Skip to content

Upgrade dependencies, Node 24, and PostgreSQL 18 - #31

Merged
shobhit-seg merged 1 commit into
mainfrom
codex/dependency-security-node24-pg18
Aug 3, 2026
Merged

shobhit-seg merged 1 commit into
mainfrom
codex/dependency-security-node24-pg18

Conversation

@shobhit-seg

Copy link
Copy Markdown
Collaborator

Summary

  • remediate reported npm vulnerabilities across direct and transitive dependencies
  • upgrade the application runtime to Node 24.18.0 and align local, CI, Amplify, and Docker pins
  • upgrade the local PostgreSQL service to 18.4 with the PostgreSQL 18 volume layout
  • harden the runtime image, pin CI actions by commit SHA, and replace MailHog with a scanned Mailpit digest
  • migrate the frontend to React 19 and React Router 8 where required by advisory fixes

Validation

  • pnpm audit --json: 0 vulnerabilities across 585 dependencies
  • pnpm audit --prod --json: 0 vulnerabilities across 330 dependencies
  • pnpm lint
  • pnpm typecheck
  • pnpm test: 32 tests passed
  • pnpm build
  • Node 24 native better-sqlite3 smoke test
  • PostgreSQL 18.4 startup/query smoke test
  • production image archive build and Trivy scan: 0 high/critical findings

Notes

  • PostgreSQL schema and migration files are unchanged.
  • Compose uses a new pgdata18 volume, preserving any existing local PostgreSQL 16 volume rather than starting it under an incompatible major.
  • The official PostgreSQL 18.4 Alpine image still has upstream scanner findings in bundled gosu plus one Alpine package finding; it was substantially cleaner than the official Debian variant.
  • No repository .env file was read during validation.

@shobhit-seg
shobhit-seg added this pull request to the merge queue Aug 3, 2026
Merged via the queue into main with commit f1d9f99 Aug 3, 2026
1 check passed
@shobhit-seg
shobhit-seg deleted the codex/dependency-security-node24-pg18 branch August 3, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants