Skip to content

chore(deps): modernize to vite 7 + jspdf 4; clear audit advisories - #7

Merged
daniellee-ux merged 1 commit into
mainfrom
chore/modernize-deps
Jun 23, 2026
Merged

daniellee-ux merged 1 commit into
mainfrom
chore/modernize-deps

Conversation

@daniellee-ux

Copy link
Copy Markdown
Owner

What

Modernizes @opencanva/core's heavy deps to clear the npm audit advisories users were seeing:

  • vite ^5.4.10 → ^7.0.0
  • jspdf ^2.5.2 → ^4.2.1
  • @vitejs/plugin-react ^4.3.3 → ^4.7.0 (already peer-supports vite 7)
  • create-opencanva core dep ^0.1.0 → ^0.2.0
  • Versions: @opencanva/core 0.1.1 → 0.2.0, create-opencanva 0.1.1 → 0.2.0

Why

npm audit reported 2 moderate / 2 high / 1 critical — all from the transitive jspdf@2 → dompurify chain plus vite@5 → esbuild. jspdf 4 drops the bundled DOMPurify (it's now optional + patched 3.4.11) and vite 7 ships a modern esbuild.

Result: 5 advisories → 1 low, and that one is the Windows-only, dev-server-only esbuild advisory (GHSA-g7r4-m6w7-qqqr) which doesn't apply to how Vite uses esbuild — documented as accepted in SECURITY.md.

No source changes needed

  • jspdf: the call site already uses the v4 named import + stable addImage/save, and the Export handler already try/catches → toast.
  • vite: the plugin hooks (server.ws, handleHotUpdate, transformIndexHtml, configureServer) and config keys are unchanged in v7.

Hardening (from the adversarial review)

  • engines.node (^20.19.0 || >=22.12.0) added to core, create-opencanva, and the scaffold template — old-Node users now get a clear EBADENGINE instead of a cryptic vite crash.
  • Node floor noted in README + CONTRIBUTING + the CI node pin.

⚠️ Publish order (required)

@opencanva/core@0.2.0 must be published before create-opencanva@0.2.0, otherwise npm create opencanva can't resolve the new ^0.2.0 range.

Verified by running (Node 26)

  • ✅ Typecheck (core / demo / template)
  • ✅ Dev renders, 0 errors/warnings, lint clean, Live sync (vite 7 HMR/ws path)
  • ✅ Export PNG / SVG / PDF (jspdf 4) — valid files, 0 errors
  • ✅ Production build (vite 7.3.5)
  • ✅ Cold standalone install renders (the blank-page scenario, on vite 7)
  • ✅ check:sync + isolated template scaffold-install-typecheck
  • ✅ Adversarial multi-agent compatibility review (vite7 / jspdf4 / resolution / consumers) — findings folded in

🤖 Generated with Claude Code

Bumps @opencanva/core deps: vite ^5.4.10 -> ^7.0.0, jspdf ^2.5.2 -> ^4.2.1,
@vitejs/plugin-react ^4.3.3 -> ^4.7.0. Clears the npm audit chain (was 2
moderate / 2 high / 1 critical, via old dompurify+esbuild) down to a single
low, Windows-only, dev-server-only esbuild advisory that does not apply to
Vite's usage (documented in SECURITY.md).

No source changes were needed: the jspdf call site already uses the v4 named
import + stable addImage/save API (and the Export handler already catches and
toasts failures), and the Vite plugin hooks (server.ws, handleHotUpdate,
transformIndexHtml, configureServer) are unchanged in v7.

create-opencanva: bump its core dep to ^0.2.0 (a ^0.1.0 pin would strand every
fresh 'npm create' project on the pre-upgrade core) and version to 0.2.0.
NOTE: @opencanva/core@0.2.0 must be published BEFORE create-opencanva@0.2.0,
else 'npm create opencanva' cannot resolve ^0.2.0.

Add engines.node (^20.19.0 || >=22.12.0, Vite 7's floor) to core,
create-opencanva, and the scaffold template so old-Node users get a clear
EBADENGINE instead of a cryptic crash; note the floor in README, CONTRIBUTING,
and the CI node pin.

Versions: @opencanva/core 0.1.1 -> 0.2.0, create-opencanva 0.1.1 -> 0.2.0.

Verified by running (Node 26): dev render + HMR/live-sync, PNG/SVG/PDF export,
production build, standalone cold-install render, all typechecks + CI gates.
Adversarial multi-agent review (vite7/jspdf4 compat, resolution, consumers)
folded in.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@daniellee-ux
daniellee-ux merged commit c49007c into main Jun 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant