Skip to content

chore(deps): integrate secure dependencies and shared CI coverage - #261

Merged
DavidHLP merged 20 commits into
codex/u03-db-row-prooffrom
codex/security-source-map-js
Oct 11, 2026
Merged

DavidHLP merged 20 commits into
codex/u03-db-row-prooffrom
codex/security-source-map-js

Conversation

@DavidHLP

@DavidHLP DavidHLP commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

The shared pnpm lock resolved vulnerable source-map-js 1.2.1, while dependency PRs based on the older backend stack failed image security scans. Pin source-map-js 1.2.2, enable shared dependency CI coverage, and integrate the Actions, frontend/type and dotenv18 upgrades onto the patched backend stack.

PR #259 has merged into this branch. The current head is 9c16b47. Its Git tree 596e12234a6a0029c856a47c2be0bd611a5cc33a exactly matches tested integration candidate 6186e58; CI38062115205 completed SUCCESS with all 32 gates passing on that candidate. This is verified tree equivalence, not a new CI run on the merge commit. Both final integration review axes approved that content; the remote supply-chain contract passed. No equivalent test run was restarted.

Preserve writable table computed bindings and template event typing. Lockfile conflict resolution retains the newer frontend peers and removes obsolete intlify snapshots. The base is codex/u03-db-row-proof; this PR does not complete formal U02/U03/U04 acceptance or deploy production.

Root package.json, pnpm-lock.yaml and pnpm-workspace.yaml changes now trigger Console, Management and Docker CI gates. Previously a lock-only workflow dispatch skipped the frontend jobs. Both frontend Dockerfiles consume these shared files. The development guide documents these triggers; its repository corpus manifest deliberately follows the new whole-file SHA while preserving the excerpt digest and all validation/permission rules.

Historical baseline validation for head b987619:

  • Two independent static review axes: APPROVE exact head.
  • Remote corpus regression: 11 passed, 0.13 seconds.
  • Remote path-filter self-check: all nine shared file/scope matches passed; app-specific source paths remain scoped.
  • Current CI: https://github.com/DavidHLP/UltiCode/actions/runs/38059142328 completed SUCCESS on exact head b987619: all 32 gates passed, including Agent, both frontend production dependency audits, all nine Docker gates, migrations, contract compatibility and all three backend test profiles.
  • Prior f0430d3 CI passed both frontend tests including production dependency audit and all nine Docker build gates; this is historical component evidence, not a final-head overall pass.

No changes to frozen acceptance candidates, sealed holdout, security validator logic or unrelated services/mvnw.cmd. No production deployment or paid model calls.

dependabot Bot and others added 19 commits October 10, 2026 08:04
Bumps the all-actions group with 4 updates: [actions/setup-node](https://github.com/actions/setup-node), [actions/upload-artifact](https://github.com/actions/upload-artifact), [jdx/mise-action](https://github.com/jdx/mise-action) and [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `actions/setup-node` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@8207627...949feb2)

Updates `actions/upload-artifact` from 7.0.1 to 7.0.2
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@043fb46...cf430e0)

Updates `jdx/mise-action` from 5.0.1 to 5.1.1
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](jdx/mise-action@7a4e45a...2d8d4ca)

Updates `actions/download-artifact` from 7.0.0 to 8.0.2
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@37930b1...9000827)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-actions
- dependency-name: jdx/mise-action
  dependency-version: 5.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
- dependency-name: actions/download-artifact
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the development group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.1` | `30.1.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.2` | `5.0.3` |
| [@iconify-json/lucide](https://github.com/iconify/icon-sets) | `1.2.137` | `1.2.140` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.2` | `5.0.3` |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.38.0` | `6.40.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.1` | `8.3.3` |
| [vite-plugin-pwa](https://github.com/vite-pwa/vite-plugin-pwa) | `1.3.0` | `2.0.0` |
| [vue-tsc](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc) | `3.3.11` | `3.3.12` |
| [@vitest/ui](https://github.com/vitest-dev/vitest/tree/HEAD/packages/ui) | `5.0.2` | `5.0.3` |


Updates `jsdom` from 30.1.1 to 30.1.2
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.1...v30.1.2)

Updates `vitest` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `@iconify-json/lucide` from 1.2.137 to 1.2.140
- [Commits](https://github.com/iconify/icon-sets/commits)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `knip` from 6.38.0 to 6.40.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.40.0/packages/knip)

Updates `vite` from 8.3.1 to 8.3.3
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.3/packages/vite)

Updates `vite-plugin-pwa` from 1.3.0 to 2.0.0
- [Release notes](https://github.com/vite-pwa/vite-plugin-pwa/releases)
- [Commits](vite-pwa/vite-plugin-pwa@v1.3.0...v2.0.0)

Updates `vue-tsc` from 3.3.11 to 3.3.12
- [Release notes](https://github.com/vuejs/language-tools/releases)
- [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vuejs/language-tools/commits/v3.3.12/packages/tsc)

Updates `@vitest/ui` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/ui)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-version: 30.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@iconify-json/lucide"
  dependency-version: 1.2.140
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development
- dependency-name: knip
  dependency-version: 6.40.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development
- dependency-name: vite
  dependency-version: 8.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: vite-plugin-pwa
  dependency-version: 2.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development
- dependency-name: vue-tsc
  dependency-version: 3.3.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@vitest/ui"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.4.2 to 18.0.6.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.2...v18.0.6)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.6
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-11T02:56:05.650054Z b987619 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

chore(deps): integrate dependency upgrades on patched backend stack
@DavidHLP DavidHLP changed the title fix(deps): enforce patched source-map and shared dependency CI chore(deps): integrate secure dependencies and shared CI coverage Oct 11, 2026
@DavidHLP
DavidHLP merged commit 7eac21a into codex/u03-db-row-proof Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant