17 Commits
Author SHA1 Message Date
maziggy 3dcbbdd25e Housekeeping 2026-07-24 12:07:29 +02:00
maziggy 59a649ac57 Merge branch 'main' into release/1.2.5 2026-07-24 11:47:51 +02:00
maziggy 8afc9b2d19 Housekeeping 2026-07-22 15:45:59 +02:00
maziggy 3372d959ad security(frontend): bump linkify-it and dompurify to patched releases
npm audit flagged both against the production dependency tree, and the
Frontend Security job fails on any fixable high-severity finding there
(FIXABLE HIGH: linkify-it).

linkify-it 5.0.1 -> 5.0.2 (GHSA-v245-v573-v5vm, high, CVSS 7.5) fixes a
quadratic-complexity DoS in the mailto: validator scan loop. It reaches us
only through prosemirror-markdown inside @tiptap/pm; the editor's own
autolinking uses linkifyjs, which is a different package and unaffected.
Nothing under frontend/src/ imports prosemirror-markdown or markdown-it and
neither appears in the production bundle, so the vulnerable code is tree-
shaken out and no running install was exposed.

dompurify 3.4.11 -> 3.4.12 (GHSA-c2j3-45gr-mqc4, low) fixes a
CUSTOM_ELEMENT_HANDLING bypass of afterSanitizeElements for allowed custom
elements. DOMPurify is shipped, but we never set CUSTOM_ELEMENT_HANDLING and
register no afterSanitizeElements hook, so the bypass has no precondition;
ProjectPageModal additionally passes a strict ALLOWED_TAGS/ALLOWED_ATTR
allowlist.

Both patched versions already satisfy the ranges their parents declare, so
this is a lockfile-only change - no overrides entry needed, package.json
untouched. npm audit reports zero vulnerabilities, npm run build is clean,
and all 2423 frontend tests pass.
2026-07-22 15:44:52 +02:00
maziggy 8e06fe6d1f Housekeeping 2026-04-22 18:02:42 +02:00
maziggy 273de168b9 cleanup 2026-04-22 17:58:14 +02:00
maziggy 4d87f10855 Hosekeeping 2026-04-22 17:52:42 +02:00
maziggy 00e757f866 cleanup 2026-04-22 17:51:31 +02:00
maziggy 7eb82f58fa Updated CHANGELOG 2026-03-11 10:13:35 +01:00
maziggy 54110cd8c2 Housekeeping 2026-03-11 09:57:47 +01:00
maziggy f28421d1ae Add Home Assistant as notification provider (#656)
Sends persistent notifications to the HA dashboard using the existing
  HA connection from Settings. Zero config — just select "Home Assistant"
  as provider type. Users can forward notifications to mobile via HA
  automations.
2026-03-10 10:10:14 +01:00
maziggy 0fe5837d2c Housekeeping 2026-03-10 09:25:40 +01:00
maziggy a95fa9e124 chore: rebuild static assets after merge 2026-03-09 12:47:44 +01:00
maziggy 5632368490 fix: remove incorrect ethernet badge on printer cards
home_flag bit 18 was incorrectly interpreted as "wired/ethernet
  connection", causing the ethernet badge to always show — even on
  printers without an ethernet port (e.g. A1, P1S). This hid the
  WiFi signal indicator entirely.

  Removed the wired_network field and ethernet badge UI. The WiFi
  signal badge now shows correctly whenever the printer reports
  signal strength.
2026-03-09 12:33:23 +01:00
maziggy 297c3212fa Housekeeping 2025-12-31 12:24:17 +01:00
maziggy 9f665a9382 Housekeeping 2025-12-31 11:36:53 +01:00
maziggy 6d71261de7 Renaming app to Bambuddy 2025-12-09 08:55:59 +00:00