Skip to content

chore(deps): aggiorna stack e correggi gli audit - #560

Closed
max23468 wants to merge 1 commit into
mainfrom
codex/dependency-refresh-2026-08-26
Closed

chore(deps): aggiorna stack e correggi gli audit#560
max23468 wants to merge 1 commit into
mainfrom
codex/dependency-refresh-2026-08-26

Conversation

@max23468

Copy link
Copy Markdown
Owner

Riepilogo\n- aggiorna Prisma 7.10, Shopify CLI, Vite/Vitest, Supabase e toolchain\n- migra Shopify App React Router 1→2 e session storage 5→6\n- porta React Doctor a 0.9.12 e aggiorna l’Action\n- corregge le vulnerabilità transitive deepmerge-ts e nanoid\n\n## Verifiche\n- Verifica SyncBay: corsia full.

  • npm run format:check
  • npm run prisma:generate
  • npm run lint
  • npm run doctor
  • npm run test:tooling
  • npm run typecheck:raw
  • npm run coverage:lib
  • npm run test:services:raw
  • npm run build:raw
  • npm run prisma:validate
  • npm run smoke:ui
  • npm run ui:check
  • npm run ui:browser-check
  • npm run audit:prod
    Checking formatting...

All matched files use the correct format.
Finished in 12549ms on 509 files using 8 threads.

✔ Generated Prisma Client (v7.10.0) to ./prisma/generated/client in 783ms

Start by importing your Prisma Client (See: https://pris.ly/d/importing-client)

✔ Select projects › syncbay

Agent guidance

  • Treat React Doctor diagnostics as starting hypotheses. Read the relevant code before confirming or suppressing each finding.
  • For each group, decide true positive, false positive, or needs-human-review, then assign high/medium/low confidence.
  • Do not suppress a finding without evidence from the file in question. Confidence requires code context.
  • Understand the root cause before editing. Fix the underlying code instead of changing react-doctor config or suppressing rules unless explicitly asked.
  • Investigate deeply where relevant: race conditions, security-sensitive flows, state propagation, multi-file refactors, and downstream dependency chains.
  • Ignore pure style preferences, theoretical issues without real impact, missing features, and unrelated pre-existing code.
  • Start with high-confidence fixes that preserve behavior. Leave low-confidence or product-dependent changes as notes.
  • Run npx react-doctor@latest --verbose --scope changed before and after changes, plus relevant tests after each focused batch.
  • When available, spawn subagents or isolated worktrees for independent rule families, then review and merge only the best safe fixes.
  • Split unrelated, broad, or behavior-changing work into separate PRs/branches instead of one large cleanup.
  • When one rule spans dozens of files (a migration-scale change), fix a representative sample first, confirm the recipe holds, and get the code owner's sign-off before changing the rest. Don't mass-fix a broad pattern in one unreviewed pass.
  • For confirmed issues that cannot be fixed now, create GitHub issues with the rule, file/line, confidence, impact, and proposed fix.
  • If a fix needs an API, UX, or architecture decision, stop and ask before editing.

✔ Scanned 412 files in 24.5s

React Doctor — syncbay
Score: 100 / 100 Great

✔ No issues found!

────────────────────────────────────────────────────────────

Share: https://react.doctor/share?p=syncbay&s=100
Tell others how you did on socials

Docs: https://react.doctor/docs
Learn more about fixing issues, setting up CI/CD, and
configuring rules with a config file

GitHub: https://github.com/millionco/react-doctor
Report issues and star the repository!

RUN v4.1.11 /Users/Matteo/Documents/Codex/2026-08-26/fa/work/repo-updates/SyncBay

Test Files 23 passed (23)
Tests 131 passed (131)
Start at 13:54:14
Duration 95.26s (transform 3.98s, setup 0ms, import 13.20s, tests 97.04s, environment 21ms)

✔ legge la priorità solo dall'intestazione del finding (3.075959ms)
✔ blocca soltanto P0/P1 dell'HEAD corrente (0.370708ms)
✔ P2/P3 sono advisory e completano il gate dopo l'assestamento (0.337ms)
✔ un advisory top-level richiede il marker dell'HEAD (1.639584ms)
✔ il pollice della PR vale solo per il primo giro automatico (0.167666ms)
✔ i giri successivi usano la reaction dell'invocazione corrente (0.091375ms)
✔ seleziona solo un'invocazione esatta, fidata e successiva all'HEAD (0.210041ms)
✔ il primo giro è automatico solo su apertura o ready (0.094417ms)
✔ gli errori operativi bloccano in assenza di una review conclusa più recente (0.227875ms)
✔ valida il numero PR e mantiene il polling entro cinque ore (0.383875ms)
✔ il workflow usa codice trusted e non richiede commenti al primo giro (19.860375ms)
ℹ tests 11
ℹ suites 0
ℹ pass 11
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 131.506583

RUN v4.1.11 /Users/Matteo/Documents/Codex/2026-08-26/fa/work/repo-updates/SyncBay
Coverage enabled with v8

Test Files 107 passed (107)
Tests 626 passed (626)
Start at 13:56:03
Duration 12.68s (transform 5.41s, setup 0ms, import 14.25s, tests 2.48s, environment 65ms)

% Coverage report from v8
-------------------|---------|----------|---------|---------|-------------------
File | % Stmts | % Branch | % Funcs | % Lines | Uncovered Line #s
-------------------|---------|----------|---------|---------|-------------------
All files | 89.06 | 80.26 | 96.01 | 91.84 |
...runtime-url.ts | 94.28 | 92.85 | 100 | 94.11 | 43,73
safe-http-url.ts | 75 | 100 | 100 | 75 | 7
...che-headers.ts | 85.71 | 100 | 50 | 85.71 | 15
...alth-center.ts | 90.47 | 80 | 71.42 | 88.23 | 80-82
...mage-repair.ts | 95.23 | 93.75 | 100 | 100 | 31
...t-execution.ts | 53.84 | 57.14 | 100 | 53.84 | 76-96
...atalog-page.ts | 91.3 | 78.84 | 75 | 90.47 | 32,58-62,70
...g-reconcile.ts | 95.23 | 95 | 100 | 95 | 30
...fill-report.ts | 95.91 | 89.02 | 100 | 95.34 | 118,142
...rage-report.ts | 100 | 83.33 | 100 | 100 | 72
...ion-intents.ts | 82.6 | 89.65 | 66.66 | 86.36 | 13,22,40
...e-proposals.ts | 93.02 | 80.55 | 100 | 97.22 | 165
...urces-apply.ts | 88.4 | 70.27 | 100 | 87.09 | ...27,136,150,153
...ources-read.ts | 93.33 | 83.33 | 100 | 92.85 | 65
...ict-actions.ts | 71.42 | 70.96 | 75 | 73.33 | 26-43
...t-detection.ts | 97.67 | 97.91 | 100 | 100 | 138
...ict-display.ts | 44.11 | 35.84 | 50 | 44.82 | ...35,44-55,69-73
syncbay-copy.ts | 0 | 100 | 0 | 0 | 16-19
...diagnostics.ts | 74.19 | 61.53 | 100 | 76 | ...12,124-128,135
...time-format.ts | 0 | 0 | 0 | 0 | 1-19
...on-backfill.ts | 82.43 | 75.75 | 92.85 | 89.06 | ...23,199-204,259
...ion-cleanup.ts | 88.42 | 69.3 | 97.95 | 92.7 | ...63,488-494,498
...ption-rules.ts | 80 | 64.28 | 81.81 | 78.57 | 43,74-81
...-delta-sync.ts | 91.89 | 83.33 | 100 | 96.42 | 10
...bay-trading.ts | 76.92 | 58.53 | 84.61 | 77.77 | 33-46,59,78,165
...ress-budget.ts | 85.07 | 78.12 | 100 | 90.59 | ...69,277-278,286
...ror-message.ts | 93.33 | 92.59 | 100 | 100 | 20,30
...atalog-copy.ts | 100 | 50 | 100 | 100 | 36-45
...ield-policy.ts | 94.02 | 77.55 | 100 | 98.27 | 176
...og-takeover.ts | 96.82 | 92.18 | 100 | 98 | 248
...cile-policy.ts | 88.88 | 50 | 100 | 88.88 | 37
...atalog-mode.ts | 83.33 | 80 | 80 | 83.33 | 13
...view-window.ts | 85.71 | 80 | 85.71 | 88.23 | 102,109
...w-candidate.ts | 87.5 | 87.14 | 100 | 100 | 40,63-87
...al-schedule.ts | 100 | 83.33 | 100 | 100 | 12
...diagnostics.ts | 92.85 | 87.3 | 100 | 92.45 | 134-138,158
...-quarantine.ts | 96.55 | 90.9 | 100 | 95.65 | 75
...-scheduling.ts | 87.75 | 79.76 | 87.09 | 91.95 | 106,300-310
...fy-baseline.ts | 100 | 83.33 | 100 | 100 | 8
...performance.ts | 88.88 | 59.09 | 87.5 | 92.3 | 59,105
...order-stock.ts | 92.3 | 88.88 | 100 | 92.3 | 21
...-pagination.ts | 100 | 88.88 | 100 | 100 | 2,8
...t-alignment.ts | 88.88 | 73.52 | 87.5 | 92 | 47,87
...g-rule-sync.ts | 93.75 | 93.33 | 100 | 100 | 49
...icing-rules.ts | 88.37 | 83.33 | 100 | 92.1 | 52,65,164
...cing-source.ts | 89.47 | 73.07 | 100 | 100 | 35,45-46,57-73
...ct-baseline.ts | 92.85 | 91.66 | 100 | 100 | 43
...fill-report.ts | 90.76 | 88.37 | 100 | 94 | 202,247-249
...t-sync-plan.ts | 97.14 | 90.47 | 100 | 97.14 | 78
...duct-facets.ts | 77.27 | 66.85 | 100 | 79.64 | ...93-507,569-574
...ct-matching.ts | 85.1 | 79.45 | 95.23 | 89.15 | ...23,165,170-172
...on-settings.ts | 100 | 88.88 | 100 | 100 | 40-43
...publication.ts | 82.81 | 66.66 | 87.5 | 83.05 | ...53,259,270,310
...shot-dedupe.ts | 88.46 | 67.39 | 100 | 94.73 | 61
...hot-payload.ts | 94.82 | 92.42 | 100 | 96 | 107,211
...y-checklist.ts | 88.88 | 80 | 100 | 100 | 35-37,93,138-139
...equest-body.ts | 96.42 | 84.61 | 100 | 100 | 17,55
...ion-cleanup.ts | 95 | 88.88 | 100 | 100 | 97,107
...er-fairness.ts | 91.3 | 75 | 100 | 100 | 42-54
...runtime-log.ts | 85.71 | 81.39 | 100 | 100 | 44-51,56-62,67-68
...diagnostics.ts | 89.65 | 80 | 100 | 89.28 | 137,159,170
...opify-admin.ts | 93.75 | 87.64 | 100 | 96.66 | 71,113
...ory-mapping.ts | 92.18 | 84.25 | 100 | 93.33 | ...47,417,420,426
...hange-batch.ts | 100 | 70 | 100 | 100 | 25-27
...-metafields.ts | 92.3 | 85.29 | 100 | 100 | 42-62,83
...t-thumbnail.ts | 95.23 | 89.47 | 100 | 100 | 6-11
...pify-scopes.ts | 80 | 75 | 100 | 100 | 2
...t-selection.ts | 94.11 | 77.27 | 100 | 100 | 14,21-27,43-53
...ify-webhook.ts | 93.22 | 82.19 | 100 | 98 | 72
...job-archive.ts | 84 | 76.92 | 100 | 94.73 | 36
...ob-recovery.ts | 90 | 90 | 100 | 100 | 18
...stock-guard.ts | 97.36 | 79.16 | 100 | 100 | 38-50,62-73
...idempotency.ts | 100 | 95 | 100 | 100 | 29
...vice-health.ts | 92.68 | 83.33 | 100 | 94.87 | 85,159
...sync-health.ts | 93.33 | 93.75 | 100 | 100 | 54
...bnail-cache.ts | 100 | 87.5 | 100 | 100 | 23
...ay-ui-state.ts | 90.26 | 77.19 | 100 | 94.18 | ...00,603,608-612
...hook-errors.ts | 86.95 | 86.66 | 100 | 86.95 | 28,36,47
version.ts | 0 | 100 | 100 | 0 | 17-18
-------------------|---------|----------|---------|---------|-------------------

=============================== Coverage summary ===============================
Statements : 89.06% ( 2947/3309 )
Branches : 80.26% ( 2513/3131 )
Functions : 96.01% ( 771/803 )
Lines : 91.84% ( 2637/2871 )

RUN v4.1.11 /Users/Matteo/Documents/Codex/2026-08-26/fa/work/repo-updates/SyncBay

Test Files 23 passed (23)
Tests 89 passed (89)
Start at 13:56:16
Duration 2.55s (transform 4.80s, setup 0ms, import 8.61s, tests 1.14s, environment 10ms)

Using Vite Environment API (experimental)
vite v8.2.2 building client environment for production...
transforming...
✓ 379 modules transformed.
rendering chunks...
computing gzip size...
build/client/.vite/manifest.json 12.07 kB │ gzip: 1.40 kB
build/client/assets/syncbay-embedded-s5MdinUi.css 19.52 kB │ gzip: 3.34 kB
build/client/assets/api.diagnostics.database-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/api.diagnostics.shopify-admin-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/api.jobs.run-due-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/auth._-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/auth.ebay.callback-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/auth.ebay.start-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/ebay.account-deletion-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.app.scopes_update-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.app.uninstalled-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.ebay.account-deletion-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.inventory_levels.update-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.orders.cancelled-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.orders.create-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.orders.paid-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/webhooks.products.update-BvRk9kiK.js 0.00 kB │ gzip: 0.02 kB
build/client/assets/syncbay-toast-Ulh2oz06.js 0.17 kB │ gzip: 0.14 kB
build/client/assets/PublicAppProvider-Cn4YpsNs.js 0.22 kB │ gzip: 0.19 kB
build/client/assets/import-product-status-DJdR-tu8.js 0.26 kB │ gzip: 0.16 kB
build/client/assets/use-action-toast-aPuPxWlu.js 0.37 kB │ gzip: 0.26 kB
build/client/assets/syncbay-brand-BqI4zRvw.js 0.54 kB │ gzip: 0.32 kB
build/client/assets/route-4_Xwn0zV.js 0.64 kB │ gzip: 0.41 kB
build/client/assets/SyncBayBrandPanel-7C--nAFx.js 0.86 kB │ gzip: 0.46 kB
build/client/assets/syncbay-copy-SnAn6YTt.js 0.99 kB │ gzip: 0.45 kB
build/client/assets/SyncBayLive-CoNaeQNy.js 1.02 kB │ gzip: 0.48 kB
build/client/assets/route-Bnfu-jGq.js 1.72 kB │ gzip: 0.84 kB
build/client/assets/about-DgL5HfW1.js 1.80 kB │ gzip: 0.82 kB
build/client/assets/privacy-BxDaGixg.js 3.79 kB │ gzip: 1.47 kB
build/client/assets/terms-Bnu7Ubdi.js 4.00 kB │ gzip: 1.54 kB
build/client/assets/app-BsjIo9qo.js 4.10 kB │ gzip: 1.74 kB
build/client/assets/root-D6NgqcU7.js 5.76 kB │ gzip: 2.04 kB
build/client/assets/app.conflicts-Cjqrh6pQ.js 8.89 kB │ gzip: 3.13 kB
build/client/assets/syncbay-ui-state-Dp9of2KC.js 8.97 kB │ gzip: 3.46 kB
build/client/assets/app.catalog-SL_QbQFQ.js 10.61 kB │ gzip: 3.50 kB
build/client/assets/app.index-umwy-F14.js 11.71 kB │ gzip: 4.12 kB
build/client/assets/SyncBayUi-BQYWOvi6.js 13.03 kB │ gzip: 3.92 kB
build/client/assets/app.settings-DzEry3OH.js 13.68 kB │ gzip: 4.00 kB
build/client/assets/app.activity-vqfgHyY5.js 15.01 kB │ gzip: 5.28 kB
build/client/assets/app.import-preview-weLG3Wk
.js 26.66 kB │ gzip: 7.75 kB
build/client/assets/jsx-runtime-DHgiARHb.js 130.97 kB │ gzip: 43.22 kB
build/client/assets/entry.client-CrDoHkWx.js 186.23 kB │ gzip: 58.73 kB

✓ built in 693ms
vite v8.2.2 building ssrBundle_nodejs_eyJydW50aW1lIjoibm9kZWpzIn0 environment for production...
transforming...
✓ 191 modules transformed.
rendering chunks...

✓ 1 asset cleaned from React Router server build.
build/client/assets/syncbay-embedded-s5MdinUi.css

computing gzip size...
build/server/nodejs_eyJydW50aW1lIjoibm9kZWpzIn0/.vite/manifest.json 0.23 kB │ gzip: 0.16 kB
build/server/nodejs_eyJydW50aW1lIjoibm9kZWpzIn0/index.js 924.13 kB │ gzip: 200.06 kB

✓ built in 422ms
The schema at prisma/schema.prisma is valid 🚀
Smoke UI passato: nav, Panoramica, Catalogo, Conflitti, Attività, Importazione, Impostazioni e gestione location presenti.
UI SSR verificate: 6 pagine, 32 scenari isolati (715 test, build, smoke, 32 scenari UI e browser check)\n- React Doctor: 100/100\n- npm audit, audit produzione e OSV Scanner: puliti\n\nReact Router 8 e TypeScript 7 restano esclusi per peer incompatibili upstream. Nessun deploy eseguito.

@max23468 max23468 closed this Aug 26, 2026
@max23468
max23468 deleted the codex/dependency-refresh-2026-08-26 branch August 26, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant