This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Media Servers
✓ No known CVEs patched
This release patches 1 known CVE
Affected surfaces
deps
Summary
AI summaryRemoval of unused packages and replacement of the abandoned github-api library resolves a high‑severity vulnerability.
Full changelog
What's Changed
- Remove 17 unused packages (antd, sequelize, passport, passport-jwt, github-api, axios-cache-interceptor, http-proxy-middleware, config, dns-cache, dottie, randomcolor, semver, react-scripts, check-valid-url, dottie, and @testing-library/* leftovers from CRA template)
- Replace github-api (abandoned, bundled [email protected] CVE) with direct axios call to GitHub Contents API — resolves 1 high severity vulnerability
- Upgrade to Vite 8 + @vitejs/plugin-react-swc@4, rewrite vite.config.js with rolldown-compatible manualChunks function and loadEnv for JS_BASE_URL
- Update Dockerfile to node:26-bookworm-slim with apt-get upgrade, reducing image CVEs from 3 high to 2 high
- Drop CRA boilerplate: App.test.jsx, setupTests.js, eslintConfig block
https://github.com/CyferShepard/Jellystat/pull/530
New Contributors
- @at-besa made their first contribution in https://github.com/CyferShepard/Jellystat/pull/530
Full Changelog: https://github.com/CyferShepard/Jellystat/compare/1.1.10...1.1.11
Breaking Changes
- Removed unused packages: antd, sequelize, passport, passport-jwt, github-api, axios-cache-interceptor, http-proxy-middleware, config, dns-cache, dottie, randomcolor, semver, react-scripts, check-valid-url, @testing-library/* leftovers
- Replaced github-api (abandoned) with direct axios call to GitHub Contents API
Security Fixes
- Replaced github-api (bundled [email protected] vulnerable) resolving 1 high severity vulnerability
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]