Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@ jobs:
- name: Setup Node
uses: actions/setup-node@v4
with:
# Vite 7 requires Node ^20.19.0 || >=22.12.0 — keep this at/above that floor.
node-version: 22
cache: npm

Expand Down
2 changes: 2 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ the file contract, and the hard rules.

## Getting started

Requires **Node ≥ 20.19** (or ≥ 22.12) — the floor Vite 7 enforces.

```bash
npm install
npm run dev # → http://localhost:5173 ; open a design at /d/<id>
Expand Down
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@ discover files → virtual module → React component contract → click-t

## Quick start

> Requires **Node ≥ 20.19** (or ≥ 22.12) — the version Vite 7 needs.

**Start a new project** — nothing to clone; this scaffolds a project and pulls `@opencanva/core` from npm:

```bash
Expand Down
10 changes: 10 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,3 +50,13 @@ shapes what's in scope:
locally).

When in doubt, report it — we'd rather triage a non-issue than miss a real one.

## Known accepted advisories

- **esbuild dev-server file read on Windows** ([GHSA-g7r4-m6w7-qqqr](https://github.com/advisories/GHSA-g7r4-m6w7-qqqr)) —
surfaced transitively by `npm audit` via Vite's pinned `esbuild`. It is **low
severity, Windows-only, and dev-server-only**, and it concerns esbuild's *own*
`serve` mode, which Vite does not use. The patched esbuild is outside Vite 7's
declared range, so there is no clean in-range bump yet. Per the out-of-scope
policy above we'll inherit the fix when Vite widens its esbuild range. This sits
squarely within the "local, dev-time tool on localhost" threat model.
Loading
Loading