mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 16:39:42 +02:00
chore: COD-28 harden dependencies and public assets
This commit is contained in:
Generated
+3865
-2694
File diff suppressed because it is too large
Load Diff
+25
-10
@@ -21,8 +21,9 @@
|
|||||||
"typecheck": "tsc --noEmit",
|
"typecheck": "tsc --noEmit",
|
||||||
"lint": "eslint --config config/eslint.config.js 'src/**/*.ts'",
|
"lint": "eslint --config config/eslint.config.js 'src/**/*.ts'",
|
||||||
"lint:fix": "eslint --config config/eslint.config.js 'src/**/*.ts' --fix",
|
"lint:fix": "eslint --config config/eslint.config.js 'src/**/*.ts' --fix",
|
||||||
"format": "prettier --write 'src/**/*.ts'",
|
"format": "prettier --write 'src/**/*.ts' 'src/web/public/**/*.{js,css,html,json}'",
|
||||||
"format:check": "prettier --check 'src/**/*.ts'",
|
"format:check": "prettier --check 'src/**/*.ts' 'src/web/public/**/*.{js,css,html,json}'",
|
||||||
|
"check:public-assets": "node scripts/check-public-assets.mjs",
|
||||||
"capture:subagents": "node scripts/capture-subagent-screenshots.mjs",
|
"capture:subagents": "node scripts/capture-subagent-screenshots.mjs",
|
||||||
"changeset": "changeset",
|
"changeset": "changeset",
|
||||||
"version-packages": "changeset version && npm install --package-lock-only && node scripts/check-lockfile-sync.mjs",
|
"version-packages": "changeset version && npm install --package-lock-only && node scripts/check-lockfile-sync.mjs",
|
||||||
@@ -53,7 +54,7 @@
|
|||||||
"@fastify/compress": "^8.3.1",
|
"@fastify/compress": "^8.3.1",
|
||||||
"@fastify/cookie": "^11.0.2",
|
"@fastify/cookie": "^11.0.2",
|
||||||
"@fastify/multipart": "^10.0.0",
|
"@fastify/multipart": "^10.0.0",
|
||||||
"@fastify/static": "^8.0.0",
|
"@fastify/static": "^9.1.3",
|
||||||
"@fastify/websocket": "^11.2.0",
|
"@fastify/websocket": "^11.2.0",
|
||||||
"@xterm/addon-fit": "^0.11.0",
|
"@xterm/addon-fit": "^0.11.0",
|
||||||
"@xterm/addon-unicode11": "^0.9.0",
|
"@xterm/addon-unicode11": "^0.9.0",
|
||||||
@@ -62,18 +63,18 @@
|
|||||||
"chalk": "^5.3.0",
|
"chalk": "^5.3.0",
|
||||||
"chokidar": "^3.6.0",
|
"chokidar": "^3.6.0",
|
||||||
"commander": "^12.1.0",
|
"commander": "^12.1.0",
|
||||||
"fastify": "^5.1.0",
|
"fastify": "^5.8.5",
|
||||||
"node-pty": "^1.1.0",
|
"node-pty": "^1.1.0",
|
||||||
"qrcode": "^1.5.4",
|
"qrcode": "^1.5.4",
|
||||||
"uuid": "^10.0.0",
|
"uuid": "^14.0.0",
|
||||||
"web-push": "^3.6.7",
|
"web-push": "^3.6.7",
|
||||||
"zod": "^4.3.6"
|
"zod": "^4.3.6"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@changesets/cli": "^2.29.8",
|
"@changesets/cli": "^2.29.8",
|
||||||
"@eslint/js": "^9.0.0",
|
"@eslint/js": "^9.0.0",
|
||||||
"@remotion/cli": "4.0.429",
|
"@remotion/cli": "4.0.473",
|
||||||
"@remotion/transitions": "4.0.429",
|
"@remotion/transitions": "4.0.473",
|
||||||
"@types/node": "^20.19.33",
|
"@types/node": "^20.19.33",
|
||||||
"@types/pngjs": "^6.0.5",
|
"@types/pngjs": "^6.0.5",
|
||||||
"@types/qrcode": "^1.5.6",
|
"@types/qrcode": "^1.5.6",
|
||||||
@@ -81,7 +82,7 @@
|
|||||||
"@types/uuid": "^10.0.0",
|
"@types/uuid": "^10.0.0",
|
||||||
"@types/web-push": "^3.6.4",
|
"@types/web-push": "^3.6.4",
|
||||||
"@types/ws": "^8.18.1",
|
"@types/ws": "^8.18.1",
|
||||||
"@vitest/coverage-v8": "^4.0.18",
|
"@vitest/coverage-v8": "^4.1.8",
|
||||||
"agent-browser": "^0.6.0",
|
"agent-browser": "^0.6.0",
|
||||||
"esbuild": "^0.27.3",
|
"esbuild": "^0.27.3",
|
||||||
"eslint": "^9.0.0",
|
"eslint": "^9.0.0",
|
||||||
@@ -90,16 +91,30 @@
|
|||||||
"pngjs": "^7.0.0",
|
"pngjs": "^7.0.0",
|
||||||
"prettier": "^3.4.0",
|
"prettier": "^3.4.0",
|
||||||
"puppeteer": "^24.36.0",
|
"puppeteer": "^24.36.0",
|
||||||
"remotion": "4.0.429",
|
"remotion": "4.0.473",
|
||||||
"tsx": "^4.15.0",
|
"tsx": "^4.15.0",
|
||||||
"typescript": "^5.9.3",
|
"typescript": "^5.9.3",
|
||||||
"typescript-eslint": "^8.0.0",
|
"typescript-eslint": "^8.0.0",
|
||||||
"vitest": "^4.0.18"
|
"vitest": "^4.1.8"
|
||||||
},
|
},
|
||||||
"optionalDependencies": {
|
"optionalDependencies": {
|
||||||
"@remotion/compositor-linux-x64-gnu": "^4.0.432",
|
"@remotion/compositor-linux-x64-gnu": "^4.0.432",
|
||||||
"@rspack/binding-linux-x64-gnu": "^1.7.7"
|
"@rspack/binding-linux-x64-gnu": "^1.7.7"
|
||||||
},
|
},
|
||||||
|
"overrides": {
|
||||||
|
"basic-ftp": "^5.3.1",
|
||||||
|
"fast-uri": "^3.1.2",
|
||||||
|
"flatted": "^3.4.2",
|
||||||
|
"anymatch": {
|
||||||
|
"picomatch": "^2.3.2"
|
||||||
|
},
|
||||||
|
"micromatch": {
|
||||||
|
"picomatch": "^2.3.2"
|
||||||
|
},
|
||||||
|
"readdirp": {
|
||||||
|
"picomatch": "^2.3.2"
|
||||||
|
}
|
||||||
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=18.0.0"
|
"node": ">=18.0.0"
|
||||||
},
|
},
|
||||||
|
|||||||
+1095
-891
File diff suppressed because it is too large
Load Diff
@@ -45,6 +45,6 @@
|
|||||||
"jsdom": "^24.1.3",
|
"jsdom": "^24.1.3",
|
||||||
"tsup": "^8.5.1",
|
"tsup": "^8.5.1",
|
||||||
"typescript": "^5.5.0",
|
"typescript": "^5.5.0",
|
||||||
"vitest": "^2.1.9"
|
"vitest": "^4.1.8"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,66 @@
|
|||||||
|
#!/usr/bin/env node
|
||||||
|
|
||||||
|
import { execFileSync } from 'node:child_process';
|
||||||
|
import { readdirSync, readFileSync } from 'node:fs';
|
||||||
|
import { dirname, extname, join, relative, resolve } from 'node:path';
|
||||||
|
import { fileURLToPath } from 'node:url';
|
||||||
|
|
||||||
|
const repoRoot = resolve(dirname(fileURLToPath(import.meta.url)), '..');
|
||||||
|
const publicRoot = resolve(repoRoot, 'src/web/public');
|
||||||
|
const prettierBin = resolve(repoRoot, 'node_modules/.bin/prettier');
|
||||||
|
const checkedExtensions = new Set(['.js', '.css', '.html', '.json']);
|
||||||
|
|
||||||
|
function collectTextAssets(dir) {
|
||||||
|
const files = [];
|
||||||
|
for (const entry of readdirSync(dir, { withFileTypes: true })) {
|
||||||
|
const fullPath = join(dir, entry.name);
|
||||||
|
if (entry.isDirectory()) {
|
||||||
|
files.push(...collectTextAssets(fullPath));
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (checkedExtensions.has(extname(entry.name))) {
|
||||||
|
files.push(fullPath);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return files;
|
||||||
|
}
|
||||||
|
|
||||||
|
function findNullByte(buffer) {
|
||||||
|
for (let i = 0; i < buffer.length; i += 1) {
|
||||||
|
if (buffer[i] === 0) return i;
|
||||||
|
}
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
const files = collectTextAssets(publicRoot);
|
||||||
|
const failures = [];
|
||||||
|
|
||||||
|
for (const file of files) {
|
||||||
|
const rel = relative(repoRoot, file);
|
||||||
|
const data = readFileSync(file);
|
||||||
|
const nullByteIndex = findNullByte(data);
|
||||||
|
if (nullByteIndex !== -1) {
|
||||||
|
failures.push(`${rel}: contains literal NUL byte at offset ${nullByteIndex}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (extname(file) === '.js') {
|
||||||
|
try {
|
||||||
|
execFileSync(process.execPath, ['--check', file], { cwd: repoRoot, stdio: 'pipe' });
|
||||||
|
} catch (err) {
|
||||||
|
failures.push(`${rel}: JavaScript syntax check failed\n${String(err.stderr || err.message).trim()}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
execFileSync(prettierBin, ['--check', ...files], { cwd: repoRoot, stdio: 'pipe' });
|
||||||
|
} catch (err) {
|
||||||
|
failures.push(`Prettier public asset check failed\n${String(err.stdout || err.stderr || err.message).trim()}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (failures.length > 0) {
|
||||||
|
console.error(failures.join('\n\n'));
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
console.log(`Public asset checks passed (${files.length} files).`);
|
||||||
@@ -1089,7 +1089,7 @@ class CodemanApp {
|
|||||||
const placeholders = [];
|
const placeholders = [];
|
||||||
const masked = text.replace(fenceRe, (m) => {
|
const masked = text.replace(fenceRe, (m) => {
|
||||||
placeholders.push(m);
|
placeholders.push(m);
|
||||||
return ` | |||||||