mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-06 22:21:29 +02:00
npm audit flagged both against the production dependency tree, and the Frontend Security job fails on any fixable high-severity finding there (FIXABLE HIGH: linkify-it). linkify-it 5.0.1 -> 5.0.2 (GHSA-v245-v573-v5vm, high, CVSS 7.5) fixes a quadratic-complexity DoS in the mailto: validator scan loop. It reaches us only through prosemirror-markdown inside @tiptap/pm; the editor's own autolinking uses linkifyjs, which is a different package and unaffected. Nothing under frontend/src/ imports prosemirror-markdown or markdown-it and neither appears in the production bundle, so the vulnerable code is tree- shaken out and no running install was exposed. dompurify 3.4.11 -> 3.4.12 (GHSA-c2j3-45gr-mqc4, low) fixes a CUSTOM_ELEMENT_HANDLING bypass of afterSanitizeElements for allowed custom elements. DOMPurify is shipped, but we never set CUSTOM_ELEMENT_HANDLING and register no afterSanitizeElements hook, so the bypass has no precondition; ProjectPageModal additionally passes a strict ALLOWED_TAGS/ALLOWED_ATTR allowlist. Both patched versions already satisfy the ranges their parents declare, so this is a lockfile-only change - no overrides entry needed, package.json untouched. npm audit reports zero vulnerabilities, npm run build is clean, and all 2423 frontend tests pass.
41 lines
1.8 KiB
HTML
41 lines
1.8 KiB
HTML
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no" />
|
|
<!-- L-4: Restrict Referer header to origin-only on cross-origin navigation so
|
|
sensitive tokens in query parameters are not leaked to third-party servers. -->
|
|
<meta name="referrer" content="strict-origin-when-cross-origin" />
|
|
<title>Bambuddy</title>
|
|
|
|
<!-- PWA Meta Tags -->
|
|
<meta name="description" content="Monitor and manage your Bambu Lab 3D printers" />
|
|
<meta name="theme-color" content="#00ae42" />
|
|
<meta name="mobile-web-app-capable" content="yes" />
|
|
<meta name="apple-mobile-web-app-capable" content="yes" />
|
|
<meta name="apple-mobile-web-app-status-bar-style" content="black-translucent" />
|
|
<meta name="apple-mobile-web-app-title" content="Bambuddy" />
|
|
|
|
<!-- Manifest -->
|
|
<link rel="manifest" href="/manifest.json" />
|
|
|
|
<!-- Favicons -->
|
|
<link rel="icon" type="image/png" sizes="32x32" href="/img/favicon-32x32.png" />
|
|
<link rel="icon" type="image/png" sizes="16x16" href="/img/favicon-16x16.png" />
|
|
<link rel="apple-touch-icon" sizes="180x180" href="/img/apple-touch-icon.png" />
|
|
|
|
<!-- Splash screens for iOS -->
|
|
<link rel="apple-touch-startup-image" href="/img/android-chrome-512x512.png" />
|
|
<script type="module" crossorigin src="/assets/index-DMXg01ou.js"></script>
|
|
<link rel="stylesheet" crossorigin href="/assets/index-kl51qImb.css">
|
|
</head>
|
|
<body>
|
|
<div id="root"></div>
|
|
|
|
<!-- Service Worker Registration (skip on SpoolBuddy kiosk).
|
|
Kept as an external file so the CSP `script-src 'self'` covers it
|
|
without needing 'unsafe-inline' or per-build hashes. -->
|
|
<script src="/sw-register.js"></script>
|
|
</body>
|
|
</html>
|