Skip to content

chore: refresh dependencies - #12

Merged
BatLeDev merged 9 commits into
masterfrom
deps-refresh
Oct 2, 2026
Merged

BatLeDev merged 9 commits into
masterfrom
deps-refresh

Conversation

@BatLeDev

@BatLeDev BatLeDev commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Switch the license from MIT to AGPL-3.0-only.
  • Docker: bump the base image to node 24.21 / alpine 3.24 and remove tooling the image does not use.
  • Update dependencies within their current ranges and remove unused ones.
  • Upgrade config to v5. v5 resolves NODE_CONFIG_DIR against the cwd only when the path starts with ..
  • UI: upgrade unplugin-auto-import and unplugin-vue-components, and lint with the Vuetify 4 ESLint rules.
  • Upgrade commitlint to v21.
  • Fix (UI): simple metrics are now read only after both periods are fetched.

Majors left out

  • mongodb 7 and tough-cookie 6: @data-fair/lib-node still declares peers mongodb: 6 and tough-cookie: 5.
  • eslint 10 and neostandard 0.13: neostandard 0.13 has a peer dependency on eslint ^9.
  • typescript 7: vue-tsc crashes on it because TS 7 has no JS API.
  • The uuid moderate advisory comes in through exceljs, which is unmaintained. It is not reachable because exceljs only calls v4() without a buffer.

Test plan

  • UI build
  • Integration tests (npm test)

BatLeDev and others added 9 commits October 2, 2026 08:46
…unused tooling

Upgrade alpine packages at build time and remove npm, corepack and yarn
from the runtime stages: they are not used to run the services and carry
their own vulnerabilities.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Clears every npm audit finding but uuid (via exceljs, see PR). Raise the
lib-vue / lib-vuetify / vuetify floors to the versions now locked:
lib-vuetify >= 2.4 needs lib-vue >= 1.29, and VDateInput left the labs in
vuetify 4.1, so its labs import is dropped (the auto-import resolves it
from the core).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- api: ws and lib-utils are never imported
- daemon: lib-utils is never imported; align the lib-express dev dependency
  (type-only import) with the api so it is no longer installed twice
- root: drop @types/chart.js (chart.js 4 ships its own types) and move
  tough-cookie (only used by axios-auth in tests) to dev dependencies
- ui: inline truncate-middle, used once in chart-categories

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
config only resolves NODE_CONFIG_DIR against the cwd when it starts with
a dot. The tests passed 'api/config/', which config 4 happened to resolve
through the api workspace symlink in node_modules and config 5 does not:
make those paths explicitly relative. Loaded configurations are identical
to config 4 for api and daemon in development, test and production.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The production bundle is byte-identical to the previous versions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Use flat/recommended-v4 instead of flat/base: same deprecation rules plus
the vuetify 4 ones (snackbar, legacy grid props, elevation overflow,
typography), to catch regressions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fetchSimpleAgg returns { current: null, previous: null } until the period is
known, and the simple metrics computed then threw on every page load.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@BatLeDev
BatLeDev merged commit 882b5ee into master Oct 2, 2026
5 checks passed
@BatLeDev
BatLeDev deleted the deps-refresh branch October 2, 2026 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant