mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-11 10:56:43 -08:00
Closes all 69 open Dependabot alerts with one coordinated update instead of per-alert bot branches. Runtime scope (ships in the packaged Electron app): - js-yaml override 4.3.0 -> 4.3.1 (quadratic CPU DoS in !!omap, via electron-updater; second selector added for the new ^4.3.0 declarers). The dev-only js-yaml@3.15.1 copy is outside the advisory range (>=4.0.0 <4.3.1) and has no 3.x backport, so it stays. - fast-uri override 3.1.4 -> 3.1.6 (CVE-2026-18446 host confusion, via electron-conf -> ajv). Dev scope: - astro 5.18.1 -> 7.2.4 (+@astrojs/mdx 7.0.7); the deprecated @astrojs/tailwind integration only supports Astro <= 5, so Tailwind v3 now runs through apps/website/postcss.config.mjs (+autoprefixer). Astro 7's prerender entry externalizes cookie/html-escaper/mrmime/zod, which pnpm's strict layout cannot resolve from the emitted chunk location - declared as root devDependencies at astro's own versions. Astro's transitive vite 6.x/esbuild 0.27/sharp 0.34 copies leave the tree with it; the patched root vite@7.3.6 pin is untouched. - hono -> 4.12.34, @hono/node-server -> 1.19.17, undici 7.x -> 7.29.0, postcss 8.5.6 -> 8.5.26, immutable -> 5.1.9, svgo 4.0.0 -> 4.0.2, serialize-javascript 6.0.2 -> 7.1.0, minimatch 3.1.2 -> 3.1.5, ip-address -> 10.5.0, qs -> 6.15.3, picomatch 4.0.3 -> 4.0.5, uuid 8.3.2 -> 11.1.1, brace-expansion 1.x -> 1.1.18, ws (jsdom) -> 8.21.3, esbuild (drizzle-kit's @esbuild-kit loader) -> 0.25.12. eslint now ignores generated **/.astro output, which Astro 7 emits with patterns the flat config rejects. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
IPTVnator Website
The website is an Astro static site deployed to GitHub Pages at https://4gray.github.io/iptvnator/.
Blog Comments
Blog posts render Giscus comments from apps/website/src/components/GiscusComments.astro.
Giscus stores comments in GitHub Discussions for 4gray/iptvnator and maps each page to a discussion by pathname, including the GitHub Pages base path such as /iptvnator/blog/why-external-players-help/.
The embed is wired to the dedicated Blog comments discussion category:
- Repository id:
MDEwOlJlcG9zaXRvcnkyMTMxOTQ3Mzg= - Category id:
DIC_kwDODLUX8s4C9eBJ - Mapping:
pathname - Theme:
transparent_dark
If the category is recreated, query the new category id:
gh api graphql \
-f owner=4gray \
-f name=iptvnator \
-f query='query($owner:String!, $name:String!) { repository(owner:$owner, name:$name) { discussionCategories(first:25) { nodes { id name slug isAnswerable } } } }'
Then update data-category-id in GiscusComments.astro.
Moderation happens in GitHub Discussions. Maintainers can hide, delete, lock, or move discussions and comments from the repository Discussions UI.