This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@vitest/coverage-v8](https://vitest.dev/guide/coverage) ([source](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8)) | [`4.1.10` → `4.1.11`](https://renovatebot.com/diffs/npm/@vitest%2fcoverage-v8/4.1.10/4.1.11) |  |  | | [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | [`5.10.1` → `5.11.0`](https://renovatebot.com/diffs/npm/fast-xml-parser/5.10.1/5.11.0) |  |  | | [happy-dom](https://github.com/capricorn86/happy-dom) | [`20.11.2` → `20.11.6`](https://renovatebot.com/diffs/npm/happy-dom/20.11.2/20.11.6) |  |  | | [hls.js](https://github.com/video-dev/hls.js) | [`1.7.0` → `1.7.1`](https://renovatebot.com/diffs/npm/hls.js/1.7.0/1.7.1) |  |  | | [mediasoup](https://mediasoup.org) ([source](https://github.com/versatica/mediasoup)) | [`3.24.2` → `3.26.0`](https://renovatebot.com/diffs/npm/mediasoup/3.24.2/3.26.0) |  |  | | [openid-client](https://github.com/panva/openid-client) | [`6.8.5` → `6.8.7`](https://renovatebot.com/diffs/npm/openid-client/6.8.5/6.8.7) |  |  | | [vitest](https://vitest.dev) ([source](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)) | [`4.1.10` → `4.1.11`](https://renovatebot.com/diffs/npm/vitest/4.1.10/4.1.11) |  |  | --- ### Release Notes <details> <summary>vitest-dev/vitest (@​vitest/coverage-v8)</summary> ### [`v4.1.11`](https://github.com/vitest-dev/vitest/releases/tag/v4.1.11) [Compare Source](https://github.com/vitest-dev/vitest/compare/v4.1.10...v4.1.11) ##### 🐞 Bug Fixes - Revive global concurrency limit for test lifecycle \[backport to v4] - by [@​sheremet-va](https://github.com/sheremet-va) and [@​hi-ogawa](https://github.com/hi-ogawa) in [#​10992](https://github.com/vitest-dev/vitest/issues/10992) [<samp>(5146d)</samp>](https://github.com/vitest-dev/vitest/commit/5146df80b) - **browser**: - Encode iframeId in tester iframe URL \[backport to v4] - by [@​sheremet-va](https://github.com/sheremet-va), **Pduhard** and **Claude Opus 4.8** in [#​10955](https://github.com/vitest-dev/vitest/issues/10955) [<samp>(10b2c)</samp>](https://github.com/vitest-dev/vitest/commit/10b2cd201) - Trigger playwright/chromium gc on lower disk availability \[backport to v4] - by [@​hi-ogawa](https://github.com/hi-ogawa), **Hiroshi Ogawa** and **OpenCode** in [#​10951](https://github.com/vitest-dev/vitest/issues/10951) [<samp>(9851d)</samp>](https://github.com/vitest-dev/vitest/commit/9851dbc41) - **mocker**: - Restrict redirect mocks to the fs allowlist \[backport to v4] - by [@​sheremet-va](https://github.com/sheremet-va) in [#​10974](https://github.com/vitest-dev/vitest/issues/10974) [<samp>(fe5a1)</samp>](https://github.com/vitest-dev/vitest/commit/fe5a11d3c) ##### [View changes on GitHub](https://github.com/vitest-dev/vitest/compare/v4.1.10...v4.1.11) </details> <details> <summary>NaturalIntelligence/fast-xml-parser (fast-xml-parser)</summary> ### [`v5.11.0`](https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.11.0) [Compare Source](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0) #### What's Changed - add support for endIndex in node metadata (5.x edition) by [@​Wain-PC](https://github.com/Wain-PC) in [#​850](https://github.com/NaturalIntelligence/fast-xml-parser/pull/850) - fix: don't crash on a closing tag with no matching opening tag by [@​hdimer](https://github.com/hdimer) in [#​861](https://github.com/NaturalIntelligence/fast-xml-parser/pull/861) #### New Contributors - [@​Wain-PC](https://github.com/Wain-PC) made their first contribution in [#​850](https://github.com/NaturalIntelligence/fast-xml-parser/pull/850) - [@​hdimer](https://github.com/hdimer) made their first contribution in [#​861](https://github.com/NaturalIntelligence/fast-xml-parser/pull/861) **Full Changelog**: <https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0> </details> <details> <summary>capricorn86/happy-dom (happy-dom)</summary> ### [`v20.11.6`](https://github.com/capricorn86/happy-dom/releases/tag/v20.11.6) [Compare Source](https://github.com/capricorn86/happy-dom/compare/v20.11.5...v20.11.6) ##### :construction\_worker\_man: Patch fixes - Updates docs for the global-registrator package - By **[@​capricorn86](https://github.com/capricorn86)** in task [#​2300](https://github.com/capricorn86/happy-dom/issues/2300) ### [`v20.11.5`](https://github.com/capricorn86/happy-dom/releases/tag/v20.11.5) [Compare Source](https://github.com/capricorn86/happy-dom/compare/v20.11.4...v20.11.5) ##### :construction\_worker\_man: Patch fixes - Allow explicit element types for querySelector (e.g. `querySelector<HTMLInputElement>(".my-input")`) - By **[@​cyphercodes](https://github.com/cyphercodes)** ### [`v20.11.4`](https://github.com/capricorn86/happy-dom/releases/tag/v20.11.4) [Compare Source](https://github.com/capricorn86/happy-dom/compare/v20.11.3...v20.11.4) ##### :construction\_worker\_man: Patch fixes - Fixes the CORS check `fetch()` to match origins instead of host and protocol - By **[@​rexxars](https://github.com/rexxars)** in task [#​1490](https://github.com/capricorn86/happy-dom/issues/1490) ### [`v20.11.3`](https://github.com/capricorn86/happy-dom/releases/tag/v20.11.3) [Compare Source](https://github.com/capricorn86/happy-dom/compare/v20.11.2...v20.11.3) ##### :construction\_worker\_man: Patch fixes - Make document.links return a live HTMLCollection - By **[@​bangseongbeom](https://github.com/bangseongbeom)** in task [#​2299](https://github.com/capricorn86/happy-dom/issues/2299) - Copy labels array to prevent mutation of cached querySelectorAll result - By **[@​mixelburg](https://github.com/mixelburg)** in task [#​2226](https://github.com/capricorn86/happy-dom/issues/2226) </details> <details> <summary>video-dev/hls.js (hls.js)</summary> ### [`v1.7.1`](https://github.com/video-dev/hls.js/releases/tag/v1.7.1) [Compare Source](https://github.com/video-dev/hls.js/compare/v1.7.0...v1.7.1) ### Summary HLS.js v1.7.1 includes bug fixes and improvements over the previous release. #### Changes Since The Last Release - Fix Interstitial snap-out at live edge and `BUFFER_APPEND_NO_PROGRESS` false positives ([#​7979](https://github.com/video-dev/hls.js/issues/7979)) [@​robwalch](https://github.com/robwalch) - Workaround issue where `ManagedMediaSource` does not emit "startstreaming" when seeking ([#​7984](https://github.com/video-dev/hls.js/issues/7984)) - Fix permanent stall loading fragment-hint parts of encrypted low-latency streams ([#​7976](https://github.com/video-dev/hls.js/issues/7976)) [@​zaki699-blip](https://github.com/zaki699-blip) - Document decode timebase change in MIGRATING ([#​7986](https://github.com/video-dev/hls.js/issues/7986)) [@​robwalch](https://github.com/robwalch) #### Demo Page <https://26ea065a.hls-js-dev.pages.dev/demo/> #### API and Breaking Changes No public exports were removed and no runtime behavior changes are required to upgrade from v1.6 to v1.7. TypeScript consumers might see new compile errors where previously loose types have been narrowed. Each is listed with upgrade guidance in the migration guide: <https://github.com/video-dev/hls.js/blob/v1.7.0/MIGRATING.md#migrating-from-hlsjs-16-to-17> Some exported type dependencies ("eventemitter3", "[@​svta/cml-cmcd](https://github.com/svta/cml-cmcd)", "[@​svta/cml-utils](https://github.com/svta/cml-utils)", "[@​svta/cml-structured-field-values](https://github.com/svta/cml-structured-field-values)") have not been bundled with hls.d.ts. Please file an issue if this is blocking you from upgrading. #### Feedback Please provide feedback via [Issues in GitHub](https://github.com/video-dev/hls.js/issues/new/choose). For more details on how to contribute to HLS.js, see our [CONTRIBUTING guide](https://github.com/video-dev/hls.js/blob/master/CONTRIBUTING.md). </details> <details> <summary>versatica/mediasoup (mediasoup)</summary> ### [`v3.26.0`](https://github.com/versatica/mediasoup/blob/HEAD/CHANGELOG.md#3260) [Compare Source](https://github.com/versatica/mediasoup/compare/3.25.0...3.26.0) - **Breaking change:** Simulcast and SVC: Limit temporal layer to the preferred one ([PR #​1892](https://github.com/versatica/mediasoup/pull/1892)). ### [`v3.25.0`](https://github.com/versatica/mediasoup/blob/HEAD/CHANGELOG.md#3250) [Compare Source](https://github.com/versatica/mediasoup/compare/3.24.2...3.25.0) - Worker: Fix undefined behavior in `RtpStreamRecv::UpdateScore()` when no packets were received ([PR #​1886](https://github.com/versatica/mediasoup/pull/1886)). - SCTP: Fix `SackChunk::GetValidatedGapAckBlocks()` returning a bogus gap-ack-block ([PR #​1891](https://github.com/versatica/mediasoup/pull/1891)). - Do not make generated RTCP Sender Reports depend on RTP packet arrival time ([issue #​1881](https://github.com/versatica/mediasoup/issues/1881)): - `RemoteClockOffsetEstimator` class ([PR #​1882](https://github.com/versatica/mediasoup/pull/1882)). - Prepare `RtpStream` classes for capture time based RTCP Sender Reports ([PR #​1883](https://github.com/versatica/mediasoup/pull/1883), [PR #​1888](https://github.com/versatica/mediasoup/pull/1888)). - `RemoteCaptureTimeEstimator` class ([PR #​1884](https://github.com/versatica/mediasoup/pull/1884)). - Estimate the capture instant of each received RTP packet ([PR #​1885](https://github.com/versatica/mediasoup/pull/1885)). - Generate RTCP Sender Reports based on the capture instant of the media rather than on the packet arrival time ([PR #​1887](https://github.com/versatica/mediasoup/pull/1887)). - `SimulcastProducerStreamManager`: Apply new capture time logic and fix 'abs-capture-time' rewriting ([PR #​1889](https://github.com/versatica/mediasoup/pull/1889)). </details> <details> <summary>panva/openid-client (openid-client)</summary> ### [`v6.8.7`](https://github.com/panva/openid-client/blob/HEAD/CHANGELOG.md#687-2026-08-20) [Compare Source](https://github.com/panva/openid-client/compare/v6.8.6...v6.8.7) ##### Fixes - allow destructuring the claims helper ([38bd8c0](https://github.com/panva/openid-client/commit/38bd8c052a7e1e6d0e2beda14d35fb38b9b26d4c)), references [#​887](https://github.com/panva/openid-client/issues/887) ### [`v6.8.6`](https://github.com/panva/openid-client/blob/HEAD/CHANGELOG.md#686-2026-08-18) [Compare Source](https://github.com/panva/openid-client/compare/v6.8.5...v6.8.6) ##### Fixes - avoid undefined user-agent in fetchProtectedResource ([492c3c3](https://github.com/panva/openid-client/commit/492c3c36aad1ac324661b808b32bc17a35d22665)), references [#​885](https://github.com/panva/openid-client/issues/885) </details> --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMy4yIiwidXBkYXRlZEluVmVyIjoiNDQuMzkuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19--> Reviewed-on: https://git.keligrubb.com/keligrubb/kestrelos/pulls/47 Co-authored-by: Renovate Bot <renovate@keligrubb.com>
KestrelOS
Tactical Operations Center (TOC) for OSINT feeds. Map view with offline-capable tiles and clickable camera/feed sources; click a marker to view the live stream.
Stack
- Nuxt 4, JavaScript, Tailwind CSS, ESLint, Vitest
- Leaflet + leaflet.offline (offline map and OSM tile caching)
- Mediasoup + mediasoup-client (WebRTC live streaming)
- Docker and Helm for deployment
Setup
npm install
npm run dev
Open http://localhost:3000. The app requires login by default; you will see the login page until you sign in.
HTTPS for local dev (camera / geolocation on your phone)
Camera and geolocation in the browser require a secure context (HTTPS) when you open the app from your phone. To test Share live from a device on your LAN without buying a domain or cert:
-
Generate a self-signed cert (once). Use your machine's LAN IP so the phone can use it:
chmod +x scripts/gen-dev-cert.sh ./scripts/gen-dev-cert.sh 192.168.1.123Replace
192.168.1.123with your server's IP. -
Start the dev server (it will use HTTPS if
.dev-certs/exists):npm run dev -
On your phone, open https://192.168.1.123:3000 (same IP you passed above). Accept the browser's "untrusted certificate" warning once (e.g. Advanced → Proceed). Then log in and use Share live; camera and location will work.
Without the certs, npm run dev still runs over HTTP as before.
Note: If you see a warning about NODE_TLS_REJECT_UNAUTHORIZED=0, you can ignore it for local development with self-signed certificates. The server will still work correctly.
WebRTC Live Streaming
The Share live feature uses WebRTC for real-time video streaming from mobile browsers. It requires:
- HTTPS (for camera/geolocation access on mobile)
- Mediasoup server (runs automatically in the Nuxt process)
- mediasoup-client (browser library, included automatically)
Streaming from a phone on your LAN: The server auto-detects your machine's LAN IP (from network interfaces) and uses it for WebRTC. Open https://:3000 on both phone and laptop (same IP as for your dev cert). To override (e.g. Docker or multiple NICs), set MEDIASOUP_ANNOUNCED_IP. Ensure firewall allows UDP/TCP ports 40000-49999 on the server.
See docs/live-streaming.md for setup and usage.
ATAK / CoT (Cursor on Target)
KestrelOS can act as a TAK Server so ATAK and iTAK devices connect and share positions. No plugins: in ATAK, add a Server connection (host = KestrelOS, port 8089 for CoT). Check Use Authentication and enter your KestrelOS username and password (local users use their login password; OIDC users must set an ATAK password once under Account in the web app). Devices relay CoT to each other (team members see each other on the ATAK map) and appear on the KestrelOS web map; they drop off after ~90 seconds if no updates. CoT runs on port 8089 (default).
Scripts
npm run dev- development servernpm run build- production buildnpm run test- run testsnpm run test:coverage- run tests with coverage (85% threshold)npm run test:e2e- Playwright E2E testsnpm run lint- ESLint (zero warnings)
Documentation
Full docs are in the docs/ directory: installation (npm, Docker, Helm), authentication (local login, OIDC), map and cameras (adding IPTV, ALPR, CCTV, NVR, etc.), ATAK and iTAK, and Share live (mobile device as live camera).
Configuration
- Devices: Manage cameras/devices via the API (
/api/devices); see Map and cameras. Each device needsname,device_type,lat,lng,stream_url, andsource_type(mjpegorhls). - Environment: No required env vars for basic run. For production, set
HOST=0.0.0.0and expose ports 3000 (web/API) and 8089 (CoT). For TLS use.dev-certs/or setCOT_SSL_CERTandCOT_SSL_KEY. - Authentication: The login page always offers password sign-in (local). Optionally set
BOOTSTRAP_EMAILandBOOTSTRAP_PASSWORDbefore the first run to create the first admin; otherwise a default admin is created and its credentials are printed in the terminal. To also show an OIDC sign-in button, configureOIDC_ISSUER,OIDC_CLIENT_ID,OIDC_CLIENT_SECRET, and optionallyOIDC_LABEL,OIDC_REDIRECT_URI. See docs/auth.md for local login, OIDC config, and sign up. - Bootstrap admin (when using local auth): The server initializes the database and runs bootstrap at startup. On first run (no users in the database), it creates the first admin. If you set
BOOTSTRAP_EMAILandBOOTSTRAP_PASSWORDbefore starting, that account is created. If you don't set them, a default admin is created (identifier:admin) with a random password and the credentials are printed in the terminal-copy them and sign in at/login, then change the password or add users via Members. Use Members to change roles (admin, leader, member). Only admins can change roles; admins and leaders can edit POIs. - Database: SQLite file at
data/kestrelos.db(created automatically). Contains users, sessions, and POIs.
Docker
docker build -t kestrelos:latest .
docker run -p 3000:3000 -p 8089:8089 kestrelos:latest
Kubernetes (Helm)
From Gitea registry:
helm repo add keligrubb --username YOUR_USER --password YOUR_TOKEN https://git.keligrubb.com/api/packages/keligrubb/helm
helm repo update
helm install kestrelos keligrubb/kestrelos
From source:
helm install kestrelos ./helm/kestrelos
Health: GET /health (overview), GET /health/live (liveness), GET /health/ready (readiness). Probes are configured in the Helm chart. Optional: enable Ingress in helm/kestrelos/values.yaml.
Releases
Merges to main trigger a semver release. Use one of these prefixes in your PR title to set the version bump:
major:- breaking changesminor:- new featurespatch:- bug fixes, docs (default if no prefix)
Example: minor: Add map layer toggle
Security
- Device data is validated server-side; only valid entries are returned.
- Stream URLs are sanitized to
http://orhttps://only; other protocols are rejected.
License
MIT
