Compare commits

...
4 Commits
Author SHA1 Message Date
CI 068f82c0ff release v1.1.11 [skip ci] 2026-08-19 02:11:32 +00:00
Keli GrubbandMadison Grubb 1f45cc152a refactor(websocket): remove unused broadcastToSession export (#45)
Push / release (push) Successful in 11s
Push / publish (push) Successful in 32s
## Removed

- `broadcastToSession` from `server/plugins/websocket.js` — an exported but never-imported, never-called dead-code function. Its dependencies (`getSessionConnections`, `addSessionConnection`, `removeSessionConnection`) are retained since they remain actively used for per-session connection tracking within the plugin.

## Notes

- Full repository search confirms zero remaining references to `broadcastToSession`.
- ESLint passes; full test suite passes (50 files, 406 tests).

Closes #40

---------

Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #45
2026-08-19 02:11:19 +00:00
CI be95b6864b release v1.1.10 [skip ci] 2026-08-14 22:27:50 +00:00
Keli GrubbandMadison Grubb cfac12b699 chore(deps): update dependencies and fix security vulnerabilities (#44)
Push / release (push) Successful in 12s
Push / publish (push) Successful in 37s
## Summary

Updates all out-of-date dependencies and applies `npm audit fix` to resolve 14 security vulnerabilities (3 critical, 8 high).

### Dependency Updates

| Package | Current → Latest |
|---|---|
| `nuxt` | 4.4.8 → 4.5.2 |
| `mediasoup` | 3.20.9 → 3.24.2 |
| `mediasoup-client` | 3.21.0 → 3.22.0 |
| `hls.js` | 1.6.16 → 1.7.0 |
| `vue` | 3.5.38 → 3.5.41 |
| `vue-router` | 5.1.0 → 5.2.0 |
| `@nuxt/icon` | 2.2.3 → 2.5.0 |
| `eslint` | 10.5.0 → 10.8.1 |
| `vitest` / `@vitest/coverage-v8` | 4.1.9 → 4.1.10 |
| `ws` | 8.21.0 → 8.21.3 |
| `openid-client` | 6.8.4 → 6.8.5 |
| `fast-xml-parser` | 5.9.3 → 5.10.1 |
| `happy-dom` | 20.10.6 → 20.11.2 |
| `@playwright/test` | 1.61.1 → 1.62.1 |
| `@nuxt/eslint` | 1.16.0 → 1.17.0 |
| `@nuxt/test-utils` | 4.0.3 → 4.1.0 |
| `@iconify-json/tabler` | 1.2.35 → 1.2.38 |

### Security Audit Fixes (`npm audit fix`)

- **`@nuxt/devtools`** (critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's host
- **`tar`** (critical): Multiple process-crash/DoS vulnerabilities via crafted tar archives
- **`esbuild`** (high): Arbitrary file read when running dev server on Windows
- **`brace-expansion`** (high): Multiple DoS vectors (memory exhaustion, process hang)
- **`flatted`** (high): Prototype pollution via `parse()`
- **`svgo`** (high): `removeScripts` plugin leaves executable scripts intact

### Verification

- All 406 tests pass (3 skipped)
- Lint clean (`eslint . --max-warnings 0`)
- `npm audit` reports 0 vulnerabilities

---------

Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #44
2026-08-14 22:27:36 +00:00
8 changed files with 2591 additions and 3792 deletions
+1 -1
View File
@@ -41,7 +41,7 @@ jobs:
e2e: e2e:
runs-on: ubuntu-latest runs-on: ubuntu-latest
container: container:
image: mcr.microsoft.com/playwright:v1.61.1-noble image: mcr.microsoft.com/playwright:v1.62.1-noble
steps: steps:
- uses: https://git.keligrubb.com/actions/checkout@v7 - uses: https://git.keligrubb.com/actions/checkout@v7
+1 -1
View File
@@ -1 +1 @@
setups.@nuxt/test-utils="4.0.3" setups.@nuxt/test-utils="4.1.0"
+60
View File
@@ -1,3 +1,63 @@
## [1.1.11] - 2026-08-19
### Changed
- remove unused broadcastToSession export (#45)
## Removed
- `broadcastToSession` from `server/plugins/websocket.js` — an exported but never-imported, never-called dead-code function. Its dependencies (`getSessionConnections`, `addSessionConnection`, `removeSessionConnection`) are retained since they remain actively used for per-session connection tracking within the plugin.
## Notes
- Full repository search confirms zero remaining references to `broadcastToSession`.
- ESLint passes; full test suite passes (50 files, 406 tests).
Closes #40
## [1.1.10] - 2026-08-14
### Changed
- update dependencies and fix security vulnerabilities (#44)
## Summary
Updates all out-of-date dependencies and applies `npm audit fix` to resolve 14 security vulnerabilities (3 critical, 8 high).
### Dependency Updates
| Package | Current → Latest |
|---|---|
| `nuxt` | 4.4.8 → 4.5.2 |
| `mediasoup` | 3.20.9 → 3.24.2 |
| `mediasoup-client` | 3.21.0 → 3.22.0 |
| `hls.js` | 1.6.16 → 1.7.0 |
| `vue` | 3.5.38 → 3.5.41 |
| `vue-router` | 5.1.0 → 5.2.0 |
| `@nuxt/icon` | 2.2.3 → 2.5.0 |
| `eslint` | 10.5.0 → 10.8.1 |
| `vitest` / `@vitest/coverage-v8` | 4.1.9 → 4.1.10 |
| `ws` | 8.21.0 → 8.21.3 |
| `openid-client` | 6.8.4 → 6.8.5 |
| `fast-xml-parser` | 5.9.3 → 5.10.1 |
| `happy-dom` | 20.10.6 → 20.11.2 |
| `@playwright/test` | 1.61.1 → 1.62.1 |
| `@nuxt/eslint` | 1.16.0 → 1.17.0 |
| `@nuxt/test-utils` | 4.0.3 → 4.1.0 |
| `@iconify-json/tabler` | 1.2.35 → 1.2.38 |
### Security Audit Fixes (`npm audit fix`)
- **`@nuxt/devtools`** (critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's host
- **`tar`** (critical): Multiple process-crash/DoS vulnerabilities via crafted tar archives
- **`esbuild`** (high): Arbitrary file read when running dev server on Windows
- **`brace-expansion`** (high): Multiple DoS vectors (memory exhaustion, process hang)
- **`flatted`** (high): Prototype pollution via `parse()`
- **`svgo`** (high): `removeScripts` plugin leaves executable scripts intact
### Verification
- All 406 tests pass (3 skipped)
- Lint clean (`eslint . --max-warnings 0`)
- `npm audit` reports 0 vulnerabilities
## [1.1.9] - 2026-08-13 ## [1.1.9] - 2026-08-13
### Changed ### Changed
- update dependency fast-xml-parser to v5.10.1 [security] (#42) - update dependency fast-xml-parser to v5.10.1 [security] (#42)
+2 -2
View File
@@ -2,5 +2,5 @@ apiVersion: v2
name: kestrelos name: kestrelos
description: KestrelOS TOC for OSINT feeds - map, camera feeds, offline tiles description: KestrelOS TOC for OSINT feeds - map, camera feeds, offline tiles
type: application type: application
version: 1.1.9 version: 1.1.11
appVersion: "1.1.9" appVersion: "1.1.11"
+1 -1
View File
@@ -2,7 +2,7 @@ replicaCount: 1
image: image:
repository: git.keligrubb.com/keligrubb/kestrelos repository: git.keligrubb.com/keligrubb/kestrelos
tag: 1.1.9 tag: 1.1.11
pullPolicy: IfNotPresent pullPolicy: IfNotPresent
service: service:
+2507 -3758
View File
File diff suppressed because it is too large Load Diff
+19 -19
View File
@@ -1,6 +1,6 @@
{ {
"name": "kestrelos", "name": "kestrelos",
"version": "1.1.9", "version": "1.1.11",
"private": true, "private": true,
"type": "module", "type": "module",
"scripts": { "scripts": {
@@ -20,32 +20,32 @@
"import:alpr": "node scripts/import-alpr.js" "import:alpr": "node scripts/import-alpr.js"
}, },
"dependencies": { "dependencies": {
"@nuxt/icon": "^2.2.3", "@nuxt/icon": "^2.5.0",
"@nuxtjs/tailwindcss": "^6.14.0", "@nuxtjs/tailwindcss": "^6.14.0",
"fast-xml-parser": "^5.9.3", "fast-xml-parser": "^5.10.1",
"hls.js": "^1.6.16", "hls.js": "^1.7.0",
"jszip": "^3.10.1", "jszip": "^3.10.1",
"leaflet": "^1.9.4", "leaflet": "^1.9.4",
"leaflet.offline": "^3.2.1", "leaflet.offline": "^3.2.1",
"mediasoup": "^3.20.9", "mediasoup": "^3.24.2",
"mediasoup-client": "^3.21.0", "mediasoup-client": "^3.22.0",
"nuxt": "^4.4.8", "nuxt": "^4.5.2",
"openid-client": "^6.8.4", "openid-client": "^6.8.5",
"qrcode": "^1.5.4", "qrcode": "^1.5.4",
"supercluster": "^9.0.0", "supercluster": "^9.0.0",
"vue": "^3.5.38", "vue": "^3.5.41",
"vue-router": "^5.1.0", "vue-router": "^5.2.0",
"ws": "^8.21.0" "ws": "^8.21.3"
}, },
"devDependencies": { "devDependencies": {
"@iconify-json/tabler": "^1.2.35", "@iconify-json/tabler": "^1.2.38",
"@nuxt/eslint": "^1.16.0", "@nuxt/eslint": "^1.17.0",
"@nuxt/test-utils": "^4.0.3", "@nuxt/test-utils": "^4.1.0",
"@playwright/test": "^1.61.1", "@playwright/test": "^1.62.1",
"@vitest/coverage-v8": "^4.1.9", "@vitest/coverage-v8": "^4.1.10",
"@vue/test-utils": "^2.4.11", "@vue/test-utils": "^2.4.11",
"eslint": "^10.5.0", "eslint": "^10.8.1",
"happy-dom": "^20.10.6", "happy-dom": "^20.11.2",
"vitest": "^4.1.9" "vitest": "^4.1.10"
} }
} }
-10
View File
@@ -43,16 +43,6 @@ export function removeSessionConnection(sessionId, ws) {
} }
} }
export function broadcastToSession(sessionId, message) {
const conns = getSessionConnections(sessionId)
const data = JSON.stringify(message)
for (const ws of conns) {
if (ws.readyState === 1) { // OPEN
ws.send(data)
}
}
}
export default defineNitroPlugin((nitroApp) => { export default defineNitroPlugin((nitroApp) => {
nitroApp.hooks.hook('ready', async () => { nitroApp.hooks.hook('ready', async () => {
const server = nitroApp.h3App.server || nitroApp.h3App.nodeServer const server = nitroApp.h3App.server || nitroApp.h3App.nodeServer