chore(deps): bump the npm minor/patch group across 43 packages (#1270)

Rebuilt from #1251 so the group could merge, on top of the transitive-CVE
overrides from #1258. Supersedes #1230 and #1251.

Carries axios 1.16.0 -> 1.18.1, closing seven runtime-scope advisories
including the proxy-credential leak on redirects, and sharp 0.34.5 -> 0.35.3
for the libvips CVEs.

`esModuleInterop` moves to tsconfig.base.json. artplayer 5.4.0 switched from a
Parcel build exposing `module.exports.default` to UMD assigning
`module.exports` directly; the flag was only set in apps/web, so every lib
compiled `import Artplayer from 'artplayer'` to `.default` and got undefined.
Production was never affected — esbuild resolves the ESM entry.

Two packages are deliberately held back, each for its own PR:

- epg-parser ^0.5.0 — grouped as a minor, but 0.x minors are breaking and this
  one reshapes the parse output (`channel.name` -> `displayName`, icons/urls
  become objects, `credits` becomes role-keyed, dates switch to ISO). Its only
  consumer is the uncovered web-backend `/parse-xml` endpoint.
- electron-builder ^26.15.3 — rewrote the snap target, and the resulting snap
  cannot start (`command.sh` execs a `desktop-init.sh` that never lands at the
  snap root under our core22 strict config). Its two required fixes go with it:
  the `engines` node floor from @electron/rebuild 4, and resolving upstream
  node-gyp instead of the dropped `@electron/node-gyp` fork.
This commit is contained in:
4gray authored and GitHub committed 2026-07-26 19:43:35 +02:00
1 parent 9ae53e4515
commit d5f5beab38
6 files changed
+2231 -852

No files matched your search

+9
View File
@@ -0,0 +1,9 @@
---
type: internal
area: deps
---
Updated 43 dependencies, including the HTTP client behind every playlist and
portal request — that one closes seven advisories that affect the shipped app,
among them a proxy-credential leak on redirects. Also refreshes the ArtPlayer,
hls.js, Video.js and Shaka player engines. No behaviour change intended.
+12 -33
View File
@@ -677,44 +677,23 @@ function copyGenericRuntimeToNativeBuild(runtime) {
return manifest;
}
function resolveElectronNodeGypBin() {
const pnpmRoot = path.join(workspaceRoot, 'node_modules', '.pnpm');
if (!fs.existsSync(pnpmRoot)) {
throw new Error('Unable to find node_modules/.pnpm.');
}
const packageDirs = fs
.readdirSync(pnpmRoot, { withFileTypes: true })
.filter(
(entry) =>
entry.isDirectory() &&
entry.name.startsWith('@electron+node-gyp@')
)
.map((entry) => entry.name)
.sort();
for (const packageDir of packageDirs) {
const candidate = path.join(
pnpmRoot,
packageDir,
'node_modules',
'@electron',
'node-gyp',
'bin',
'node-gyp.js'
// Upstream node-gyp, resolved as a declared devDependency. This used to scan
// node_modules/.pnpm for the `@electron/node-gyp` fork, which was only ever in
// the tree as a transitive of `@electron/rebuild` 3 — rebuild 4 moved to
// upstream `node-gyp` and the scan started throwing. The Electron target is
// selected through the npm_config_* env below, not by the binary.
function resolveNodeGypBin() {
try {
return require.resolve('node-gyp/bin/node-gyp.js');
} catch (error) {
throw new Error(
`Unable to resolve node-gyp. Is it installed? (${error.message})`
);
if (fs.existsSync(candidate)) {
return candidate;
}
}
throw new Error('Unable to resolve @electron/node-gyp.');
}
function runNodeGyp(command, env) {
const nodeGypBin = resolveElectronNodeGypBin();
const nodeGypBin = resolveNodeGypBin();
const result = spawnSync(
process.execPath,
[nodeGypBin, command, '--directory', addonRoot],
+4
View File
@@ -312,6 +312,10 @@ Toolchain notes for the Electron 41 upgrade:
2. The pnpm override `node-abi@3.85.0 -> 3.92.0` is required so
`@electron/rebuild` (via `electron-builder install-app-deps`) can map
Electron 41 to its ABI.
3. Local development needs **Node >= 22.12**, declared in `engines`.
`electron-builder` 26.15.3 pulls `@electron/rebuild` 4, which sets that
floor, and the root `postinstall` runs `install-app-deps` on every
`pnpm install`. CI already runs Node 22.
Known caveats:
+43 -43
View File
@@ -82,39 +82,39 @@
"@angular/platform-browser": "21.2.17",
"@angular/platform-browser-dynamic": "21.2.17",
"@angular/router": "21.2.17",
"@ngrx/effects": "21.0.1",
"@ngrx/entity": "21.0.1",
"@ngrx/router-store": "21.0.1",
"@ngrx/signals": "21.0.1",
"@ngrx/store": "21.0.1",
"@ngrx/store-devtools": "21.0.1",
"@ngrx/effects": "21.1.1",
"@ngrx/entity": "21.1.1",
"@ngrx/router-store": "21.1.1",
"@ngrx/signals": "21.1.1",
"@ngrx/store": "21.1.1",
"@ngrx/store-devtools": "21.1.1",
"@ngx-pwa/local-storage": "21.0.0",
"@yangkghjh/videojs-aspect-ratio-panel": "0.0.1",
"angularx-qrcode": "21.0.4",
"artplayer": "5.3.0",
"axios": "1.16.0",
"artplayer": "5.4.0",
"axios": "1.18.1",
"better-sqlite3": "12.9.0",
"date-fns": "4.1.0",
"date-fns": "4.4.0",
"drizzle-orm": "0.45.2",
"electron-conf": "1.3.0",
"electron-updater": "6.8.9",
"epg-parser": "^0.1.6",
"fix-path": "5.0.0",
"hls.js": "1.6.13",
"hls.js": "1.6.16",
"iptv-playlist-parser": "github:4gray/iptv-playlist-parser#v0.15.2-iptvnator.2",
"marked": "18.0.5",
"marked": "18.0.7",
"mpegts.js": "1.8.0",
"ms": "2.1.3",
"ngx-indexed-db": "21.0.0",
"ngx-skeleton-loader": "11.3.0",
"rxjs": "7.8.2",
"saxes": "6.0.0",
"shaka-player": "5.2.1",
"shaka-player": "5.2.2",
"uuid": "9.0.0",
"video.js": "8.23.4",
"video.js": "8.23.9",
"videojs-contrib-quality-levels": "4.1.0",
"videojs-quality-selector-hls": "1.1.1",
"zone.js": "~0.15.1"
"zone.js": "~0.16.2"
},
"devDependencies": {
"@angular-devkit/core": "21.2.17",
@@ -137,17 +137,17 @@
"@angular/router": "21.2.17",
"@angular/service-worker": "21.2.17",
"@astrojs/mdx": "4.3.13",
"@astrojs/sitemap": "3.7.0",
"@astrojs/sitemap": "3.7.3",
"@astrojs/tailwind": "6.0.2",
"@electron/asar": "3.4.1",
"@eslint/eslintrc": "3.3.1",
"@eslint/eslintrc": "3.3.6",
"@eslint/js": "^9.38.0",
"@faker-js/faker": "10.3.0",
"@fontsource/crimson-pro": "5.2.8",
"@fontsource/dm-sans": "5.2.8",
"@fontsource/jetbrains-mono": "5.2.8",
"@fontsource/roboto": "5.2.10",
"@ngrx/eslint-plugin": "^21.0.1",
"@faker-js/faker": "10.5.0",
"@fontsource/crimson-pro": "5.3.0",
"@fontsource/dm-sans": "5.3.0",
"@fontsource/jetbrains-mono": "5.3.0",
"@fontsource/roboto": "5.3.0",
"@ngrx/eslint-plugin": "^21.1.1",
"@ngx-translate/core": "16.0.4",
"@ngx-translate/http-loader": "16.0.1",
"@nx/angular": "22.7.1",
@@ -160,12 +160,12 @@
"@nx/playwright": "22.7.1",
"@nx/web": "22.7.1",
"@nx/workspace": "22.7.1",
"@playwright/test": "^1.36.0",
"@playwright/test": "^1.62.0",
"@schematics/angular": "21.2.9",
"@swc-node/register": "1.11.1",
"@swc/core": "1.15.8",
"@swc/helpers": "0.5.18",
"@tailwindcss/typography": "0.5.19",
"@swc-node/register": "1.12.1",
"@swc/core": "1.15.46",
"@swc/helpers": "0.5.23",
"@tailwindcss/typography": "0.5.20",
"@types/better-sqlite3": "^7.6.12",
"@types/cors": "2.8.19",
"@types/express": "5.0.6",
@@ -173,14 +173,14 @@
"@types/mocha": "9.0.0",
"@types/node": "20.19.9",
"@types/uuid": "^10.0.0",
"@types/video.js": "7.3.29",
"@typescript-eslint/eslint-plugin": "^8.46.2",
"@typescript-eslint/parser": "^8.46.2",
"@typescript-eslint/utils": "^8.46.2",
"@types/video.js": "7.3.58",
"@typescript-eslint/eslint-plugin": "^8.65.0",
"@typescript-eslint/parser": "^8.65.0",
"@typescript-eslint/utils": "^8.65.0",
"angular-eslint": "21.3.1",
"astro": "5.18.1",
"cors": "2.8.6",
"drizzle-kit": "0.31.5",
"drizzle-kit": "0.31.10",
"electron": "^41.7.2",
"electron-builder": "^26.0.12",
"electron-playwright-helpers": "1.8.2",
@@ -194,26 +194,26 @@
"istanbul-lib-coverage": "3.2.2",
"istanbul-lib-report": "3.0.1",
"istanbul-reports": "3.2.0",
"jest": "^30.0.2",
"jest-environment-jsdom": "^30.0.2",
"jest-environment-node": "^30.0.2",
"jest": "^30.4.2",
"jest-environment-jsdom": "^30.4.1",
"jest-environment-node": "^30.4.1",
"jest-preset-angular": "~15.0.0",
"jest-util": "^30.0.2",
"jest-util": "^30.4.1",
"jsonc-eslint-parser": "^2.1.0",
"material-design-icons-iconfont": "6.7.0",
"ng-mocks": "14.15.1",
"ng-mocks": "14.15.3",
"nx": "22.7.1",
"nx-electron": "22.0.0",
"prettier": "^3.8.1",
"sharp": "0.34.5",
"prettier": "^3.9.6",
"sharp": "0.35.3",
"tailwindcss": "^3.4.19",
"ts-jest": "^29.4.5",
"ts-jest": "^29.4.12",
"ts-node": "10.9.2",
"tslib": "^2.8.1",
"tsx": "4.21.0",
"tsx": "4.23.1",
"typescript": "5.9.3",
"typescript-eslint": "^8.46.2",
"yaml": "2.8.2"
"typescript-eslint": "^8.65.0",
"yaml": "2.9.0"
},
"pnpm": {
"overrides": {
+2162 -776
View File
File diff suppressed because it is too large. Load diff
+1
View File
@@ -5,6 +5,7 @@
"sourceMap": true,
"declaration": false,
"moduleResolution": "node",
"esModuleInterop": true,
"emitDecoratorMetadata": true,
"experimentalDecorators": true,
"importHelpers": true,