Merge branch 'security-updates-form-data-multer' into main
Mirror to GitHub / mirror (push) Successful in 31s
Test and Lint / backend-test (push) Successful in 1m26s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m9s
Version and Release / version-bump (push) Successful in 43s
Version and Release / trigger-drone (push) Successful in 3s

Upgrades npm packages for improved security and stability:
- 8 packages upgraded across backend and frontend
- 0 npm audit vulnerabilities maintained
- All upgrades tested and production-ready
This commit is contained in:
2025-07-22 11:15:47 +02:00
5 changed files with 1082 additions and 752 deletions
+589 -296
View File
File diff suppressed because it is too large Load Diff
+7 -7
View File
@@ -21,17 +21,17 @@
"adm-zip": "^0.5.16",
"archiver": "^5.3.1",
"axios": "^1.10.0",
"bcrypt": "^5.1.0",
"chokidar": "^3.5.3",
"bcrypt": "6.0.0",
"chokidar": "4.0.3",
"cors": "^2.8.5",
"dotenv": "^16.0.3",
"express": "^4.18.2",
"express-rate-limit": "^6.7.0",
"express-validator": "^7.0.1",
"form-data": "^4.0.3",
"form-data": "^4.0.4",
"handlebars": "^4.7.8",
"helmet": "^7.0.0",
"i18next": "^25.3.1",
"i18next": "25.3.2",
"i18next-browser-languagedetector": "^8.2.0",
"i18next-http-backend": "^3.0.2",
"joi": "^17.9.1",
@@ -39,12 +39,12 @@
"jsonwebtoken": "^9.0.0",
"knex": "^2.4.2",
"mime-types": "^3.0.1",
"multer": "^2.0.1",
"multer": "^2.0.2",
"node-cron": "^3.0.2",
"nodemailer": "^6.9.1",
"nodemailer": "7.0.5",
"pg": "^8.16.3",
"react-i18next": "^15.6.0",
"sharp": "^0.32.0",
"sharp": "0.34.3",
"sqlite3": "^5.1.6",
"uuid": "^11.1.0",
"winston": "^3.8.2",
+438 -446
View File
File diff suppressed because it is too large Load Diff
+3 -3
View File
@@ -25,7 +25,7 @@
"@types/react-google-recaptcha": "^2.1.9",
"axios": "^1.3.2",
"clsx": "^2.0.0",
"date-fns": "^2.29.3",
"date-fns": "4.1.0",
"dompurify": "^3.2.6",
"i18next": "^25.3.1",
"i18next-browser-languagedetector": "^8.2.0",
@@ -33,7 +33,7 @@
"js-cookie": "^3.0.5",
"lodash": "^4.17.21",
"lowlight": "^2.9.0",
"lucide-react": "^0.292.0",
"lucide-react": "0.525.0",
"react": "^18.3.1",
"react-countdown": "^2.3.5",
"react-dom": "^18.3.1",
@@ -42,7 +42,7 @@
"react-image-gallery": "^1.2.11",
"react-intersection-observer": "^9.4.3",
"react-router-dom": "^6.8.0",
"react-toastify": "^9.1.1",
"react-toastify": "11.0.5",
"tailwind-merge": "^3.3.1"
},
"devDependencies": {
+45
View File
@@ -0,0 +1,45 @@
# Package Upgrade Summary - Production System
Date: 2025-07-22
## ✅ Successfully Upgraded (8 packages)
### Phase 1 (Low Risk):
**Backend:**
- i18next: 25.3.1 → 25.3.2
- bcrypt: 5.1.1 → 6.0.0
- nodemailer: 6.10.1 → 7.0.5
**Frontend:**
- date-fns: 2.30.0 → 4.1.0
- lucide-react: 0.292.0 → 0.525.0
### Phase 2 (Medium Risk - Carefully Tested):
**Backend:**
- sharp: 0.32.6 → 0.34.3
- chokidar: 3.6.0 → 4.0.3
**Frontend:**
- react-toastify: 9.1.3 → 11.0.5
## 🚫 Deferred Upgrades (High Risk)
### Critical Bug Found:
- **archiver**: MUST stay at 5.3.2 (v7 has append() bug that breaks watermarks)
### Major Breaking Changes:
- express 4 → 5
- knex 2 → 3
- React 18 → 19
- tailwindcss 3 → 4
## Security Status
- **npm audit vulnerabilities: 0** ✅
- All upgraded packages tested and working
- No known security issues in current packages
## Backup Locations
- Phase 1: `/backups/phase1-upgrade-20250722-103923/`
- Phase 2: `/backups/phase2-upgrade-20250722-104940/`
## Production Ready
All upgrades have been tested and are ready for production deployment. Monitor closely for 48 hours after deployment.