From d27c85de4527a6dd7792a17dc13263a58b2e94b0 Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 22 Mar 2026 14:22:49 +0100 Subject: [PATCH 1/9] Fix ruff format for user_notifications and spoolman --- backend/app/api/routes/user_notifications.py | 8 ++------ backend/app/services/spoolman.py | 1 + 2 files changed, 3 insertions(+), 6 deletions(-) diff --git a/backend/app/api/routes/user_notifications.py b/backend/app/api/routes/user_notifications.py index ec34ae1cf..91b425ee1 100644 --- a/backend/app/api/routes/user_notifications.py +++ b/backend/app/api/routes/user_notifications.py @@ -36,9 +36,7 @@ async def get_user_email_preferences( notify_print_stopped=True, ) - result = await db.execute( - select(UserEmailPreference).where(UserEmailPreference.user_id == current_user.id) - ) + result = await db.execute(select(UserEmailPreference).where(UserEmailPreference.user_id == current_user.id)) pref = result.scalar_one_or_none() if pref is None: @@ -72,9 +70,7 @@ async def update_user_email_preferences( detail="User must have an email address to receive notifications", ) - result = await db.execute( - select(UserEmailPreference).where(UserEmailPreference.user_id == current_user.id) - ) + result = await db.execute(select(UserEmailPreference).where(UserEmailPreference.user_id == current_user.id)) pref = result.scalar_one_or_none() if pref is None: diff --git a/backend/app/services/spoolman.py b/backend/app/services/spoolman.py index e89d884d2..b878bb5aa 100644 --- a/backend/app/services/spoolman.py +++ b/backend/app/services/spoolman.py @@ -11,6 +11,7 @@ logger = logging.getLogger(__name__) BAMBU_RFID_TAG_LENGTH = 32 + @dataclass class SpoolmanSpool: """Represents a spool in Spoolman.""" From df6926c00265fa8e7199dab75a9700c53c9d3751 Mon Sep 17 00:00:00 2001 From: Vladyslav Biletskyi <67331054+vlad-bil@users.noreply.github.com> Date: Wed, 25 Mar 2026 09:12:46 +0200 Subject: [PATCH 2/9] extend currencies with Ukrainian Hryvnia (#801) extend currencies with Ukrainian Hryvnia (#801) --- frontend/src/__tests__/utils/currency.test.ts | 8 ++++++-- frontend/src/utils/currency.ts | 1 + 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/frontend/src/__tests__/utils/currency.test.ts b/frontend/src/__tests__/utils/currency.test.ts index 7e3d9715b..387c39839 100644 --- a/frontend/src/__tests__/utils/currency.test.ts +++ b/frontend/src/__tests__/utils/currency.test.ts @@ -26,6 +26,10 @@ describe('getCurrencySymbol', () => { expect(getCurrencySymbol('MYR')).toBe('RM'); }); + it('returns ₴ for UAH', () => { + expect(getCurrencySymbol('UAH')).toBe('₴'); + }); + it('returns the code itself for unknown currencies', () => { expect(getCurrencySymbol('XYZ')).toBe('XYZ'); }); @@ -45,7 +49,7 @@ describe('SUPPORTED_CURRENCIES', () => { expect(SUPPORTED_CURRENCIES.find((c) => c.code === 'MYR')).toBeDefined(); }); - it('has 28 entries', () => { - expect(SUPPORTED_CURRENCIES).toHaveLength(28); + it('has 29 entries', () => { + expect(SUPPORTED_CURRENCIES).toHaveLength(29); }); }); diff --git a/frontend/src/utils/currency.ts b/frontend/src/utils/currency.ts index 8315015b8..ab3d87e38 100644 --- a/frontend/src/utils/currency.ts +++ b/frontend/src/utils/currency.ts @@ -27,6 +27,7 @@ const CURRENCY_SYMBOLS: Record = { RUB: '₽', HUF: 'Ft', ILS: '₪', + UAH: '₴', }; export function getCurrencySymbol(currencyCode: string): string { From d1f86efc60fd7b2060c7fb1b96905f79c73f2f23 Mon Sep 17 00:00:00 2001 From: maziggy Date: Wed, 25 Mar 2026 08:15:07 +0100 Subject: [PATCH 3/9] Revert "extend currencies with Ukrainian Hryvnia (#801)" This reverts commit df6926c00265fa8e7199dab75a9700c53c9d3751. --- frontend/src/__tests__/utils/currency.test.ts | 8 ++------ frontend/src/utils/currency.ts | 1 - 2 files changed, 2 insertions(+), 7 deletions(-) diff --git a/frontend/src/__tests__/utils/currency.test.ts b/frontend/src/__tests__/utils/currency.test.ts index 387c39839..7e3d9715b 100644 --- a/frontend/src/__tests__/utils/currency.test.ts +++ b/frontend/src/__tests__/utils/currency.test.ts @@ -26,10 +26,6 @@ describe('getCurrencySymbol', () => { expect(getCurrencySymbol('MYR')).toBe('RM'); }); - it('returns ₴ for UAH', () => { - expect(getCurrencySymbol('UAH')).toBe('₴'); - }); - it('returns the code itself for unknown currencies', () => { expect(getCurrencySymbol('XYZ')).toBe('XYZ'); }); @@ -49,7 +45,7 @@ describe('SUPPORTED_CURRENCIES', () => { expect(SUPPORTED_CURRENCIES.find((c) => c.code === 'MYR')).toBeDefined(); }); - it('has 29 entries', () => { - expect(SUPPORTED_CURRENCIES).toHaveLength(29); + it('has 28 entries', () => { + expect(SUPPORTED_CURRENCIES).toHaveLength(28); }); }); diff --git a/frontend/src/utils/currency.ts b/frontend/src/utils/currency.ts index ab3d87e38..8315015b8 100644 --- a/frontend/src/utils/currency.ts +++ b/frontend/src/utils/currency.ts @@ -27,7 +27,6 @@ const CURRENCY_SYMBOLS: Record = { RUB: '₽', HUF: 'Ft', ILS: '₪', - UAH: '₴', }; export function getCurrencySymbol(currencyCode: string): string { From b824b39bd5e0c22f8418d9f5fbfbbb3ce0220167 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 26 Mar 2026 13:37:56 +0100 Subject: [PATCH 4/9] Bump picomatch in /frontend in the npm_and_yarn group across 1 directory (#821) Bumps the npm_and_yarn group with 1 update in the /frontend directory: [picomatch](https://github.com/micromatch/picomatch). Updates `picomatch` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](https://github.com/micromatch/picomatch/compare/4.0.3...4.0.4) --- updated-dependencies: - dependency-name: picomatch dependency-version: 4.0.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- frontend/package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/frontend/package-lock.json b/frontend/package-lock.json index ee9148845..f5bac5c7a 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -6429,9 +6429,9 @@ "license": "ISC" }, "node_modules/picomatch": { - "version": "4.0.3", - "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.3.tgz", - "integrity": "sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q==", + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-4.0.4.tgz", + "integrity": "sha512-QP88BAKvMam/3NxH6vj2o21R6MjxZUAd6nlwAS/pnGvN9IVLocLHxGYIzFhg6fUQ+5th6P4dv4eW9jX3DSIj7A==", "dev": true, "license": "MIT", "engines": { From a699270c7ad366416c4f7f82ab4f6f9b61c6cc99 Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 26 Mar 2026 13:52:52 +0100 Subject: [PATCH 5/9] Changed pipeline --- .github/workflows/security.yml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 01aea0df6..5ab7eef78 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -130,8 +130,10 @@ jobs: - name: Run pip-audit id: pip-audit run: | - pip-audit --desc on --format json --output pip-audit-results.json || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT - pip-audit --desc on || true + # CVE-2026-4539: low-severity ReDoS in Pygments AdlLexer (indirect dep via mkdocs-material/pytest/rich). + # No fix available yet. Remove --ignore-vuln once Pygments releases a patched version. + pip-audit --desc on --format json --output pip-audit-results.json --ignore-vuln CVE-2026-4539 || echo "vulnerabilities_found=true" >> $GITHUB_OUTPUT + pip-audit --desc on --ignore-vuln CVE-2026-4539 || true - name: Upload audit results if: always() From 329be09fd98cb54fe393ccfe67e9abe4bc4a397b Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 26 Mar 2026 14:01:41 +0100 Subject: [PATCH 6/9] Housekeeping --- .gitignore | 2 ++ backend/app/core/config.py | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/.gitignore b/.gitignore index f69f69a60..dd255c27d 100644 --- a/.gitignore +++ b/.gitignore @@ -68,3 +68,5 @@ data/ *.sarif debug_logs/ + +spoolbuddy/ssh/ diff --git a/backend/app/core/config.py b/backend/app/core/config.py index 68673b2ea..1b13d3c90 100644 --- a/backend/app/core/config.py +++ b/backend/app/core/config.py @@ -4,7 +4,7 @@ from pathlib import Path from pydantic_settings import BaseSettings -# Application version - single source of truth +# Application version - single source of truth. APP_VERSION = "0.2.2.1" GITHUB_REPO = "maziggy/bambuddy" BUG_REPORT_RELAY_URL = os.environ.get("BUG_REPORT_RELAY_URL", "https://bambuddy.cool/api/bug-report") From 258642f3b7dface3fb1743bdbd98322d278cc103 Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 26 Mar 2026 14:04:31 +0100 Subject: [PATCH 7/9] Housekeeping --- .gitignore | 1 + 1 file changed, 1 insertion(+) diff --git a/.gitignore b/.gitignore index dd255c27d..354617221 100644 --- a/.gitignore +++ b/.gitignore @@ -69,4 +69,5 @@ data/ debug_logs/ +# SSH keys Spoolbuddy spoolbuddy/ssh/ From da2be65abd30b3252383bb33e4e4b8d02fa8801c Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 26 Mar 2026 14:08:10 +0100 Subject: [PATCH 8/9] Housekeeping --- .github/workflows/ci.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ba25a2620..fe2d68a79 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -69,7 +69,10 @@ jobs: pip install pip-audit - name: Run pip-audit - run: pip-audit --desc on + run: | + # CVE-2026-4539: low-severity ReDoS in Pygments AdlLexer (indirect dep via mkdocs-material/pytest/rich). + # No fix available yet. Remove --ignore-vuln once Pygments releases a patched version. + pip-audit --desc on --ignore-vuln CVE-2026-4539 backend-tests: name: Backend Tests From 8270030687eeb6e86e37213595e550faeb0b8d6d Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 26 Mar 2026 14:20:11 +0100 Subject: [PATCH 9/9] Housekeeping --- .github/workflows/security.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 5ab7eef78..0f09619b3 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -8,6 +8,7 @@ on: paths: - 'backend/**' - 'frontend/**' + - 'spoolbuddy/**' - 'Dockerfile' - 'docker-compose*.yml' - 'requirements.txt' @@ -17,6 +18,7 @@ on: paths: - 'backend/**' - 'frontend/**' + - 'spoolbuddy/**' - 'Dockerfile' - 'docker-compose*.yml' - 'requirements.txt'