Repository navigation
Clear security/quality findings, add CI, harden release workflow - #41
Merged
Merged
Conversation
Clears GHSA-67mh-4wv8-2f99 (esbuild dev server), GHSA-82fw-gwwq-j7x9 (@vitest/mocker path traversal) and the transitive nanoid/postcss advisories. Vite 7 is the smallest major that drops the vulnerable esbuild; vite 8 (rolldown) was skipped as a larger change. npm audit now reports 0 vulnerabilities. Vite 7 needs Node 20.19+/22.12+, so the README requirement is raised. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
Patch-level lockfile update; cargo audit is clean apart from unmaintained/unsound warnings in the gtk3 stack pinned by tauri. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
decodeURIComponent threw a URIError on input like a lone '%', which escaped as a logged 500. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
js/unused-local-variable findings from the code-quality suite. The COLUMNS table was never read; the generator addresses cells by letter directly. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
Until now only the tag-triggered release ran any checks, so tests, the server typecheck and cargo tests never ran on PRs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
The 1.3.2 notes were inlined in the workflow, so the next tag would have been drafted with them. They now live in docs/RELEASE_NOTES_<version>.md and the job fails if the file is missing. The job also runs the test suite and checks that the tag matches package.json, tauri.conf.json and Cargo.toml before building. Drop the unused artifact-name matrix key. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Works through the repo's Security & Quality findings (Dependabot, CodeQL default setup) and closes the gaps that let them accumulate: there was no CI on push/PR, and the release workflow would have published the 1.3.2 notes for any future tag.
Related issue
No issue — maintenance pass over the Security & Quality tab. Supersedes Dependabot PRs #36, #37, #39, #40.
Type of change
Changes made
Commit-by-commit:
npm audit fixfor nanoid/postcss). Clears GHSA-67mh-4wv8-2f99 (esbuild dev server), GHSA-82fw-gwwq-j7x9 (@vitest/mocker), nanoid and postcss advisories.npm audit: 0 vulnerabilities. Vite 8 (rolldown) deliberately skipped as a bigger change for no extra security benefit. README Node requirement raised to 20.19+/22.12+ (Vite 7 minimum).decodeURIComponentthrew a URIError). Regression test added; verified it fails without the fix.COLUMNStable (CodeQLjs/unused-local-variable, code-quality suite).ci.yml+dependabot.yml. CI on push tomainand PRs:validate:printers,npm test,npm run build,npm run build:server,npm audit --omit=dev --audit-level=high,cargo test --lib. The audit is limited to shipped deps so a fresh dev-tool advisory doesn't turn every PR red. Dependabot handles that instead.docs/RELEASE_NOTES_1.3.2.md, byte-identical to the old inline body (checked by parsing the old YAML).docs/RELEASE_NOTES_<version>.mdand fails if it's missing.npm testbefore building.package.json,tauri.conf.jsonorCargo.toml.artifact-namematrix key.integration.ymlchecked: the Orca pin matchesPINNED_MANAGED_ORCAinengine.rs, no change needed.validate:printersran in CI.Testing performed
I checked for new console or build errors.
I added or updated relevant documentation.
npm test: 478 passed.npm run build,npm run build:server,npm run validate:printers: OK.vitedev server starts on 7.3.6. Builtdist/still uses relative./paths.cargo test --lib: 62 passed, 11 ignored.cargo audit: no vulnerabilities, only unmaintained/unsound warnings (see risks).Local CodeQL 2.27.1 (same version as the default setup), code-scanning + code-quality suites:
rust/cleartext-loggingresults, all false positives (see risks).Clean
npm ciwith npm 10 against the regenerated lockfile.Not run on GitHub yet: the new
ci.ymlruns for the first time on this PR. Therelease.ymlchanges only run on the next tag.Test environment
Operating system: Linux (cloud container)
PerfectFit version or branch: 1.3.2 /
claude/busy-hamilton-z2zym0Slicer and version: n/a
Printer, if relevant: n/a
Compatibility and risks
docs/RELEASE_NOTES_<version>.md, or with mismatched manifest versions, now fails the release job. This is intentional.lts/*.VariantStrIter): glib 0.18 is pinned by Tauri's GTK3 stack, so it can't be updated from here. The app doesn't use that API, which is also why Dependabot's update run failed.rust/cleartext-loggingindiscovery.rs/flow_test.rs: all inside#[cfg(test)] #[ignore]manual probes that print a local profile folder name / session id to stdout. They aren't secrets and aren't in shipped code.Final checklist
🤖 Generated with Claude Code
https://claude.ai/code/session_012ogkkoq4TrDQskE34iXVzx
Generated by Claude Code