diff --git a/.config/dotnet-tools.json b/.config/dotnet-tools.json index 7dcefc33..6030b249 100644 --- a/.config/dotnet-tools.json +++ b/.config/dotnet-tools.json @@ -3,7 +3,7 @@ "isRoot": true, "tools": { "dotnet-ef": { - "version": "10.0.8", + "version": "10.0.11", "commands": [ "dotnet-ef" ], diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index beb62399..628622ea 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -21,7 +21,7 @@ jobs: backend: ${{ steps.filter.outputs.backend }} frontend: ${{ steps.filter.outputs.frontend }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: dorny/paths-filter@v4 id: filter with: @@ -39,13 +39,13 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - - uses: actions/setup-dotnet@v5 + - uses: actions/setup-dotnet@v6 with: global-json-file: global.json - - uses: actions/cache@v5 + - uses: actions/cache@v6 with: path: ~/.nuget/packages key: nuget-${{ runner.os }}-${{ hashFiles('src/backend/**/*.csproj', 'src/backend/Directory.Packages.props') }} @@ -92,15 +92,15 @@ jobs: run: working-directory: src/frontend steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: pnpm/action-setup@v6 with: package_json_file: src/frontend/package.json - - uses: actions/setup-node@v6 + - uses: actions/setup-node@v7 with: - node-version: 22 + node-version: 24 cache: pnpm cache-dependency-path: src/frontend/pnpm-lock.yaml diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index 5ae9a3fc..e8340e0d 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -27,7 +27,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: fetch-depth: 1 diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index 94dcce55..2b8ccc26 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -26,7 +26,7 @@ jobs: actions: read # Required for Claude to read CI results on PRs steps: - name: Checkout repository - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: fetch-depth: 1 diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 345c0740..52e92fa0 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -35,7 +35,7 @@ jobs: backend: ${{ steps.filter.outputs.backend }} frontend: ${{ steps.filter.outputs.frontend }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: dorny/paths-filter@v4 id: filter with: @@ -56,7 +56,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: docker/setup-buildx-action@v4 @@ -75,7 +75,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: docker/setup-buildx-action@v4 diff --git a/README.md b/README.md index 21c69e7a..37b8d078 100644 --- a/README.md +++ b/README.md @@ -56,7 +56,7 @@ Every project starts the same way: authentication, role management, rate limitin - [Docker Desktop](https://www.docker.com/products/docker-desktop/) - [.NET 10 SDK](https://dotnet.microsoft.com/download/dotnet/10.0) -- [Node.js 22+](https://nodejs.org/) (run `corepack enable` for pnpm) +- [Node.js 24+](https://nodejs.org/) (run `corepack enable` for pnpm) - [Git](https://git-scm.com/) ### 1. Clone & Initialize diff --git a/docs/sessions/2026-08-17-dependency-updates.md b/docs/sessions/2026-08-17-dependency-updates.md new file mode 100644 index 00000000..9e395807 --- /dev/null +++ b/docs/sessions/2026-08-17-dependency-updates.md @@ -0,0 +1,48 @@ +# Dependency Updates (August 2026) + +**Date**: 2026-08-17 +**Scope**: Bring all NuGet, npm and GitHub Actions dependencies to their latest versions, superseding the open Dependabot PRs. + +## Summary + +Updated every backend NuGet package, every frontend npm package and every GitHub Action to the latest release, including several major bumps (SkiaSharp 4, NSubstitute 6, ESLint 10, Vite 8, Vitest 4, TypeScript 6). Node.js runtime moved from 22 to 24 (active LTS). Small code adaptations were needed for Vitest 4 mock semantics and the new ESLint 10 `no-useless-assignment` rule. Backend (1046 tests) and frontend (286 tests, lint, svelte-check, production build, Docker image) are all green. + +## Changes Made + +| File | Change | Reason | +|------|--------|--------| +| `src/backend/Directory.Packages.props` | All packages to latest; framework 10.0.11 | Security/bug fixes; supersedes Dependabot #519, #520, #521, #522, #503 | +| `.config/dotnet-tools.json` | dotnet-ef 10.0.8 -> 10.0.11 | Keep tool aligned with EF Core version | +| `src/frontend/package.json`, `pnpm-lock.yaml` | All packages to latest; pnpm 10.34.5 | Supersedes Dependabot #515 | +| `src/frontend/vite.config.ts` | Add `clearMocks: true` | Vitest 4: `restoreMocks` no longer resets `vi.fn()` call state | +| `src/frontend/src/lib/utils/crop.test.ts` | `Image` stub uses a regular function | Vitest 4: `vi.fn(arrow)` cannot be invoked with `new` | +| `src/frontend/src/lib/components/ui/sidebar/sidebar-trigger.svelte` | `bind:ref` on `