.28.0",
149+
"undici": "7.29.0",
150150
"uuid": "13.0.2",
151151
"ws": "8.21.0",
152152
"zen-observable-ts": "1.1.0",

‎api/src/unraid-api/graph/resolvers/notifications/notifications.service.spec.ts‎

Lines changed: 18 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -49,13 +49,17 @@ const zeroOverview = (): NotificationOverview => ({
4949
},
5050
});
5151

52-
async function disableNotificationsWatcher() {
53-
const watcher = Reflect.get(NotificationsService, 'watcher') as {
54-
close?: () => Promise<void>;
55-
} | null;
56-
await watcher?.close?.();
57-
Reflect.set(NotificationsService, 'watcher', null);
58-
Reflect.set(NotificationsService, 'overview', zeroOverview());
52+
async function disableNotificationsWatcher(service: NotificationsService) {
53+
try {
54+
await Reflect.get(service, 'initialization');
55+
} finally {
56+
const watcher = Reflect.get(NotificationsService, 'watcher') as {
57+
close?: () => Promise<void>;
58+
} | null;
59+
await watcher?.close?.();
60+
Reflect.set(NotificationsService, 'watcher', null);
61+
Reflect.set(NotificationsService, 'overview', zeroOverview());
62+
}
5963
}
6064

6165
// we run sequentially here because this module's state depends on external, shared systems
@@ -88,7 +92,7 @@ describe.sequential('NotificationsService', () => {
8892
}).compile();
8993

9094
service = module.get<NotificationsService>(NotificationsService); // this might need to be a module.resolve instead of get
91-
await disableNotificationsWatcher();
95+
await disableNotificationsWatcher(service);
9296
vi.spyOn(service, 'paths').mockImplementation(() => testPaths);
9397

9498
await service.deleteAllNotifications();
@@ -218,6 +222,11 @@ describe.sequential('NotificationsService', () => {
218222
});
219223
});
220224

225+
it('keeps the filesystem watcher disabled after initialization', async () => {
226+
await Reflect.get(service, 'initialization');
227+
expect(Reflect.get(NotificationsService, 'watcher')).toBeNull();
228+
});
229+
221230
it('generates unique ids', async () => {
222231
const notifications = await Promise.all(
223232
// we break the "rules" here to speed up this test by ~450ms
@@ -620,7 +629,7 @@ describe.concurrent('NotificationsService legacy script compatibility', () => {
620629
}).compile();
621630

622631
service = module.get<NotificationsService>(NotificationsService);
623-
await disableNotificationsWatcher();
632+
await disableNotificationsWatcher(service);
624633
});
625634

626635
it.for([['normal'], ['warning'], ['alert']] as const)(

‎package.json‎

Lines changed: 15 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -29,11 +29,12 @@
2929
"ajv@>=7.0.0-alpha.0 <8.18.0": "8.20.0",
3030
"axios": "1.18.1",
3131
"body-parser": "2.3.0",
32-
"brace-expansion@<1.1.16": "1.1.16",
33-
"brace-expansion@>=3.0.0 <5.0.7": "5.0.7",
32+
"brace-expansion@<1.1.18": "1.1.18",
33+
"brace-expansion@>=3.0.0 <5.0.9": "5.0.9",
34+
"csv-parse": "7.0.2",
3435
"defu": "6.1.7",
3536
"esbuild": "0.28.1",
36-
"fast-uri": "3.1.4",
37+
"fast-uri": "3.1.6",
3738
"fast-xml-parser": "5.8.0",
3839
"file-type": "22.0.1",
3940
"flatted": "3.4.2",
@@ -45,24 +46,30 @@
4546
"js-beautify": "1.15.4",
4647
"js-cookie": "3.0.8",
4748
"jiti": "2.7.0",
48-
"js-yaml": "4.3.0",
49+
"js-yaml": "4.3.2",
4950
"lodash": "4.18.1",
5051
"minimatch@<3.1.5": "3.1.5",
5152
"minimatch@>=9.0.0 <9.0.9": "9.0.9",
5253
"nuxt": "4.4.8",
5354
"picomatch@<2.3.2": "2.3.2",
5455
"picomatch@>=4.0.0 <4.0.4": "4.0.4",
55-
"postcss": "8.5.15",
56-
"qs": "6.15.2",
56+
"postcss": "8.5.23",
57+
"qs": "6.16.0",
5758
"shell-quote": "1.8.4",
5859
"protobufjs": "7.6.5",
59-
"tar": "7.5.20",
60+
"tar": "7.5.21",
6061
"tmp": "0.2.7",
6162
"uuid@>=8.0.0 <11.1.1": "11.1.1",
6263
"uuid@>=11.0.0 <11.1.1": "11.1.1",
6364
"vue-eslint-parser": "10.4.1",
6465
"ws": "8.21.0",
65-
"yaml": "2.9.0"
66+
"yaml": "2.9.0",
67+
"find-my-way@>=9.0.0 <9.7.0": "9.7.0",
68+
"ip-address@>=10.0.0 <10.3.1": "10.3.1",
69+
"nanoid@>=3.0.0 <3.3.18": "3.3.18",
70+
"stylus@<0.64.0": "0.64.0",
71+
"brace-expansion@>=2.0.0 <2.1.4": "2.1.4",
72+
"fastify@>=5.0.0 <5.12.1": "5.12.1"
6673
},
6774
"peerDependencyRules": {
6875
"allowAny": [

‎packages/unraid-api-plugin-connect/package.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@
6262
"rxjs": "7.8.2",
6363
"type-fest": "5.0.0",
6464
"typescript": "5.9.2",
65-
"undici": "7.28.0",
65+
"undici": "7.29.0",
6666
"vitest": "3.2.6",
6767
"ws": "8.21.0",
6868
"zen-observable-ts": "1.1.0"
@@ -97,7 +97,7 @@
9797
"lodash-es": "4.18.1",
9898
"nest-authz": "2.17.0",
9999
"rxjs": "7.8.2",
100-
"undici": "7.28.0",
100+
"undici": "7.29.0",
101101
"ws": "8.21.0",
102102
"zen-observable-ts": "1.1.0"
103103
}

‎packages/unraid-shared/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@
7070
"lodash-es": "4.18.1",
7171
"nest-authz": "2.17.0",
7272
"rxjs": "7.8.2",
73-
"undici": "7.28.0",
73+
"undici": "7.29.0",
7474
"ws": "8.21.0"
7575
}
7676
}

0 commit comments

Comments
 (0)