mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
* fix(docker): build the server image with Go 1.26 The Docker verify job failed with "go.mod requires go >= 1.26 (running go 1.25.12; GOTOOLCHAIN=local)". The Go 1.26 upgrade bumped go.mod but left the Dockerfile on golang:1.25-bookworm, and GOTOOLCHAIN=local in the base image means it cannot download a newer toolchain. golang:1.26-bookworm confirmed present upstream. Not verified locally (Docker Desktop not running); the CI Docker job proves it on this PR. * fix(client): override brace-expansion and qs to patched versions npm audit --audit-level=high failed the Client Static Checks job with 10 vulnerabilities (8 high, 2 moderate). npm audit fix could not resolve any of them. There is really only one advisory behind the eight high findings: brace-expansion <=5.0.7, a DoS via unbounded expansion length causing OOM. minimatch, glob, test-exclude, @vitest/coverage-v8, eslint and @eslint/* were all just transitive consumers of it, and those top-level dev deps are already at their latest versions, so no bump reaches the fix. qs 6.11.1-6.15.1 is a second, independent advisory arriving via @stryker-mutator/core -> typed-rest-client. No patch exists inside the brace-expansion 1.x or 2.x lines (the fix landed in 5.0.8), so overrides are the only route. Collapsing every copy to 5.0.9 risked breaking minimatch 3.x, which requires it as CJS, so the whole client gate was run to check: npm audit 0 vulnerabilities, tsc clean, oxlint unchanged (pre-existing no-underscore-dangle warnings only), eslint exit 0, prettier clean, and vitest 3572 tests across 129 files all passing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * ci: stop running the suite twice for one push to dev Listing dev under both push and pull_request meant a single push to dev fired both events, running every job twice (visible as duplicated checks on #1274). While a dev -> main PR is open, pull_request(synchronize) already covers each push to dev, so dev only needs the pull_request trigger. workflow_dispatch covers a dev branch with no PR open yet. * chore(deps): roll up the seven open dependabot PRs Consolidates #1267-#1273 onto this branch so they land as one CI run instead of seven, each of which was triggering the full suite including tauri-build. - google.golang.org/grpc 1.81.1 -> 1.82.1 (#1267) - github.com/google/cel-go 0.28.1 -> 0.29.0 (#1268) - defu 6.1.4 -> 6.1.7, root lockfile (#1269) - tauri 2.11.0 -> 2.11.1 (#1270) - @modelcontextprotocol/sdk 1.29 -> 1.30 (#1271) - tar 0.4.45 -> 0.4.46 (#1272) - serde_with 3.18.0 -> 3.21.0 (#1273) Applied by regenerating each lockfile from its manifest rather than merging seven lockfile diffs. Verified: go build across all four tag variants, go vet, govulncheck (0 vulnerabilities in called code), go test -race (14 packages, 0 failures), cargo clippy --all-targets -D warnings, cargo test --lib (73 passed). CI covers neither the root package.json nor tools/mcp-introspect, so those two were checked by hand: changelogen still runs under defu 6.1.7 (release.yml depends on it) and the introspect server still imports the 1.30 SDK. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(ci): drop the brace-expansion override, scope the audit to shipped deps The brace-expansion override I added to clear npm audit broke Client Unit Tests in CI: TypeError: (0 , brace_expansion_1.default) is not a function at minimatch braceExpand -> TestExclude.glob -> V8CoverageProvider.getUntestedFiles minimatch requires brace-expansion as CJS and v5 is not callable that way. It only fires under --coverage, which is why a local `vitest run` missed it; CI runs `vitest run --coverage`. Verified the fix with that exact command. There is no patched brace-expansion in the 1.x/2.x lines those tools pin (the fix landed in 5.0.8), and eslint, @vitest/coverage-v8 and stryker are already latest, so no bump reaches it. Since the whole chain is dev tooling that never ships, the gate is now `npm audit --omit=dev --audit-level=high`, which reports 0 vulnerabilities. The reasoning and the revisit condition are recorded in ci.yml next to the step. The qs override stays: qs is CJS, the override is proven safe, and it closes a real advisory. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(client): route all cert-tofu emits through the single call site Tauri Full Build failed on all three platforms with the generated bindings redeclaring onCertTofu (TS2323/TS2393), which killed `tauri build` at its beforeBuildCommand: src/generated/events.ts(36,23): error TS2323: Cannot redeclare exported variable 'onCertTofu'. tauri-typegen emits one onCertTofu binding per `emit("cert-tofu", ..)` call site it finds. ws_proxy.rs already funnelled its emits through a helper for exactly this reason -- its doc comment says so -- but http_proxy.rs emitted directly from all three TOFU outcomes, so the crate had four call sites. Makes ws_proxy::emit_cert_tofu pub(crate) and routes http_proxy's trusted, first_use and mismatch paths through it, leaving one call site crate-wide. The now-unused Emitter import is dropped from http_proxy so clippy -D warnings stays clean. Behaviour is unchanged: same event name, same payloads, same order. Not reproducible locally -- typegen only regenerates under CI's clean checkout, and a full `npm run tauri build` here passes tsc either way -- so the Tauri Full Build job on this PR is the proof. Verified locally: exactly one emit("cert-tofu") call site remains, cargo clippy --all-targets -D warnings clean, and the release build completes through bundling. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
146 lines
6.5 KiB
AMPL
146 lines
6.5 KiB
AMPL
module github.com/owncord/server
|
|
|
|
go 1.26
|
|
|
|
require (
|
|
aead.dev/minisign v0.3.0
|
|
github.com/BurntSushi/toml v1.6.0
|
|
github.com/coder/websocket v1.8.15
|
|
github.com/corazawaf/coraza/v3 v3.6.0
|
|
github.com/go-chi/chi/v5 v5.3.1
|
|
github.com/google/uuid v1.6.0
|
|
github.com/knadh/koanf/parsers/yaml v1.1.0
|
|
github.com/knadh/koanf/providers/env v1.1.0
|
|
github.com/knadh/koanf/providers/file v1.2.1
|
|
github.com/knadh/koanf/providers/structs v1.0.0
|
|
github.com/knadh/koanf/v2 v2.3.5
|
|
github.com/livekit/protocol v1.50.4
|
|
github.com/livekit/server-sdk-go/v2 v2.18.1
|
|
github.com/microcosm-cc/bluemonday v1.0.27
|
|
github.com/prometheus/client_golang v1.24.1
|
|
github.com/sasha-s/go-deadlock v0.3.9
|
|
github.com/tetratelabs/wazero v1.12.0
|
|
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0
|
|
go.opentelemetry.io/otel v1.44.0
|
|
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0
|
|
go.opentelemetry.io/otel/exporters/prometheus v0.66.0
|
|
go.opentelemetry.io/otel/metric v1.44.0
|
|
go.opentelemetry.io/otel/sdk v1.44.0
|
|
go.opentelemetry.io/otel/sdk/metric v1.44.0
|
|
go.opentelemetry.io/otel/trace v1.44.0
|
|
go.uber.org/goleak v1.3.0
|
|
go.yaml.in/yaml/v3 v3.0.5
|
|
golang.org/x/crypto v0.54.0
|
|
golang.org/x/mod v0.38.0
|
|
golang.org/x/sync v0.22.0
|
|
google.golang.org/protobuf v1.36.11
|
|
modernc.org/sqlite v1.54.0
|
|
)
|
|
|
|
require (
|
|
buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go v1.36.11-20260415201107-50325440f8f2.1 // indirect
|
|
buf.build/go/protovalidate v1.2.0 // indirect
|
|
buf.build/go/protoyaml v0.7.0 // indirect
|
|
cel.dev/expr v0.25.2 // indirect
|
|
github.com/antlr4-go/antlr/v4 v4.13.1 // indirect
|
|
github.com/aymerick/douceur v0.2.0 // indirect
|
|
github.com/benbjohnson/clock v1.3.5 // indirect
|
|
github.com/beorn7/perks v1.0.1 // indirect
|
|
github.com/bep/debounce v1.2.1 // indirect
|
|
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
|
|
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
|
github.com/corazawaf/libinjection-go v0.3.2 // indirect
|
|
github.com/dennwc/iters v1.2.2 // indirect
|
|
github.com/dustin/go-humanize v1.0.1 // indirect
|
|
github.com/fatih/structs v1.1.0 // indirect
|
|
github.com/felixge/httpsnoop v1.0.4 // indirect
|
|
github.com/frostbyte73/core v0.1.1 // indirect
|
|
github.com/fsnotify/fsnotify v1.10.1 // indirect
|
|
github.com/gammazero/deque v1.2.1 // indirect
|
|
github.com/go-logr/logr v1.4.3 // indirect
|
|
github.com/go-logr/stdr v1.2.2 // indirect
|
|
github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
|
|
github.com/goccy/go-json v0.10.5 // indirect
|
|
github.com/goccy/go-yaml v1.18.0 // indirect
|
|
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
|
|
github.com/google/cel-go v0.29.0 // indirect
|
|
github.com/gorilla/css v1.0.1 // indirect
|
|
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
|
|
github.com/gotnospirit/makeplural v0.0.0-20180622080156-a5f48d94d976 // indirect
|
|
github.com/gotnospirit/messageformat v0.0.0-20221001023931-dfe49f1eb092 // indirect
|
|
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 // indirect
|
|
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
|
|
github.com/hashicorp/go-retryablehttp v0.7.8 // indirect
|
|
github.com/jxskiss/base62 v1.1.0 // indirect
|
|
github.com/kaptinlin/go-i18n v0.1.4 // indirect
|
|
github.com/kaptinlin/jsonschema v0.4.6 // indirect
|
|
github.com/klauspost/compress v1.19.1 // indirect
|
|
github.com/klauspost/cpuid/v2 v2.3.0 // indirect
|
|
github.com/knadh/koanf/maps v0.1.2 // indirect
|
|
github.com/lithammer/shortuuid/v4 v4.2.0 // indirect
|
|
github.com/livekit/mageutil v0.0.0-20250511045019-0f1ff63f7731 // indirect
|
|
github.com/livekit/mediatransportutil v0.0.0-20260605212259-862d4a7bcb1e // indirect
|
|
github.com/livekit/psrpc v0.7.2 // indirect
|
|
github.com/magefile/mage v1.17.2 // indirect
|
|
github.com/mattn/go-isatty v0.0.20 // indirect
|
|
github.com/mitchellh/copystructure v1.2.0 // indirect
|
|
github.com/mitchellh/reflectwalk v1.0.2 // indirect
|
|
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
|
|
github.com/nats-io/nats.go v1.52.0 // indirect
|
|
github.com/nats-io/nkeys v0.4.16 // indirect
|
|
github.com/nats-io/nuid v1.0.1 // indirect
|
|
github.com/ncruces/go-strftime v1.0.0 // indirect
|
|
github.com/petar-dambovaliev/aho-corasick v0.0.0-20250424160509-463d218d4745 // indirect
|
|
github.com/petermattis/goid v0.0.0-20250813065127-a731cc31b4fe // indirect
|
|
github.com/pion/datachannel v1.6.0 // indirect
|
|
github.com/pion/dtls/v3 v3.1.4 // indirect
|
|
github.com/pion/ice/v4 v4.2.7 // indirect
|
|
github.com/pion/interceptor v0.1.45 // indirect
|
|
github.com/pion/logging v0.2.4 // indirect
|
|
github.com/pion/mdns/v2 v2.1.0 // indirect
|
|
github.com/pion/randutil v0.1.0 // indirect
|
|
github.com/pion/rtcp v1.2.16 // indirect
|
|
github.com/pion/rtp v1.10.2 // indirect
|
|
github.com/pion/sctp v1.10.0 // indirect
|
|
github.com/pion/sdp/v3 v3.0.19 // indirect
|
|
github.com/pion/srtp/v3 v3.0.11 // indirect
|
|
github.com/pion/stun/v3 v3.1.5 // indirect
|
|
github.com/pion/transport/v4 v4.0.2 // indirect
|
|
github.com/pion/turn/v5 v5.0.9 // indirect
|
|
github.com/pion/webrtc/v4 v4.2.15 // indirect
|
|
github.com/prometheus/client_model v0.6.2 // indirect
|
|
github.com/prometheus/common v0.70.1 // indirect
|
|
github.com/prometheus/otlptranslator v1.0.0 // indirect
|
|
github.com/prometheus/procfs v0.21.1 // indirect
|
|
github.com/puzpuzpuz/xsync/v4 v4.5.0 // indirect
|
|
github.com/redis/go-redis/v9 v9.20.0 // indirect
|
|
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
|
github.com/tidwall/gjson v1.18.0 // indirect
|
|
github.com/tidwall/match v1.1.1 // indirect
|
|
github.com/tidwall/pretty v1.2.1 // indirect
|
|
github.com/twitchtv/twirp v8.1.3+incompatible // indirect
|
|
github.com/valllabh/ocsf-schema-golang v1.0.3 // indirect
|
|
github.com/wlynxg/anet v0.0.5 // indirect
|
|
github.com/zeebo/xxh3 v1.1.0 // indirect
|
|
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
|
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 // indirect
|
|
go.opentelemetry.io/proto/otlp v1.10.0 // indirect
|
|
go.uber.org/atomic v1.11.0 // indirect
|
|
go.uber.org/multierr v1.11.0 // indirect
|
|
go.uber.org/zap v1.28.0 // indirect
|
|
go.uber.org/zap/exp v0.3.0 // indirect
|
|
golang.org/x/exp v0.0.0-20260603202125-055de637280b // indirect
|
|
golang.org/x/net v0.57.0 // indirect
|
|
golang.org/x/sys v0.47.0 // indirect
|
|
golang.org/x/text v0.40.0 // indirect
|
|
golang.org/x/time v0.15.0 // indirect
|
|
google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa // indirect
|
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa // indirect
|
|
google.golang.org/grpc v1.82.1 // indirect
|
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
|
modernc.org/libc v1.74.1 // indirect
|
|
modernc.org/mathutil v1.7.1 // indirect
|
|
modernc.org/memory v1.11.0 // indirect
|
|
rsc.io/binaryregexp v0.2.0 // indirect
|
|
)
|