chore: refresh dependencies - #12
Merged
Merged
Conversation
…unused tooling Upgrade alpine packages at build time and remove npm, corepack and yarn from the runtime stages: they are not used to run the services and carry their own vulnerabilities. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Clears every npm audit finding but uuid (via exceljs, see PR). Raise the lib-vue / lib-vuetify / vuetify floors to the versions now locked: lib-vuetify >= 2.4 needs lib-vue >= 1.29, and VDateInput left the labs in vuetify 4.1, so its labs import is dropped (the auto-import resolves it from the core). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- api: ws and lib-utils are never imported - daemon: lib-utils is never imported; align the lib-express dev dependency (type-only import) with the api so it is no longer installed twice - root: drop @types/chart.js (chart.js 4 ships its own types) and move tough-cookie (only used by axios-auth in tests) to dev dependencies - ui: inline truncate-middle, used once in chart-categories Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
config only resolves NODE_CONFIG_DIR against the cwd when it starts with a dot. The tests passed 'api/config/', which config 4 happened to resolve through the api workspace symlink in node_modules and config 5 does not: make those paths explicitly relative. Loaded configurations are identical to config 4 for api and daemon in development, test and production. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The production bundle is byte-identical to the previous versions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Use flat/recommended-v4 instead of flat/base: same deprecation rules plus the vuetify 4 ones (snackbar, legacy grid props, elevation overflow, typography), to catch regressions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fetchSimpleAgg returns { current: null, previous: null } until the period is
known, and the simple metrics computed then threw on every page load.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
configto v5. v5 resolvesNODE_CONFIG_DIRagainst the cwd only when the path starts with..unplugin-auto-importandunplugin-vue-components, and lint with the Vuetify 4 ESLint rules.Majors left out
mongodb7 andtough-cookie6:@data-fair/lib-nodestill declares peersmongodb: 6andtough-cookie: 5.eslint10 andneostandard0.13: neostandard 0.13 has a peer dependency oneslint ^9.typescript7:vue-tsccrashes on it because TS 7 has no JS API.uuidmoderate advisory comes in throughexceljs, which is unmaintained. It is not reachable because exceljs only callsv4()without a buffer.Test plan
npm test)