Skip to content

Clear security/quality findings, add CI, harden release workflow - #41

Merged
Django1982 merged 7 commits into
mainfrom
claude/busy-hamilton-z2zym0
Oct 3, 2026
Merged

Django1982 merged 7 commits into
mainfrom
claude/busy-hamilton-z2zym0

Conversation

@Django1982

Copy link
Copy Markdown
Owner

Summary

Works through the repo's Security & Quality findings (Dependabot, CodeQL default setup) and closes the gaps that let them accumulate: there was no CI on push/PR, and the release workflow would have published the 1.3.2 notes for any future tag.

Related issue

No issue — maintenance pass over the Security & Quality tab. Supersedes Dependabot PRs #36, #37, #39, #40.

Type of change

  • Bug fix
  • Documentation improvement
  • Refactoring or maintenance
  • Build, installer, or release change

Changes made

Commit-by-commit:

  • Upgrade vite 5 → 7, vitest 2 → 4 (+ npm audit fix for nanoid/postcss). Clears GHSA-67mh-4wv8-2f99 (esbuild dev server), GHSA-82fw-gwwq-j7x9 (@vitest/mocker), nanoid and postcss advisories. npm audit: 0 vulnerabilities. Vite 8 (rolldown) deliberately skipped as a bigger change for no extra security benefit. README Node requirement raised to 20.19+/22.12+ (Vite 7 minimum).
  • Bump rustls 0.23.42 → 0.23.45 (RUSTSEC-2026-0285), lockfile only.
  • Server: 400 instead of 500 for malformed percent-encoding in route params (decodeURIComponent threw a URIError). Regression test added; verified it fails without the fix.
  • Remove unused imports and the dead COLUMNS table (CodeQL js/unused-local-variable, code-quality suite).
  • Add ci.yml + dependabot.yml. CI on push to main and PRs: validate:printers, npm test, npm run build, npm run build:server, npm audit --omit=dev --audit-level=high, cargo test --lib. The audit is limited to shipped deps so a fresh dev-tool advisory doesn't turn every PR red. Dependabot handles that instead.
  • release.yml:
    • Release notes move out of the workflow into docs/RELEASE_NOTES_1.3.2.md, byte-identical to the old inline body (checked by parsing the old YAML).
    • The job loads docs/RELEASE_NOTES_<version>.md and fails if it's missing.
    • Runs npm test before building.
    • Fails if the tag disagrees with the versions in package.json, tauri.conf.json or Cargo.toml.
    • Drops the unused artifact-name matrix key.
    • integration.yml checked: the Orca pin matches PINNED_MANAGED_ORCA in engine.rs, no change needed.
  • CLAUDE.md: documents the self-hosted server and its security model, the automated calibration subsystem, CI and the release procedure. Also corrects the old claim that validate:printers ran in CI.

Testing performed

  • I checked for new console or build errors.

  • I added or updated relevant documentation.

  • npm test: 478 passed. npm run build, npm run build:server, npm run validate:printers: OK. vite dev server starts on 7.3.6. Built dist/ still uses relative ./ paths.

  • cargo test --lib: 62 passed, 11 ignored. cargo audit: no vulnerabilities, only unmaintained/unsound warnings (see risks).

  • Local CodeQL 2.27.1 (same version as the default setup), code-scanning + code-quality suites:

    • JS/TS and Actions: 0 results on this branch.
    • Rust: 3 rust/cleartext-logging results, all false positives (see risks).
  • Clean npm ci with npm 10 against the regenerated lockfile.

  • Not run on GitHub yet: the new ci.yml runs for the first time on this PR. The release.yml changes only run on the next tag.

Test environment

Operating system: Linux (cloud container)
PerfectFit version or branch: 1.3.2 / claude/busy-hamilton-z2zym0
Slicer and version: n/a
Printer, if relevant: n/a

Compatibility and risks

  • Release process change: a tag without docs/RELEASE_NOTES_<version>.md, or with mismatched manifest versions, now fails the release job. This is intentional.
  • Node ≥ 20.19 / 22.12 is required for development (Vite 7). CI uses Node 24 and the release job lts/*.
  • Not fixed, needs dismissal in the Security tab:
    • glib RUSTSEC-2024-0429 (unsound VariantStrIter): glib 0.18 is pinned by Tauri's GTK3 stack, so it can't be updated from here. The app doesn't use that API, which is also why Dependabot's update run failed.
    • 3× rust/cleartext-logging in discovery.rs/flow_test.rs: all inside #[cfg(test)] #[ignore] manual probes that print a local profile folder name / session id to stdout. They aren't secrets and aren't in shipped code.

Final checklist

  • My changes are focused on one issue or purpose.
  • I reviewed my own changes.
  • I did not include unrelated formatting or generated files.
  • Existing functionality continues to work.
  • User-facing text is clear and accurate.
  • I am ready to respond to review feedback.

🤖 Generated with Claude Code

https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx


Generated by Claude Code

claude added 7 commits October 3, 2026 03:43
Clears GHSA-67mh-4wv8-2f99 (esbuild dev server), GHSA-82fw-gwwq-j7x9
(@vitest/mocker path traversal) and the transitive nanoid/postcss
advisories. Vite 7 is the smallest major that drops the vulnerable
esbuild; vite 8 (rolldown) was skipped as a larger change. npm audit
now reports 0 vulnerabilities.

Vite 7 needs Node 20.19+/22.12+, so the README requirement is raised.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
Patch-level lockfile update; cargo audit is clean apart from
unmaintained/unsound warnings in the gtk3 stack pinned by tauri.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
decodeURIComponent threw a URIError on input like a lone '%', which
escaped as a logged 500.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
js/unused-local-variable findings from the code-quality suite. The
COLUMNS table was never read; the generator addresses cells by letter
directly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
Until now only the tag-triggered release ran any checks, so tests,
the server typecheck and cargo tests never ran on PRs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
The 1.3.2 notes were inlined in the workflow, so the next tag would
have been drafted with them. They now live in
docs/RELEASE_NOTES_<version>.md and the job fails if the file is
missing. The job also runs the test suite and checks that the tag
matches package.json, tauri.conf.json and Cargo.toml before building.

Drop the unused artifact-name matrix key.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
@Django1982
Django1982 merged commit 8fff636 into main Oct 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants