Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ jobs:
- name: Install deps
run: pnpm install --frozen-lockfile
- name: Setup Python
uses: actions/setup-python@v6.3.0
uses: actions/setup-python@v7.0.0
with:
python-version: "3.12"
# ruff runs from the Poetry in-project venv (single source of truth =
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,11 +24,11 @@ jobs:
steps:
- uses: actions/checkout@v7
- name: Initialize CodeQL
uses: github/codeql-action/init@v4.37.1
uses: github/codeql-action/init@v4.38.2
with:
languages: javascript-typescript
queries: security-extended
- name: Analyze
uses: github/codeql-action/analyze@v4.37.1
uses: github/codeql-action/analyze@v4.38.2
with:
category: /language:javascript-typescript
2 changes: 1 addition & 1 deletion .github/workflows/pre-commit-autoupdate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-python@v6.3.0
- uses: actions/setup-python@v7.0.0
with:
python-version: "3.12"

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -133,13 +133,13 @@ jobs:
uses: docker/setup-buildx-action@v4
- name: Login to Docker Hub
if: ${{ env.DOCKERHUB_TOKEN != '' }}
uses: docker/login-action@v4
uses: docker/login-action@v4.6.0
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Login to GHCR
if: ${{ env.DOCKERHUB_TOKEN != '' }}
uses: docker/login-action@v4
uses: docker/login-action@v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand Down
4 changes: 2 additions & 2 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ repos:
# touches prompts/context must never leak keys/tokens/credentials).
# ---------------------------------------------------------------------------
- repo: https://github.com/gitleaks/gitleaks
rev: v8.21.2
rev: v8.30.1
hooks:
- id: gitleaks

Expand Down Expand Up @@ -79,7 +79,7 @@ repos:
# bundles its own Node tool, so it needs NO repo dependencies.
# ---------------------------------------------------------------------------
- repo: https://github.com/DavidAnson/markdownlint-cli2
rev: v0.22.1
rev: v0.23.3
hooks:
- id: markdownlint-cli2
exclude: "(^|/)node_modules/"
Expand Down
14 changes: 14 additions & 0 deletions docs/06-field-notes.md
Original file line number Diff line number Diff line change
Expand Up @@ -337,6 +337,20 @@ Base: `~/.vscode-server/data/User/`
transitive unchanged (Dependabot handles it against real npm once the point-fix lands / the proxy
mirrors it), and always **cross-check the CURRENT advisory range** (not just the version the alert
first cited) before picking the target.
- **Dependency refresh, 2026-09-30:** `pnpm -r up --lockfile-only --depth 10` refreshed compatible
transitive pins, including `fast-uri@3.1.8` and `postcss@8.5.28`, without a forced major upgrade.
Run `scripts/strip-lockfile-tarballs.sh` afterward: the Microsoft registry proxy otherwise embeds
non-portable tarball URLs. `pnpm audit` then reported zero advisories (including dev dependencies).
Build workspace packages **before** integration tests: extension tests import the gateway's built
`dist/`, so an old build can give a false auth failure despite passing typechecks.
- **Poetry artifact-host TLS failure, 2026-09-30:** PyPI metadata was reachable, but
`files.pythonhosted.org` failed TLS handshakes in this devcontainer. `PIP_INDEX_URL` works for pip
and pre-commit; Poetry instead needs a temporary `poetry source add --priority=primary` to resolve
and download packages. The Microsoft packagefeedproxy lagged the newest Ruff and librt patches, so
a temporary public index was used for those. Remove the temporary source and its `[package.source]`
entries from the generated lock, refresh the Poetry content hash, then run `poetry check --lock`
and compare **every locked artifact hash** with official PyPI JSON before committing. Do not leave
an environment-specific mirror in `pyproject.toml` or `poetry.lock`.
- **Correlation/frame ids must be `crypto.randomUUID()`, never `Math.random()` — CodeQL
`js/insecure-randomness` (2026-07-22).** Any random value that flows into a request/frame id (which a
scanner treats as a security sink) trips the High CodeQL alert even for our benign RPC-correlation
Expand Down
12 changes: 6 additions & 6 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -26,13 +26,13 @@
},
"devDependencies": {
"@eslint/js": "^10.0.1",
"@vitest/coverage-v8": "4.1.10",
"eslint": "^10.7.0",
"@vitest/coverage-v8": "4.1.11",
"eslint": "^10.11.0",
"eslint-config-prettier": "^10.1.8",
"eslint-plugin-react-hooks": "^7.1.1",
"globals": "^17.7.0",
"prettier": "^3.9.5",
"typescript": "^5.6.0",
"typescript-eslint": "^8.64.0"
"globals": "^17.12.0",
"prettier": "^3.9.9",
"typescript": "^5.9.3",
"typescript-eslint": "^8.70.1"
}
}
18 changes: 9 additions & 9 deletions packages/extension/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -238,17 +238,17 @@
"@cloakcode/gateway": "workspace:*",
"@cloakcode/protocol": "workspace:*",
"qrcode-generator": "^2.0.4",
"ws": "^8.21.1",
"zod": "^4.4.3"
"ws": "^8.21.3",
"zod": "^4.6.5"
},
"devDependencies": {
"@types/node": "^26.1.1",
"@types/vscode": "^1.90.0",
"@types/ws": "^8.5.12",
"@types/node": "^26.6.2",
"@types/vscode": "^1.138.0",
"@types/ws": "^8.18.1",
"@vscode/vsce": "^3.9.2",
"esbuild": "0.28.1",
"tsx": "^4.23.1",
"typescript": "^5.6.0",
"vitest": "4.1.10"
"esbuild": "0.28.2",
"tsx": "^4.23.15",
"typescript": "^5.9.3",
"vitest": "4.1.11"
}
}
14 changes: 7 additions & 7 deletions packages/gateway/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -28,16 +28,16 @@
},
"dependencies": {
"@cloakcode/protocol": "workspace:*",
"otpauth": "^9.5.1",
"otpauth": "^9.5.2",
"qrcode-generator": "^2.0.4",
"selfsigned": "^5.5.0",
"ws": "^8.21.1"
"ws": "^8.21.3"
},
"devDependencies": {
"@types/node": "^26.1.1",
"@types/ws": "^8.5.12",
"esbuild": "0.28.1",
"typescript": "^5.6.0",
"vitest": "4.1.10"
"@types/node": "^26.6.2",
"@types/ws": "^8.18.1",
"esbuild": "0.28.2",
"typescript": "^5.9.3",
"vitest": "4.1.11"
}
}
6 changes: 3 additions & 3 deletions packages/protocol/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -14,10 +14,10 @@
"test:coverage": "vitest run --coverage"
},
"dependencies": {
"zod": "^4.4.3"
"zod": "^4.6.5"
},
"devDependencies": {
"typescript": "^5.6.0",
"vitest": "4.1.10"
"typescript": "^5.9.3",
"vitest": "4.1.11"
}
}
14 changes: 7 additions & 7 deletions packages/web-playground/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,14 +13,14 @@
"dependencies": {
"@cloakcode/protocol": "workspace:*",
"@cloakcode/web": "workspace:*",
"react": "^19.2.7",
"react-dom": "^19.2.7"
"react": "^19.3.0",
"react-dom": "^19.3.0"
},
"devDependencies": {
"@types/react": "^19.2.17",
"@types/react-dom": "^19.2.3",
"@vitejs/plugin-react": "^6.0.0",
"typescript": "^5.6.0",
"vite": "8.1.5"
"@types/react": "^19.3.0",
"@types/react-dom": "^19.3.0",
"@vitejs/plugin-react": "^6.1.1",
"typescript": "^5.9.3",
"vite": "8.3.0"
}
}
4 changes: 2 additions & 2 deletions packages/web-playground/vite.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@ import { resolve } from "node:path";
// the reverse, so nothing here can ever reach the shipped web build/vsix.
export default defineConfig({
plugins: [react()],
publicDir: resolve(__dirname, "../web/public"),
// Both this package and @cloakcode/web declare react ^18.3.1; force ONE
publicDir: resolve(import.meta.dirname, "../web/public"),
// Both this package and @cloakcode/web declare react ^19.3.0; force ONE
// physical copy so hooks in the cross-package App don't hit "invalid hook
// call" from a duplicate React.
resolve: { dedupe: ["react", "react-dom"] },
Expand Down
22 changes: 11 additions & 11 deletions packages/web/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -18,21 +18,21 @@
},
"dependencies": {
"qrcode-generator": "^2.0.4",
"react": "^19.2.7",
"react-dom": "^19.2.7",
"react": "^19.3.0",
"react-dom": "^19.3.0",
"react-markdown": "^10.1.0",
"remark-gfm": "^4.0.0"
"remark-gfm": "^4.0.1"
},
"devDependencies": {
"@cloakcode/protocol": "workspace:*",
"@testing-library/dom": "^10.4.1",
"@testing-library/react": "^16.3.2",
"@types/react": "^19.2.17",
"@types/react-dom": "^19.2.3",
"@vitejs/plugin-react": "^6.0.0",
"@testing-library/dom": "^10.4.2",
"@testing-library/react": "^16.3.3",
"@types/react": "^19.3.0",
"@types/react-dom": "^19.3.0",
"@vitejs/plugin-react": "^6.1.1",
"jsdom": "29.1.1",
"typescript": "^5.6.0",
"vite": "8.1.5",
"vitest": "4.1.10"
"typescript": "^5.9.3",
"vite": "8.3.0",
"vitest": "4.1.11"
}
}
Loading
Loading