Release 2026.10.3.1: clear 12 undici alerts, minor-and-patch group, pin ecowitt2mqtt - #68
Merged
Merged
Conversation
Supersedes #67, which CI rejected with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH: Dependabot regenerated pnpm-lock.yaml without the `pnpm.overrides` block. Re-resolved locally instead, keeping overrides intact. Security alerts cleared (12 -> 0, all undici, fixed in 7.29.1): - 11 of the 12 were reopened by #63. Its orval 8.34 bump pulled in @scalar/json-magic 0.13.5/0.14.0, which declare an exact `undici: 7.24.4` dependency, so a vulnerable copy landed beside the patched 7.29.1. #108 (TLS cert validation bypass) is new today. - Added an `undici: ^7.29.1` override floor. Bumping orval/scalar would not hold: json-magic 0.15.4 still pins undici exactly (7.29.1), so the next advisory would reopen this. The floor stays within 7.x, which is what json-magic's own newer releases already use. Also raised two existing floors for advisories published 2026-09-29 that GitHub has not alerted on yet: fast-uri ^3.1.8 and brace-expansion ^5.0.12. pnpm audit: 27 -> 1. The remaining one is braces 3.0.3 (GHSA-vfj7-8cjw-p6xm), which has no patched release; it is reached only through eslint-config-next's lint toolchain. minor-and-patch group (#67), at #67's exact targets: @tanstack/react-query 5.103.2, next/eslint-config-next 16.3.6, tailwind-merge 3.7.0, orval 8.37.0. pnpm's resolver picked react-query 5.104.1 and orval 8.39.0 (1-2 days old); held them back to respect the 7-day cooldown. Every newly added package version in the lockfile is at least 9 days old. Overrides use caret floors, not exact pins. Verified locally: pnpm install --frozen-lockfile succeeds; generate (byte-identical output under orval 8.37), tsc, lint and build clean; 601 tests pass. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
`:latest` resolves to upstream's newest tag, so a new ecowitt2mqtt release would be picked up with no change on our side. Upstream `dev` now carries our BGT/WBGT support (bachya/ecowitt2mqtt#1401), which unit-converts those fields; our parser's FAHRENHEIT_FIELDS also converts them, so the next release would double-convert silently (30 C stored as -1.1 C, inside the plausibility bounds). 2026.01.0 is the current `:latest` (same digest), so this changes nothing today. Bump the tag only in the same change that removes FAHRENHEIT_FIELDS. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
backend/uv.lock: only the editable app version line changed. Running `uv lock` with uv 0.12.22 also bumped the lockfile `revision` 3 -> 5; kept revision 3 because the Pi deploys with uv 0.11.3. Verified with uv 0.11.3 and 0.12.22 that `uv lock --check` passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #67, which CI rejected. Also pins the ecowitt2mqtt Docker image and bumps the version to 2026.10.3.1.
Three commits, meant to be rebase-merged so each stays distinct on
main:chore(deps): clear 12 undici alerts + minor-and-patch groupchore(docker): pin ecowitt2mqtt image to 2026.01.0chore(release): bump version to 2026.10.3.1Why #67 could not be merged
#67 failed with
ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Dependabot regeneratespnpm-lock.yamlwithout thepnpm.overridesblock, sopnpm install --frozen-lockfilerefuses the lockfile. This is the known failure mode. The fix is to re-resolve locally with overrides intact and supersede, never to merge as-is. #67 would also have left the vulnerable undici in place.Security alerts cleared (12 → 0)
All 12 open alerts are
undici(4 high, 6 medium, 2 low), every one fixed in 7.29.1.>= 7.24.1, < 7.29.1< 7.29.0< 7.28.0How they came back: #63's
orval8.34 bump pulled in@scalar/json-magic0.13.5 and 0.14.0. Both declare an exactundici: 7.24.4dependency, so a vulnerable copy landed next to the patched 7.29.1, and the 11 old alerts reopened the day #63 merged.Fix: a new
undici: ^7.29.1override floor. Bumping orval or scalar would not hold: the latest@scalar/json-magic(0.15.4) still pins undici exactly, at 7.29.1, so the next undici advisory would reopen this. The floor stays within 7.x, which is what json-magic's own newer releases already use. The lockfile now has a singleundici@7.29.1.Also raised (advisories published 2026-09-29, not yet alerted by GitHub)
brace-expansionfast-uripnpm audit: 27 → 1. The remaining finding isbraces3.0.3 (GHSA-vfj7-8cjw-p6xm), which has no patched release. It's reached only througheslint-config-next→fast-glob→micromatch(lint tooling, never shipped).All overrides use caret floors, not exact pins.
minor-and-patch group (#67)
At #67's exact targets:
@tanstack/react-query5.103.2,next/eslint-config-next16.3.6,tailwind-merge3.7.0,orval8.37.0.pnpm's resolver initially picked
@tanstack/react-query5.104.1 andorval8.39.0, which are 1–2 days old. Held them back to #67's versions to respect the 7-day cooldown. Every newly added package version in the lockfile is at least 9 days old.Pin ecowitt2mqtt to 2026.01.0
docker/docker-compose.ymlusedbachya/ecowitt2mqtt:latest, which follows upstream's newest tag. Upstreamdevnow carries our BGT/WBGT support (bachya/ecowitt2mqtt#1401), which unit-converts those fields. Our parser'sFAHRENHEIT_FIELDSalso converts them, so the next upstream release would double-convert silently (30 °C stored as −1.1 °C, inside the plausibility bounds).2026.01.0is the current:latest(same digest), so nothing changes today. A comment on the service says to bump the tag only in the same change that removesFAHRENHEIT_FIELDS. Verified withdocker compose config.Version bump
backend/pyproject.toml,frontend/package.jsonandbackend/uv.lock→ 2026.10.3.1. Only the editable app version line changed inuv.lock: uv 0.12.22 also wanted to bump the lockfilerevision3 → 5, which I kept at 3 because the Pi deploys with uv 0.11.3.uv lock --checkpasses under both versions.Verification
Ran the frontend CI gate locally:
pnpm install --frozen-lockfile: succeeds (the exact step that failed on chore(deps): bump the minor-and-patch group across 1 directory with 5 updates #67)generate: byte-identical output under orval 8.37tsc --noEmit,lint,build: all cleanBackend dependencies are untouched (no Python alerts open); only its version changed.
🤖 Generated with Claude Code
https://claude.ai/code/session_019gQzmEKmJbrYsUybsYrMFM