mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
Resolves the four advisories that reach the production dependency tree. The other 16 npm audit reports are devDependencies-only (Remotion, Puppeteer, postcss, the eslint/tsx toolchain) and never ship to users. - @fastify/static 9.1.3 -> 10.1.3 GHSA-8pvw-jcv7-9cmj (authz bypass via non-canonical URL paths). Covers <=10.1.1, so all of 9.x is affected and the fix exists only on the 10.x line. - find-my-way 9.6.0 -> 9.8.0 GHSA-c96f-x56v-gq3h (HTTP/2 DDoS) - fast-uri 3.1.2 -> 3.1.5 GHSA-v2hh-gcrm-f6hx (host confusion) - brace-expansion -> 5.0.9/1.1.18 GHSA-3jxr-9vmj-r5cp (expansion DoS) The last three are transitive and needed only a lockfile re-resolve, so no overrides were introduced. The @fastify/static major changes setHeaders' first argument from a Node ServerResponse to a FastifyReply. Two consequences: 1. res.setHeader() -> reply.header(). The v9 body throws TypeError from inside the plugin on every static request. 2. Precedence flips, silently. The callback used to write to the raw response and lose to the route's staged reply headers; it now writes to the reply and wins. That gave /sw.js a year of immutable in place of the no-cache, no-store its route sets, pinning a service worker on every client with no server-side recovery. A route that already set Cache-Control now keeps it. Verified against v9 to confirm the sw.js behaviour is a regression and not a pre-existing bug. ws appears in npm audit but production is on 8.21.0, outside the vulnerable range; the only affected copy is bundled under @remotion/renderer (dev-only, and remotion is pinned at 4.0.473 because the compositor refuses to start on a version mismatch). Adds test/static-cache-headers.test.ts, which drives a real server and covers a caching contract that had no test at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
174 lines
5.1 KiB
JSON
174 lines
5.1 KiB
JSON
{
|
|
"name": "aicodeman",
|
|
"version": "1.19.6",
|
|
"description": "Mission control for AI coding agents - run 20 autonomous agents with real-time monitoring and session persistence",
|
|
"type": "module",
|
|
"main": "dist/index.js",
|
|
"types": "dist/index.d.ts",
|
|
"bin": {
|
|
"aicodeman": "./dist/index.js",
|
|
"codeman": "./dist/index.js"
|
|
},
|
|
"scripts": {
|
|
"postinstall": "node scripts/postinstall.js",
|
|
"build": "node scripts/build.mjs",
|
|
"build:gesture": "node scripts/build-gesture-bundle.mjs",
|
|
"start": "NODE_COMPILE_CACHE=${HOME}/.codeman/compile-cache node dist/index.js",
|
|
"dev": "tsx src/index.ts web",
|
|
"web": "node dist/index.js web",
|
|
"clean": "rm -rf dist",
|
|
"test": "vitest run --config config/vitest.ci.config.ts",
|
|
"test:watch": "vitest --config config/vitest.ci.config.ts",
|
|
"test:coverage": "vitest run --config config/vitest.ci.config.ts --coverage",
|
|
"test:ci": "vitest run --config config/vitest.ci.config.ts",
|
|
"test:browser": "vitest run --config config/vitest.browser.config.ts",
|
|
"test:perf": "vitest run --config config/vitest.perf.config.ts",
|
|
"test:all": "vitest run --config config/vitest.config.ts",
|
|
"pretest:mobile": "node scripts/prepare-test-vendor.mjs",
|
|
"test:mobile": "vitest run --config test/mobile/vitest.config.ts",
|
|
"check:frontend-syntax": "node scripts/check-frontend-syntax.mjs",
|
|
"fix:node-pty": "node scripts/fix-node-pty.mjs",
|
|
"typecheck": "tsc --noEmit",
|
|
"lint": "eslint --config config/eslint.config.js 'src/**/*.ts'",
|
|
"lint:fix": "eslint --config config/eslint.config.js 'src/**/*.ts' --fix",
|
|
"format": "prettier --write 'src/**/*.ts' 'src/web/public/**/*.{js,css,html,json}'",
|
|
"format:check": "prettier --check 'src/**/*.ts' 'src/web/public/**/*.{js,css,html,json}'",
|
|
"check:public-assets": "node scripts/check-public-assets.mjs",
|
|
"capture:subagents": "node scripts/capture-subagent-screenshots.mjs",
|
|
"changeset": "changeset",
|
|
"version-packages": "changeset version && npm install --package-lock-only && node scripts/check-lockfile-sync.mjs",
|
|
"check:lockfile": "node scripts/check-lockfile-sync.mjs",
|
|
"knip": "npx --yes knip@latest --config config/knip.json",
|
|
"release": "changeset publish"
|
|
},
|
|
"prettier": {
|
|
"singleQuote": true,
|
|
"semi": true,
|
|
"tabWidth": 2,
|
|
"printWidth": 120,
|
|
"trailingComma": "es5",
|
|
"endOfLine": "lf"
|
|
},
|
|
"workspaces": [
|
|
".",
|
|
"packages/*"
|
|
],
|
|
"keywords": [
|
|
"claude-code",
|
|
"claude-ai",
|
|
"claude",
|
|
"anthropic",
|
|
"opencode",
|
|
"codex",
|
|
"antigravity",
|
|
"pi",
|
|
"gemini-cli",
|
|
"ai-agents",
|
|
"agent",
|
|
"session-manager",
|
|
"self-hosted",
|
|
"developer-tools",
|
|
"tmux",
|
|
"terminal",
|
|
"xterm",
|
|
"docker",
|
|
"mosh",
|
|
"local-echo",
|
|
"web-dashboard",
|
|
"cli",
|
|
"llm",
|
|
"automation"
|
|
],
|
|
"author": "arkon",
|
|
"license": "MIT",
|
|
"dependencies": {
|
|
"@fastify/compress": "^8.3.1",
|
|
"@fastify/cookie": "^11.0.2",
|
|
"@fastify/multipart": "^10.0.0",
|
|
"@fastify/static": "^10.1.3",
|
|
"@fastify/websocket": "^11.2.0",
|
|
"@xterm/addon-fit": "^0.11.0",
|
|
"@xterm/addon-serialize": "^0.14.0",
|
|
"@xterm/addon-unicode11": "^0.9.0",
|
|
"@xterm/addon-webgl": "^0.19.0",
|
|
"@xterm/xterm": "^6.0.0",
|
|
"chalk": "^5.3.0",
|
|
"chokidar": "^3.6.0",
|
|
"commander": "^12.1.0",
|
|
"fastify": "^5.8.5",
|
|
"heic-decode": "^2.1.0",
|
|
"jpeg-js": "^0.4.4",
|
|
"node-pty": "^1.1.0",
|
|
"qrcode": "^1.5.4",
|
|
"uuid": "^14.0.0",
|
|
"web-push": "^3.6.7",
|
|
"ws": "^8.21.0",
|
|
"zod": "^4.3.6"
|
|
},
|
|
"devDependencies": {
|
|
"@changesets/cli": "^2.29.8",
|
|
"@eslint/js": "^9.0.0",
|
|
"@remotion/cli": "4.0.473",
|
|
"@remotion/transitions": "4.0.473",
|
|
"@types/node": "^20.19.33",
|
|
"@types/pngjs": "^6.0.5",
|
|
"@types/qrcode": "^1.5.6",
|
|
"@types/react": "^19.2.14",
|
|
"@types/uuid": "^10.0.0",
|
|
"@types/web-push": "^3.6.4",
|
|
"@types/ws": "^8.18.1",
|
|
"@vitest/coverage-v8": "^4.1.8",
|
|
"agent-browser": "^0.6.0",
|
|
"esbuild": "^0.27.3",
|
|
"eslint": "^9.0.0",
|
|
"pixelmatch": "^6.0.0",
|
|
"playwright": "^1.58.0",
|
|
"pngjs": "^7.0.0",
|
|
"postcss": "^8.5.15",
|
|
"prettier": "^3.4.0",
|
|
"puppeteer": "^24.36.0",
|
|
"remotion": "4.0.473",
|
|
"tsx": "^4.15.0",
|
|
"typescript": "^5.9.3",
|
|
"typescript-eslint": "^8.0.0",
|
|
"vitest": "^4.1.8"
|
|
},
|
|
"optionalDependencies": {
|
|
"@remotion/compositor-linux-x64-gnu": "^4.0.432",
|
|
"@rspack/binding-linux-x64-gnu": "^1.7.7"
|
|
},
|
|
"overrides": {
|
|
"basic-ftp": "^5.3.1",
|
|
"fast-uri": "^3.1.2",
|
|
"flatted": "^3.4.2",
|
|
"anymatch": {
|
|
"picomatch": "^2.3.2"
|
|
},
|
|
"micromatch": {
|
|
"picomatch": "^2.3.2"
|
|
},
|
|
"readdirp": {
|
|
"picomatch": "^2.3.2"
|
|
}
|
|
},
|
|
"engines": {
|
|
"node": ">=22.0.0"
|
|
},
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "git+https://github.com/Ark0N/Codeman.git"
|
|
},
|
|
"bugs": {
|
|
"url": "https://github.com/Ark0N/Codeman/issues"
|
|
},
|
|
"homepage": "https://github.com/Ark0N/Codeman#readme",
|
|
"files": [
|
|
"dist",
|
|
"scripts/postinstall.js",
|
|
"scripts/fix-node-pty.mjs",
|
|
"skills",
|
|
"LICENSE",
|
|
"README.md"
|
|
]
|
|
}
|