github-actions[bot]
82adcd1f71
chore(beta): release 3.29.0-beta.0
2026-04-23 14:54:21 +00:00
github-actions[bot]
89f86b9fe4
chore(beta): release 3.28.3-beta.0
2026-04-13 05:30:51 +00:00
github-actions[bot]
0a5b07de5d
chore(beta): release 3.28.2-beta.0
2026-04-12 18:58:40 +00:00
github-actions[bot]
623ab72916
chore(beta): release 3.28.1-beta.0
2026-04-12 08:06:08 +00:00
github-actions[bot]
c303dd51e8
chore(beta): release 3.28.0-beta.0
2026-04-11 21:24:41 +00:00
github-actions[bot]
95d8bc4065
chore(beta): release 3.27.0-beta.0
2026-04-11 06:29:51 +00:00
github-actions[bot]
b0efd32f7a
chore(beta): release 3.26.2-beta.0
2026-04-11 06:26:39 +00:00
github-actions[bot]
1f3b9c6712
chore(beta): release 3.26.1-beta.0
2026-04-09 14:27:12 +00:00
github-actions[bot]
ad64005a80
chore(beta): release 3.26.0-beta.0
2026-04-09 13:11:41 +00:00
github-actions[bot]
97b1ae5b03
chore(beta): release 3.25.0-beta.0
2026-04-08 09:51:27 +00:00
Paul Nothaft
83868ffe2f
security: fix 20 dependency vulnerabilities (11 error, 7 warning, 2 note)
...
Update direct dependencies and overrides to address GitHub code scanning alerts:
- handlebars 4.7.8 -> 4.7.9 (5 CVEs: RCE, DoS, XSS, code execution)
- nodemailer 7.0.12 -> 7.0.13 (SMTP command injection)
- tar 7.5.11 -> 7.5.13 override (symlink/hardlink path traversal)
- fast-xml-parser >=5.3.8 -> >=5.5.10 override (entity expansion bypass)
- brace-expansion >=5.0.0 -> >=5.0.5 override (DoS via zero step)
- path-to-regexp 0.1.12 -> 0.1.13 override (ReDoS via malformed URL params)
- lodash 4.17.23 -> >=4.18.1 override (prototype pollution, code execution)
The picomatch CVEs are in npm's own node_modules inside the Docker image
and do not affect application code.
2026-04-08 09:04:06 +02:00
Paul Nothaft
9ddd50f7e4
Merge pull request #266 from the-luap/security/pin-axios-version
...
security: pin axios to 1.14.0 — supply chain attack prevention
2026-04-05 18:40:47 +02:00
Paul Nothaft
bec36fc99f
security: pin axios to 1.14.0 to prevent supply chain attack
...
Axios versions 1.14.1 and 0.30.4 were compromised on March 31, 2026
with a RAT dropper (plain-crypto-js) attributed to North Korean threat
actor UNC1069/Sapphire Sleet. The malicious versions have been removed
from npm but our ^1.12.2 range could have pulled 1.14.1 on next install.
Pin to exact version 1.14.0 (latest safe release) in both frontend and
backend package.json and lock files to prevent any future resolution to
compromised versions.
References:
- https://github.com/axios/axios/issues/10604
- https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/
2026-04-05 18:40:24 +02:00
github-actions[bot]
8614c2232c
chore(beta): release 3.24.1-beta.0
2026-04-05 16:34:26 +00:00
github-actions[bot]
2b7c9b0138
chore(beta): release 3.24.0-beta.0
2026-04-04 21:33:29 +00:00
github-actions[bot]
0a7a89045b
chore(beta): release 3.23.0-beta.0
2026-04-04 20:13:49 +00:00
github-actions[bot]
85a4eb90fd
chore(beta): release 3.22.0-beta.0
2026-03-25 21:36:31 +00:00
github-actions[bot]
2ac6c51fe5
chore(beta): release 3.21.1-beta.0 ( #255 )
...
Build and Push Docker Images / build-backend (push) Failing after 3m42s
Build and Push Docker Images / build-frontend (push) Failing after 3m41s
Build and Push Docker Images / summary (push) Successful in 3s
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-22 12:43:55 +01:00
github-actions[bot]
a63f1a8dd9
chore(beta): release 3.21.0-beta.0 ( #253 )
...
Build and Push Docker Images / build-backend (push) Failing after 3m46s
Build and Push Docker Images / build-frontend (push) Failing after 3m47s
Build and Push Docker Images / summary (push) Successful in 2s
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-18 10:59:14 +01:00
github-actions[bot]
3742d71535
chore(beta): release 3.20.1-beta.0 ( #250 )
...
Build and Push Docker Images / build-backend (push) Failing after 3m46s
Build and Push Docker Images / build-frontend (push) Failing after 3m46s
Build and Push Docker Images / summary (push) Successful in 3s
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-17 17:18:56 +01:00
github-actions[bot]
f9889a93fb
chore(beta): release 3.20.0-beta.0
2026-03-17 12:05:29 +00:00
github-actions[bot]
f5997892c4
chore(beta): release 3.19.2-beta.0
2026-03-16 21:35:09 +00:00
github-actions[bot]
2618415aa1
chore(beta): release 3.19.1-beta.0
2026-03-16 21:23:14 +00:00
github-actions[bot]
1468c459ba
chore(beta): release 3.19.0-beta.0
2026-03-16 16:24:01 +00:00
github-actions[bot]
431a82eca1
chore(beta): release 3.18.2-beta.0
2026-03-16 15:26:11 +00:00
Paul Nothaft
85a07fcca7
Merge pull request #237 from the-luap/fix/security-dep-updates
...
fix: resolve code scanning security alerts (multer, tar, Node 22)
2026-03-16 16:25:52 +01:00
Paul Nothaft
1f524f2358
fix: update dependencies to resolve code scanning security alerts
...
- Upgrade multer to 2.1.1 (CVE-2026-3520, DoS via malformed requests)
- Update tar override to >=7.5.11 (CVE-2026-31802, CVE-2026-29786)
- Upgrade Node base image from 20-alpine to 22-alpine to fix npm
bundled tar/minimatch CVEs in the Docker image
2026-03-16 16:25:29 +01:00
github-actions[bot]
c652ae0ead
chore(beta): release 3.18.1-beta.0
2026-03-16 14:01:13 +00:00
github-actions[bot]
74c9a5fbcd
chore(beta): release 3.18.0-beta.0
2026-03-16 08:38:17 +00:00
github-actions[bot]
d2663bff81
chore(beta): release 3.17.2-beta.0
2026-03-11 19:48:06 +00:00
github-actions[bot]
0c98c6b453
chore(beta): release 3.17.1-beta.0
2026-03-08 14:42:28 +00:00
github-actions[bot]
7d967a47ae
chore(beta): release 3.17.0-beta.0
2026-03-05 21:21:48 +00:00
github-actions[bot]
98fd6dd8e1
chore(beta): release 3.16.0-beta.0
2026-03-05 20:38:56 +00:00
github-actions[bot]
a1d941f049
chore(beta): release 3.15.3-beta.0
2026-03-02 22:18:06 +00:00
Paul Nothaft
c0301dcbf4
Merge branch 'beta' into fix/github-issues-194-197-main
2026-03-02 23:15:37 +01:00
Paul Nothaft
cbecb9323c
fix(security): resolve Docker image CVEs for code scanning alerts
...
- Upgrade nginx base from 1.27-alpine to 1.28-alpine (Alpine 3.23, OpenSSL 3.5.5)
- Upgrade npm to latest in backend production stage to fix tar, minimatch, brace-expansion CVEs
- Add brace-expansion and minimatch overrides for app-level transitive deps
- Remove incompatible body-parser v2 override (breaks Express 4 JSON parsing)
- Remove npm upgrade from builder stages (npm 11 breaks npm ci with existing lockfile)
2026-03-02 23:06:15 +01:00
Paul Nothaft
4272618b3f
fix(security): resolve all npm audit vulnerabilities
...
Frontend (6 → 0 vulnerabilities):
- axios: update to fix DoS via __proto__ key in mergeConfig (CVE-2026-25639)
- swiper: update to fix prototype pollution (critical)
- rollup: update to fix arbitrary file write via path traversal
- minimatch: update to fix multiple ReDoS vulnerabilities
- ajv: update to fix ReDoS with $data option
- markdown-it: update to fix ReDoS
Backend (32 → 0 vulnerabilities):
- multer: update to fix DoS via incomplete cleanup and resource exhaustion
- minimatch: update to fix multiple ReDoS vulnerabilities
- Add npm overrides for transitive dependencies:
- fast-xml-parser >=5.3.8 (fixes XSS, DoS, stack overflow via AWS SDK)
- qs >=6.14.2 (fixes arrayLimit bypass DoS via Express)
- tar >=7.5.8 (fixes path traversal and hardlink attacks via sqlite3)
Docker:
- Pin nginx base image to 1.27-alpine in Dockerfile.prod
- Update security comments in backend Dockerfile
- Existing apk upgrade --no-cache ensures OpenSSL/libexpat CVEs are
patched at build time (OpenSSL 3.5.5, Alpine 3.23.3)
2026-03-02 10:36:47 +01:00
github-actions[bot]
3e0c4fd73e
chore(beta): release 3.15.2-beta.0
2026-02-22 21:37:26 +00:00
github-actions[bot]
f672c1daa6
chore(main): release 2.5.0
2026-02-21 19:48:43 +00:00
Paul Nothaft
888c4ab209
Merge main into beta for release/beta-to-main
...
Resolved conflicts in CHANGELOG.md, backend/package.json, and
frontend/package.json. Version set to 3.15.1.
2026-02-21 20:43:46 +01:00
github-actions[bot]
9045402c9a
chore(beta): release 3.15.1-beta.0
2026-02-21 19:31:37 +00:00
github-actions[bot]
fe9486e5fa
chore(beta): release 3.15.0-beta.0
2026-02-17 19:47:41 +00:00
github-actions[bot]
6613f1b088
chore(beta): release 3.14.0-beta.0
2026-02-17 14:38:14 +00:00
Paul Nothaft
3ea9d5b121
Merge pull request #185 from the-luap/feat/new-features
...
feat: original filename in admin UI, update dialog, and security hardening
2026-02-17 15:37:56 +01:00
Paul Nothaft
50c09904a9
feat: add update instructions dialog, email notifications, and capture date sorting
...
- Add Update Instructions Dialog with environment-specific commands (Docker/Git/Standalone)
- Add email notification settings for new version alerts
- Add "Sort by Capture Date" option using EXIF metadata extraction
- Fix E2E tests by loading environment variables via dotenv
- Add test-images/ and backend/*.db to .gitignore
Closes #181
2026-02-16 16:23:57 +01:00
github-actions[bot]
d239857d9a
chore(beta): release 3.13.1-beta.0
2026-02-15 21:49:34 +00:00
github-actions[bot]
edf3a43950
chore(beta): release 3.13.0-beta.0
2026-02-06 23:35:55 +00:00
github-actions[bot]
2c35543e73
chore(beta): release 3.12.0-beta.0
2026-02-06 22:29:57 +00:00
github-actions[bot]
e05fd64760
chore(beta): release 3.11.0-beta.0
2026-02-06 20:46:15 +00:00
github-actions[bot]
10ff6b118c
chore(beta): release 3.10.1-beta.0
2026-02-03 16:25:51 +00:00