feat: update dependencies - #2028
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughThis PR upgrades dependencies across the monorepo, adds pnpm audit post-processing, replaces private IP detection, and updates frontend sanitization, generated typings, component behavior, and test environment setup. ChangesBackend dependency and audit tooling
Private IP detection
Frontend package compatibility and component updates
Estimated code review effort: 4 (Complex) | ~60 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
`@api/src/unraid-api/graph/resolvers/unraid-plugins/unraid-plugins.service.spec.ts`:
- Around line 170-175: Replace the mock ConfigService object creation that uses
the `as unknown as ConfigService` casting pattern with the `vi.spyOn()` approach
to maintain type safety and avoid unsafe casting. The current pattern at the
configService initialization violates type safety guidelines. Instead of
creating a mock object and casting it, use the spy approach demonstrated in the
existing test setup to properly mock the ConfigService without bypassing
TypeScript's type checking. Apply this fix consistently wherever this pattern
appears in the test file.
In `@scripts/pnpm-audit.mjs`:
- Around line 9-13: The spawnSync call for the pnpm audit command in the audit
function does not specify an explicit maxBuffer option, which defaults to 1 MB
and can be exceeded by large audit payloads, causing stdout truncation and
JSON.parse failures. Add a maxBuffer property to the options object passed to
spawnSync with a significantly larger value (such as 10 MB or higher) to
accommodate large audit output without truncation.
In `@unraid-ui/package.json`:
- Line 89: The devDependencies for ajv has been upgraded to 8.20.0, but the
peerDependencies.ajv is still pinned to 8.17.1, creating a version mismatch.
Update the peerDependencies.ajv version from 8.17.1 to 8.20.0 to align with the
upgraded devDependencies version and match what is being consumed in
web/package.json.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: 869d8a80-ee9e-4352-9190-bb46f85b2e2b
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (11)
api/package.jsonapi/src/unraid-api/graph/resolvers/unraid-plugins/unraid-plugins.service.spec.tspackage.jsonpackages/unraid-api-plugin-connect/package.jsonpackages/unraid-api-plugin-generator/package.jsonpackages/unraid-api-plugin-health/package.jsonpackages/unraid-shared/package.jsonplugin/package.jsonscripts/pnpm-audit.mjsunraid-ui/package.jsonweb/package.json
58b6f3b to
a421619
Compare
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
a421619 to
0baec05
Compare
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #2028 +/- ##
==========================================
+ Coverage 52.77% 52.90% +0.12%
==========================================
Files 1035 1035
Lines 72060 72088 +28
Branches 8303 8313 +10
==========================================
+ Hits 38031 38135 +104
+ Misses 33903 33826 -77
- Partials 126 127 +1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
This plugin has been deployed to Cloudflare R2 and is available for testing. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0baec05c03
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "Codex (@codex) review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "Codex (@codex) address that feedback".
| updateVulnerabilityMetadata(report); | ||
|
|
||
| process.stdout.write(`${JSON.stringify(report, null, 2)}\n`); | ||
| process.exitCode = Object.keys(report.advisories ?? {}).length === 0 ? 0 : (audit.status ?? 1); |
There was a problem hiding this comment.
Preserve audit failures for registry errors
When pnpm audit --json returns a JSON error object instead of an advisory list, this line treats the missing advisories object as empty and exits 0. I reproduced this with the current registry 403 response: node scripts/pnpm-audit.mjs printed ERR_PNPM_AUDIT_BAD_RESPONSE but returned success; pnpm audit --help documents --ignore-registry-errors as the option that should make registry errors exit 0, so without that flag CI will now pass even though the audit did not complete.
Useful? React with 👍 / 👎.
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@unraid-ui/src/components/common/accordion/Accordion.vue`:
- Around line 33-35: The watcher that handles `modelValue` changes currently
blocks `undefined` values with an `if (val !== undefined)` guard check,
preventing the parent from clearing or resetting the internal `openValue` state
in controlled mode. Remove or adjust the guard condition that skips `undefined`
values so that when `modelValue` is set to `undefined`, it properly propagates
to `openValue` to maintain controlled sync semantics. Apply the same fix to any
other watchers or handlers in the Accordion component that have similar guard
conditions blocking `undefined` (mentioned as also applying to the 52-55 range).
In `@unraid-ui/vite.config.ts`:
- Around line 33-36: Fix the vite-plugin-dts configuration in vite.config.ts to
match the v5.0.2 API. Change the property outDirs (which is an array) to the
singular property outDir with a string value of 'dist'. Additionally, replace
the bundleTypes object structure (containing the non-existent bundledPackages
property) with a boolean value of false, or remove the bundleTypes configuration
entirely since false is the default in this API version.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: bcb965b8-33c9-4b8a-98ba-201fdefdc943
⛔ Files ignored due to path filters (2)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yamlweb/__test__/helpers/__snapshots__/markdown.test.ts.snapis excluded by!**/*.snap
📒 Files selected for processing (32)
AGENTS.mdapi/package.jsonapi/src/unraid-api/graph/resolvers/unraid-plugins/unraid-plugins.service.spec.tspackage.jsonpackages/unraid-api-plugin-connect/package.jsonpackages/unraid-api-plugin-generator/package.jsonpackages/unraid-api-plugin-health/package.jsonpackages/unraid-shared/package.jsonplugin/package.jsonscripts/pnpm-audit.mjsunraid-ui/package.jsonunraid-ui/src/components/common/accordion/Accordion.vueunraid-ui/vite.config.tsweb/__test__/components/Logs/SingleLogViewer.test.tsweb/__test__/components/SsoButton.test.tsweb/__test__/helpers/markdown.test.tsweb/__test__/setup.tsweb/__test__/store/callbackActions.test.tsweb/auto-imports.d.tsweb/components.d.tsweb/package.jsonweb/src/components/Common/ResizableSlideover.vueweb/src/components/Docker/DockerContainerManagement.vueweb/src/components/Onboarding/components/InternalBootConfirmDialog.vueweb/src/composables/gql/graphql.tsweb/src/composables/useContentHighlighting.tsweb/src/composables/useContextMenu.tsweb/src/composables/useDockerRowActions.tsweb/src/helpers/markdown.tsweb/src/store/callbackActions.tsweb/vitest.config.tsweb/vitest.setup.ts
💤 Files with no reviewable changes (1)
- AGENTS.md
✅ Files skipped from review due to trivial changes (8)
- web/src/helpers/markdown.ts
- web/src/components/Docker/DockerContainerManagement.vue
- web/src/composables/useContentHighlighting.ts
- web/test/store/callbackActions.test.ts
- packages/unraid-api-plugin-generator/package.json
- web/components.d.ts
- web/src/composables/gql/graphql.ts
- web/auto-imports.d.ts
🚧 Files skipped from review as they are similar to previous changes (10)
- plugin/package.json
- api/src/unraid-api/graph/resolvers/unraid-plugins/unraid-plugins.service.spec.ts
- packages/unraid-api-plugin-health/package.json
- packages/unraid-api-plugin-connect/package.json
- package.json
- packages/unraid-shared/package.json
- unraid-ui/package.json
- api/package.json
- scripts/pnpm-audit.mjs
- web/package.json
| outDirs: ['dist'], | ||
| bundleTypes: { | ||
| bundledPackages: [], | ||
| }, |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Check vite-plugin-dts version and verify API compatibility
cat unraid-ui/package.json | jq -r '.devDependencies["vite-plugin-dts"]'
# Search for other vite-plugin-dts usage patterns
rg -nC3 'vite-plugin-dts|from.*dts' unraid-ui/Repository: unraid/api
Length of output: 863
🏁 Script executed:
cat -n unraid-ui/vite.config.ts | head -50Repository: unraid/api
Length of output: 1921
🌐 Web query:
vite-plugin-dts 5.0.2 API configuration outDirs bundleTypes
💡 Result:
In vite-plugin-dts, there are no specific configuration options named outDirs or bundleTypes [1][2]. It appears these may be confused with other settings or older plugin versions: Regarding bundling types: The functionality to bundle all type declaration files into a single file is controlled by the rollupTypes option, not bundleTypes [1][2]. When set to true, the plugin uses @microsoft/api-extractor to perform the bundling [1][2]. Example usage: import dts from 'vite-plugin-dts'; export default defineConfig({ plugins: [dts({ rollupTypes: true })], }); Regarding output directories: The plugin does not provide an outDirs option. The output directory for declaration files is generally determined by your Vite build configuration (typically build.outDir) and the plugin's default behavior of following your source file structure [3][1]. If you need to restrict output, the plugin provides a strictOutput option (default: true), which ensures that generated declaration files remain within the configured outDir [2].
Citations:
- 1: https://app.unpkg.com/vite-plugin-dts@4.5.3/files/README.md
- 2: https://unpkg.com/vite-plugin-dts@4.2.1/README.md
- 3: https://www.npmjs.com/package/vite-plugin-dts
🌐 Web query:
vite-plugin-dts 5.0.2 changelog release notes
💡 Result:
vite-plugin-dts version 5.0.2 was released on June 1, 2026 [1][2][3]. As of the 5.x major release, the project has evolved into unplugin-dts [4]. While vite-plugin-dts remains available as a package, it is now maintained within the unplugin-dts repository [1][4]. The 5.0.2 update includes the following key changes: Bug Fixes: - Re-emits declarations when non-type files change during watch mode [5][6]. - Fixes a getResolvedModule error that occurred when bundling dts files outside of the src directory [5][6]. - Adds a.js extension to synthetic entry imports to support nodenext module resolution [5][6]. Additional Changes: - Version 5.0.2 also includes an internal update to bump the minimum Node.js requirement to version 20 or higher [3]. For users migrating or seeking the most versatile version of the plugin, the author recommends transitioning to the unplugin-dts package, which supports Vite, Rollup, Rolldown, Webpack, Rspack, and Esbuild [4].
Citations:
- 1: https://github.com/qmhc/unplugin-dts/blob/main/packages/vite-plugin-dts/CHANGELOG.md
- 2: https://www.npmjs.com/package/vite-plugin-dts
- 3: chore(deps): Bump vite-plugin-dts from 5.0.1 to 5.0.2 herokwon/framix#252
- 4: https://github.com/qmhc/unplugin-dts
- 5: https://npmx.dev/package-changelog/vite-plugin-dts/v/5.0.2
- 6: https://github.com/qmhc/unplugin-dts/releases/tag/unplugin-dts%401.0.2
🌐 Web query:
site:github.com vite-plugin-dts v5.0.2 API options
💡 Result:
In vite-plugin-dts version 5.x, the plugin core was migrated to unplugin-dts [1][2]. A primary breaking change in this version is the renaming of the rollupTypes option to bundleTypes [1]. Key API options for vite-plugin-dts v5.0.2 include: bundleTypes: A boolean (default: false) that enables type bundling. When set to true, it utilizes @microsoft/api-extractor to merge all declaration files into a single file [3]. tsconfigPath: A string used to specify the path to your tsconfig.json file. The plugin uses this to resolve include and exclude patterns [3][4]. outDir: Specifies the output directory for generated declaration files. This can be a string, an array of strings, or an object/array of objects to control module formats (e.g., { dir: 'dist', moduleFormat: 'esm' }) [4][5]. entryRoot: Overrides the root path of entry files, which is particularly useful in monorepo structures [4][5]. strictOutput: A boolean (default: true) that, when enabled, ignores generated declaration files that fall outside the specified outDir [4][5]. processor: Specifies the processing mode, accepting either 'ts' or 'vue' [4][5]. compilerOptions: Allows overriding TypeScript compilerOptions [4][5]. resolvers: An array for specifying custom resolvers [4][5]. For migration from version 4.x, note that the rollupTypes option has been removed in favor of bundleTypes [1]. Additionally, ensure that your project dependencies align with the updated requirements, as v5+ often requires peer dependencies like @microsoft/api-extractor and rollup [1].
Citations:
- 1: complexdatacollective/network-canvas-monorepo@73441ea
- 2: qmhc/unplugin-dts@2996858
- 3: https://github.com/qmhc/unplugin-dts/blob/main/docs/en/usage.md
- 4: https://github.com/qmhc/vite-plugin-dts
- 5: https://github.com/qmhc/unplugin-dts/tree/vite-plugin-dts%405.0.0
Fix vite-plugin-dts configuration for v5.0.2 API.
In vite-plugin-dts v5.0.2, bundleTypes is a boolean (not an object), and the option is outDir (singular, not outDirs). The current configuration is invalid:
outDirs: ['dist']should beoutDir: 'dist'bundleTypes: { bundledPackages: [] }should bebundleTypes: false(or omitted, since false is the default)
The bundledPackages property does not exist in this API version.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@unraid-ui/vite.config.ts` around lines 33 - 36, Fix the vite-plugin-dts
configuration in vite.config.ts to match the v5.0.2 API. Change the property
outDirs (which is an array) to the singular property outDir with a string value
of 'dist'. Additionally, replace the bundleTypes object structure (containing
the non-existent bundledPackages property) with a boolean value of false, or
remove the bundleTypes configuration entirely since false is the default in this
API version.
- pnpm-audit: set explicit maxBuffer and preserve registry/audit errors - unraid-ui: align peerDependencies ajv to 8.20.0 - unraid-ui: propagate undefined modelValue in Accordion controlled sync - api: replace unsafe ConfigService casts with vi.spyOn in plugins spec
|
Addressed the outstanding review feedback and rebased onto latest Fixed
Not changed (false positive)
Validation
|
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
Resolve all 27 open advisories (0 remaining on `pnpm run audit --prod`): - overrides: axios 1.18.1, js-yaml 4.3.0, tar 7.5.20, brace-expansion 1.x->1.1.16 and 3.x-5.x->5.0.7; add body-parser 2.3.0, protobufjs 7.6.5 - bump direct deps: undici 7.27.2->7.28.0 (api, shared, connect), dompurify 3.4.10->3.4.12 (web, unraid-ui)
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
Add an Audit Dependencies job to CI - Main (API) that runs `pnpm run audit --prod` (repo audit wrapper) on every PR and push to main, failing the build when unignored advisories are present.
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
Address AI review findings on the new audit gate: - pnpm-audit: fail closed (non-zero exit) when pnpm returns an unrecognized report shape, instead of treating a missing advisories key as zero advisories and exiting 0 - main.yml: scope the Audit Dependencies job to contents: read instead of inheriting the workflow's contents/pull-requests write tokens
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
| function isRecognizedAuditReport(report) { | ||
| return ( | ||
| typeof report === 'object' && | ||
| report !== null && |
build:release builds production node_modules with npm from api/package.json, which did not include the root pnpm.overrides where the CVE remediation lives. The shipped artifact therefore resolved vulnerable transitives (e.g. axios 0.26.1, 18 npm advisories) even though the pnpm audit gate reported 0. Merge the root pnpm.overrides into the generated production package.json so the npm-built release resolves the same patched versions the audit validates (npm honors the name@range key syntax). Verified: axios -> 1.18.1 and npm audit drops from 18 to 1 (the remaining ip advisory has no upstream fix and is already ignored via pnpm.auditConfig).
The ip package (CVE-2024-29415, SSRF in isPublic) is unmaintained with no patched release, and was only used for ip.isPrivate() in cloud.service's DNS check. Replace it with a small net.BlockList-based isPrivateIp helper (Node built-in, zero deps) and add unit tests. Drop the ip and @types/ip deps from both api (dead dep) and the connect plugin, and remove the now-unnecessary CVE-2024-29415 audit ignore. Repo audit is clean (0 advisories) without it.
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/main.yml:
- Around line 172-173: Update the actions/checkout step to set
persist-credentials to false, ensuring the checkout action does not retain the
GitHub token in local git configuration.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: ccf7645a-4299-4af9-bed3-4d0674cde943
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (9)
.github/workflows/main.ymlapi/package.jsonapi/scripts/build.tspackage.jsonpackages/unraid-api-plugin-connect/package.jsonpackages/unraid-api-plugin-connect/src/__test__/is-private-ip.test.tspackages/unraid-api-plugin-connect/src/connection-status/cloud.service.tspackages/unraid-api-plugin-connect/src/connection-status/is-private-ip.tsscripts/pnpm-audit.mjs
💤 Files with no reviewable changes (3)
- package.json
- api/package.json
- packages/unraid-api-plugin-connect/package.json
🚧 Files skipped from review as they are similar to previous changes (1)
- scripts/pnpm-audit.mjs
| - name: Checkout repo | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
Set persist-credentials: false for actions/checkout.
Leaving persist-credentials at its default (true) leaves the GitHub token in the local git configuration. To reduce the risk of credential exfiltration—especially when evaluating third-party dependencies—explicitly disable this.
🔒️ Proposed fix
- name: Checkout repo
uses: actions/checkout@v6
+ with:
+ persist-credentials: false📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - name: Checkout repo | |
| uses: actions/checkout@v6 | |
| - name: Checkout repo | |
| uses: actions/checkout@v6 | |
| with: | |
| persist-credentials: false |
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 172-173: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/main.yml around lines 172 - 173, Update the
actions/checkout step to set persist-credentials to false, ensuring the checkout
action does not retain the GitHub token in local git configuration.
Source: Linters/SAST tools
The Audit Dependencies job skips pnpm install (pnpm audit reads the lockfile), so setup-node's cache: 'pnpm' post-step failed with a path-validation error trying to save a nonexistent store, marking the otherwise-passing job failed. Remove the cache since there is nothing to cache.
|
🚀 Storybook has been deployed to staging: https://unraid-ui-storybook-staging.unraid-workers.workers.dev |
🔄 PR Merged - Plugin Redirected to StagingThis PR has been merged and the preview plugin has been updated to redirect to the staging version. For users testing this PR:
Staging URL: Thank you for testing! 🚀 |
🤖 I have created a release *beep* *boop* --- ## [4.36.0](v4.35.1...v4.36.0) (2026-07-21) ### Features * add docker restart mutation ([#2022](#2022)) ([b58120c](b58120c)) * update dependencies ([#2028](#2028)) ([1c8522d](1c8522d)) ### Bug Fixes * **ci:** publish PR plugin after unrelated failures ([#2046](#2046)) ([a2b0833](a2b0833)) * **ci:** resolve PR number for fork PR plugin uploads ([#2040](#2040)) ([a086778](a086778)) * **ui:** smooth notification drawer slide-in/out ([#2038](#2038)) ([66e86fe](66e86fe)) * **web:** send CSRF token on fetch-based webGUI requests ([#2039](#2039)) ([8cb15f1](8cb15f1)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Summary
pnpm-lock.yaml.ipandlodash-es.Validation
pnpm run --silent audit --prodpnpm --filter ./api type-checkpnpm --filter ./api testNotes
ipadvisory is ignored through repo audit policy because npm reports no patched version.pnpm audit --prodstill leaves a stale action for that ignored advisory; use the repo audit script for CI/user checks.Summary by CodeRabbit