Compare commits
9
Commits
v1.1.7
...
c90e348764
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c90e348764 | ||
|
|
068f82c0ff | ||
|
|
1f45cc152a | ||
|
|
be95b6864b | ||
|
|
cfac12b699 | ||
|
|
88e520aa59 | ||
|
|
5aa3bd8977 | ||
|
|
6fae069dec | ||
|
|
2d32047ae2 |
@@ -10,7 +10,7 @@ jobs:
|
||||
- uses: https://git.keligrubb.com/actions/checkout@v7
|
||||
|
||||
- name: Setup Node.js
|
||||
uses: https://git.keligrubb.com/actions/setup-node@v6
|
||||
uses: https://git.keligrubb.com/actions/setup-node@v7
|
||||
with:
|
||||
node-version: "24"
|
||||
cache: "npm"
|
||||
@@ -27,7 +27,7 @@ jobs:
|
||||
- uses: https://git.keligrubb.com/actions/checkout@v7
|
||||
|
||||
- name: Setup Node.js
|
||||
uses: https://git.keligrubb.com/actions/setup-node@v6
|
||||
uses: https://git.keligrubb.com/actions/setup-node@v7
|
||||
with:
|
||||
node-version: "24"
|
||||
cache: "npm"
|
||||
@@ -41,12 +41,12 @@ jobs:
|
||||
e2e:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: mcr.microsoft.com/playwright:v1.61.1-noble
|
||||
image: mcr.microsoft.com/playwright:v1.62.1-noble
|
||||
steps:
|
||||
- uses: https://git.keligrubb.com/actions/checkout@v7
|
||||
|
||||
- name: Setup Node.js
|
||||
uses: https://git.keligrubb.com/actions/setup-node@v6
|
||||
uses: https://git.keligrubb.com/actions/setup-node@v7
|
||||
with:
|
||||
node-version: "24"
|
||||
cache: "npm"
|
||||
|
||||
+167
@@ -1,3 +1,170 @@
|
||||
## [1.1.11] - 2026-08-19
|
||||
### Changed
|
||||
- remove unused broadcastToSession export (#45)
|
||||
|
||||
## Removed
|
||||
|
||||
- `broadcastToSession` from `server/plugins/websocket.js` — an exported but never-imported, never-called dead-code function. Its dependencies (`getSessionConnections`, `addSessionConnection`, `removeSessionConnection`) are retained since they remain actively used for per-session connection tracking within the plugin.
|
||||
|
||||
## Notes
|
||||
|
||||
- Full repository search confirms zero remaining references to `broadcastToSession`.
|
||||
- ESLint passes; full test suite passes (50 files, 406 tests).
|
||||
|
||||
Closes #40
|
||||
|
||||
## [1.1.10] - 2026-08-14
|
||||
### Changed
|
||||
- update dependencies and fix security vulnerabilities (#44)
|
||||
|
||||
## Summary
|
||||
|
||||
Updates all out-of-date dependencies and applies `npm audit fix` to resolve 14 security vulnerabilities (3 critical, 8 high).
|
||||
|
||||
### Dependency Updates
|
||||
|
||||
| Package | Current → Latest |
|
||||
|---|---|
|
||||
| `nuxt` | 4.4.8 → 4.5.2 |
|
||||
| `mediasoup` | 3.20.9 → 3.24.2 |
|
||||
| `mediasoup-client` | 3.21.0 → 3.22.0 |
|
||||
| `hls.js` | 1.6.16 → 1.7.0 |
|
||||
| `vue` | 3.5.38 → 3.5.41 |
|
||||
| `vue-router` | 5.1.0 → 5.2.0 |
|
||||
| `@nuxt/icon` | 2.2.3 → 2.5.0 |
|
||||
| `eslint` | 10.5.0 → 10.8.1 |
|
||||
| `vitest` / `@vitest/coverage-v8` | 4.1.9 → 4.1.10 |
|
||||
| `ws` | 8.21.0 → 8.21.3 |
|
||||
| `openid-client` | 6.8.4 → 6.8.5 |
|
||||
| `fast-xml-parser` | 5.9.3 → 5.10.1 |
|
||||
| `happy-dom` | 20.10.6 → 20.11.2 |
|
||||
| `@playwright/test` | 1.61.1 → 1.62.1 |
|
||||
| `@nuxt/eslint` | 1.16.0 → 1.17.0 |
|
||||
| `@nuxt/test-utils` | 4.0.3 → 4.1.0 |
|
||||
| `@iconify-json/tabler` | 1.2.35 → 1.2.38 |
|
||||
|
||||
### Security Audit Fixes (`npm audit fix`)
|
||||
|
||||
- **`@nuxt/devtools`** (critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's host
|
||||
- **`tar`** (critical): Multiple process-crash/DoS vulnerabilities via crafted tar archives
|
||||
- **`esbuild`** (high): Arbitrary file read when running dev server on Windows
|
||||
- **`brace-expansion`** (high): Multiple DoS vectors (memory exhaustion, process hang)
|
||||
- **`flatted`** (high): Prototype pollution via `parse()`
|
||||
- **`svgo`** (high): `removeScripts` plugin leaves executable scripts intact
|
||||
|
||||
### Verification
|
||||
|
||||
- All 406 tests pass (3 skipped)
|
||||
- Lint clean (`eslint . --max-warnings 0`)
|
||||
- `npm audit` reports 0 vulnerabilities
|
||||
|
||||
## [1.1.9] - 2026-08-13
|
||||
### Changed
|
||||
- update dependency fast-xml-parser to v5.10.1 [security] (#42)
|
||||
|
||||
This PR contains the following updates:
|
||||
|
||||
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|
||||
|---|---|---|---|
|
||||
| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | [`5.9.3` → `5.10.1`](https://renovatebot.com/diffs/npm/fast-xml-parser/5.9.3/5.10.1) |  |  |
|
||||
|
||||
---
|
||||
|
||||
### fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
|
||||
[GHSA-8r6m-32jq-jx6q](https://github.com/advisories/GHSA-8r6m-32jq-jx6q)
|
||||
|
||||
<details>
|
||||
<summary>More information</summary>
|
||||
|
||||
#### Details
|
||||
##### Impact
|
||||
`fast-xml-parser` processes multiple "DOCTYPE" declarations within a single XML document. Each declaration passes its entities to `@nodable/entities` through `addInputEntities()`.
|
||||
|
||||
`addInputEntities()` resets the entity expansion counters every time it is called. An attacker can therefore insert additional DOCTYPE declarations to repeatedly reset maxTotalExpansions and maxExpandedLength during one parse operation.
|
||||
|
||||
This allows a crafted XML document to exceed the configured entity-expansion limits and can cause excessive CPU use, event-loop blocking, memory exhaustion, and process termination.
|
||||
|
||||
##### Workarounds
|
||||
- Manually check if multiple DOCTYPEs are not present in input contents
|
||||
- Update to v5.10.1
|
||||
- Keep `processEntity` flag off
|
||||
|
||||
#### Severity
|
||||
- CVSS Score: 8.7 / 10 (High)
|
||||
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`
|
||||
|
||||
#### References
|
||||
- [https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8r6m-32jq-jx6q](https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8r6m-32jq-jx6q)
|
||||
- [https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e546e03987662de5495d050b5fba26bea65383f](https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e546e03987662de5495d050b5fba26bea65383f)
|
||||
- [https://github.com/NaturalIntelligence/fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser)
|
||||
- [https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.10.1](https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.10.1)
|
||||
|
||||
This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-8r6m-32jq-jx6q) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
|
||||
</details>
|
||||
|
||||
---
|
||||
|
||||
### Release Notes
|
||||
|
||||
<details>
|
||||
<summary>NaturalIntelligence/fast-xml-parser (fast-xml-parser)</summary>
|
||||
|
||||
### [`v5.10.1`](https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.10.1)
|
||||
|
||||
[Compare Source](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1)
|
||||
|
||||
**Full Changelog**: <https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1>
|
||||
|
||||
### [`v5.10.0`](https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.10.0)
|
||||
|
||||
[Compare Source](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0)
|
||||
|
||||
#### What's Changed
|
||||
|
||||
- Bump actions/checkout from 6.0.3 to 7.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​849](https://github.com/NaturalIntelligence/fast-xml-parser/pull/849)
|
||||
- Bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​848](https://github.com/NaturalIntelligence/fast-xml-parser/pull/848)
|
||||
|
||||
**Full Changelog**: <https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0>
|
||||
|
||||
</details>
|
||||
|
||||
---
|
||||
|
||||
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
|
||||
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjguMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwic2VjdXJpdHkiXX0=-->
|
||||
|
||||
## [1.1.8] - 2026-08-13
|
||||
### Changed
|
||||
- update https://git.keligrubb.com/actions/setup-node action to v7 (#38)
|
||||
|
||||
This PR contains the following updates:
|
||||
|
||||
| Package | Type | Update | Change |
|
||||
|---|---|---|---|
|
||||
| [https://git.keligrubb.com/actions/setup-node](https://git.keligrubb.com/actions/setup-node) | action | major | `v6` → `v7` |
|
||||
|
||||
---
|
||||
|
||||
### Release Notes
|
||||
|
||||
<details>
|
||||
<summary>actions/setup-node (https://git.keligrubb.com/actions/setup-node)</summary>
|
||||
|
||||
### [`v7.0.0`](https://git.keligrubb.com/actions/setup-node/compare/v7...v7)
|
||||
|
||||
[Compare Source](https://git.keligrubb.com/actions/setup-node/compare/v7...v7)
|
||||
|
||||
### [`v7`](https://git.keligrubb.com/actions/setup-node/compare/v6.5.0...v7)
|
||||
|
||||
[Compare Source](https://git.keligrubb.com/actions/setup-node/compare/v6.5.0...v7)
|
||||
|
||||
</details>
|
||||
|
||||
---
|
||||
|
||||
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
|
||||
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjUuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI2NS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
|
||||
|
||||
## [1.1.7] - 2026-08-13
|
||||
### Changed
|
||||
- update dependency supercluster to v9 (#41)
|
||||
|
||||
@@ -2,5 +2,5 @@ apiVersion: v2
|
||||
name: kestrelos
|
||||
description: KestrelOS TOC for OSINT feeds - map, camera feeds, offline tiles
|
||||
type: application
|
||||
version: 1.1.7
|
||||
appVersion: "1.1.7"
|
||||
version: 1.1.11
|
||||
appVersion: "1.1.11"
|
||||
|
||||
@@ -2,7 +2,7 @@ replicaCount: 1
|
||||
|
||||
image:
|
||||
repository: git.keligrubb.com/keligrubb/kestrelos
|
||||
tag: 1.1.7
|
||||
tag: 1.1.11
|
||||
pullPolicy: IfNotPresent
|
||||
|
||||
service:
|
||||
|
||||
Generated
+2542
-3778
File diff suppressed because it is too large
Load Diff
+19
-19
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "kestrelos",
|
||||
"version": "1.1.7",
|
||||
"version": "1.1.11",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
"scripts": {
|
||||
@@ -20,32 +20,32 @@
|
||||
"import:alpr": "node scripts/import-alpr.js"
|
||||
},
|
||||
"dependencies": {
|
||||
"@nuxt/icon": "^2.2.3",
|
||||
"@nuxt/icon": "^2.5.0",
|
||||
"@nuxtjs/tailwindcss": "^6.14.0",
|
||||
"fast-xml-parser": "^5.9.3",
|
||||
"hls.js": "^1.6.16",
|
||||
"fast-xml-parser": "^5.10.1",
|
||||
"hls.js": "^1.7.0",
|
||||
"jszip": "^3.10.1",
|
||||
"leaflet": "^1.9.4",
|
||||
"leaflet.offline": "^3.2.1",
|
||||
"mediasoup": "^3.20.9",
|
||||
"mediasoup-client": "^3.21.0",
|
||||
"nuxt": "^4.4.8",
|
||||
"openid-client": "^6.8.4",
|
||||
"mediasoup": "^3.24.2",
|
||||
"mediasoup-client": "^3.22.0",
|
||||
"nuxt": "^4.5.2",
|
||||
"openid-client": "^6.8.5",
|
||||
"qrcode": "^1.5.4",
|
||||
"supercluster": "^9.0.0",
|
||||
"vue": "^3.5.38",
|
||||
"vue-router": "^5.1.0",
|
||||
"ws": "^8.21.0"
|
||||
"vue": "^3.5.41",
|
||||
"vue-router": "^5.2.0",
|
||||
"ws": "^8.21.3"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@iconify-json/tabler": "^1.2.35",
|
||||
"@nuxt/eslint": "^1.16.0",
|
||||
"@nuxt/test-utils": "^4.0.3",
|
||||
"@playwright/test": "^1.61.1",
|
||||
"@vitest/coverage-v8": "^4.1.9",
|
||||
"@iconify-json/tabler": "^1.2.38",
|
||||
"@nuxt/eslint": "^1.17.0",
|
||||
"@nuxt/test-utils": "^4.1.0",
|
||||
"@playwright/test": "^1.62.1",
|
||||
"@vitest/coverage-v8": "^4.1.10",
|
||||
"@vue/test-utils": "^2.4.11",
|
||||
"eslint": "^10.5.0",
|
||||
"happy-dom": "^20.10.6",
|
||||
"vitest": "^4.1.9"
|
||||
"eslint": "^10.8.1",
|
||||
"happy-dom": "^20.11.2",
|
||||
"vitest": "^4.1.10"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -43,16 +43,6 @@ export function removeSessionConnection(sessionId, ws) {
|
||||
}
|
||||
}
|
||||
|
||||
export function broadcastToSession(sessionId, message) {
|
||||
const conns = getSessionConnections(sessionId)
|
||||
const data = JSON.stringify(message)
|
||||
for (const ws of conns) {
|
||||
if (ws.readyState === 1) { // OPEN
|
||||
ws.send(data)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
export default defineNitroPlugin((nitroApp) => {
|
||||
nitroApp.hooks.hook('ready', async () => {
|
||||
const server = nitroApp.h3App.server || nitroApp.h3App.nodeServer
|
||||
|
||||
Reference in New Issue
Block a user