Commit Graph

2023 Commits (2fe590f948122d7103a02efd300696ea37268f99)
 

Author SHA1 Message Date
dependabot[bot] 2fe590f948
Bump express-rate-limit from 8.2.1 to 8.3.0 in /backend
Bumps [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) from 8.2.1 to 8.3.0.
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.2.1...v8.3.0)

---
updated-dependencies:
- dependency-name: express-rate-limit
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
voc0der 4b3d738e34
Merge pull request #112 from voc0der/fix/dependabot-tar-hardlink-path-traversal
fix(deps): bump tar to 7.5.10 to resolve advisory
2 months ago
voc0der 10a851d00e fix(deps): patch tar hardlink traversal advisory 2 months ago
voc0der 0c036b6115
Merge pull request #111 from voc0der/chore/sync-upstream-security-findings
chore: sync upstream and lock patched security deps
2 months ago
voc0der 530f318844 docs(readme): remove iOS shortcut section 2 months ago
voc0der 36e6fe0512 chore(security): pin patched immutable and multer versions 2 months ago
voc0der 91533fa5c3 Merge remote-tracking branch 'upstream/master' into chore/sync-upstream-security-findings
# Conflicts:
#	README.md
2 months ago
voc0der 0918cbbaed
Merge pull request #107 from voc0der/dependabot/npm_and_yarn/immutable-5.1.5
Bump immutable from 5.1.4 to 5.1.5
2 months ago
voc0der 2d2d2898df
Merge pull request #108 from voc0der/dependabot/npm_and_yarn/backend/multer-2.1.1
Bump multer from 2.1.0 to 2.1.1 in /backend
2 months ago
voc0der 065e13c3f9
Merge pull request #109 from voc0der/dependabot/github_actions/dot-github/workflows/docker/setup-buildx-action-4
Bump docker/setup-buildx-action from 3 to 4 in /.github/workflows
2 months ago
voc0der 0f853819ed
Merge pull request #110 from voc0der/dependabot/npm_and_yarn/angular-toolchain-8142e20a17
Bump the angular-toolchain group with 13 updates
2 months ago
dependabot[bot] 0c7808eda9
Bump the angular-toolchain group with 13 updates
Bumps the angular-toolchain group with 13 updates:

| Package | From | To |
| --- | --- | --- |
| [@angular/animations](https://github.com/angular/angular/tree/HEAD/packages/animations) | `21.2.0` | `21.2.1` |
| [@angular/cdk](https://github.com/angular/components) | `21.2.0` | `21.2.1` |
| [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common) | `21.2.0` | `21.2.1` |
| [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) | `21.2.0` | `21.2.1` |
| [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core) | `21.2.0` | `21.2.1` |
| [@angular/forms](https://github.com/angular/angular/tree/HEAD/packages/forms) | `21.2.0` | `21.2.1` |
| [@angular/localize](https://github.com/angular/angular) | `21.2.0` | `21.2.1` |
| [@angular/material](https://github.com/angular/components) | `21.2.0` | `21.2.1` |
| [@angular/platform-browser](https://github.com/angular/angular/tree/HEAD/packages/platform-browser) | `21.2.0` | `21.2.1` |
| [@angular/platform-browser-dynamic](https://github.com/angular/angular/tree/HEAD/packages/platform-browser-dynamic) | `21.2.0` | `21.2.1` |
| [@angular/router](https://github.com/angular/angular/tree/HEAD/packages/router) | `21.2.0` | `21.2.1` |
| [@angular/compiler-cli](https://github.com/angular/angular/tree/HEAD/packages/compiler-cli) | `21.2.0` | `21.2.1` |
| [@angular/language-service](https://github.com/angular/angular/tree/HEAD/packages/language-service) | `21.2.0` | `21.2.1` |


Updates `@angular/animations` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/animations)

Updates `@angular/cdk` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/components/releases)
- [Changelog](https://github.com/angular/components/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/components/compare/v21.2.0...v21.2.1)

Updates `@angular/common` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/common)

Updates `@angular/compiler` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/compiler)

Updates `@angular/core` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/core)

Updates `@angular/forms` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/forms)

Updates `@angular/localize` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/compare/v21.2.0...v21.2.1)

Updates `@angular/material` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/components/releases)
- [Changelog](https://github.com/angular/components/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/components/compare/v21.2.0...v21.2.1)

Updates `@angular/platform-browser` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/platform-browser)

Updates `@angular/platform-browser-dynamic` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/platform-browser-dynamic)

Updates `@angular/router` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/router)

Updates `@angular/compiler-cli` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/compiler-cli)

Updates `@angular/language-service` from 21.2.0 to 21.2.1
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.1/packages/language-service)

---
updated-dependencies:
- dependency-name: "@angular/animations"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/cdk"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/common"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/compiler"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/core"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/forms"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/localize"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/material"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/platform-browser"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/platform-browser-dynamic"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/router"
  dependency-version: 21.2.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/compiler-cli"
  dependency-version: 21.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
- dependency-name: "@angular/language-service"
  dependency-version: 21.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: angular-toolchain
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
dependabot[bot] d209bc062e
Bump docker/setup-buildx-action from 3 to 4 in /.github/workflows
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3 to 4.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](https://github.com/docker/setup-buildx-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
dependabot[bot] a2bfa10028
Bump multer from 2.1.0 to 2.1.1 in /backend
Bumps [multer](https://github.com/expressjs/multer) from 2.1.0 to 2.1.1.
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](https://github.com/expressjs/multer/compare/v2.1.0...v2.1.1)

---
updated-dependencies:
- dependency-name: multer
  dependency-version: 2.1.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
dependabot[bot] 48516f00fa
Bump immutable from 5.1.4 to 5.1.5
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.4 to 5.1.5.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/immutable-js/immutable-js/compare/v5.1.4...v5.1.5)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
Glassed Silver 072210b605
Merge pull request #1144 from ItsOpenSourceSoftware/patch-1
Update README.md
2 months ago
Glassed Silver 5b0ec39dcd
Merge pull request #1141 from weblate/weblate-youtubedl-material-ytdl-material
Translations update from Hosted Weblate
2 months ago
voc0der 0cbada0fa1
Merge pull request #106 from voc0der/fix/dependabot-hono-security-20260304
fix: patch vulnerable hono transitive dependencies
2 months ago
voc0der 0c56a055c2 fix: patch vulnerable hono transitive dependencies 2 months ago
voc0der b8cdf95bf2
Merge pull request #105 from voc0der/chore/dependabot-batch-2026-03-04
Batch dependabot updates (#101-#104) + fix flaky docker build
2 months ago
voc0der 78a56ac13e Retry TwitchDownloader latest release lookup 2 months ago
dependabot[bot] 2bffa2d7ff Bump fs-extra from 11.3.3 to 11.3.4
Bumps [fs-extra](https://github.com/jprichardson/node-fs-extra) from 11.3.3 to 11.3.4.
- [Changelog](https://github.com/jprichardson/node-fs-extra/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jprichardson/node-fs-extra/compare/11.3.3...11.3.4)

---
updated-dependencies:
- dependency-name: fs-extra
  dependency-version: 11.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
dependabot[bot] 8c6ffbd278 Bump fs-extra from 11.3.3 to 11.3.4 in /backend
Bumps [fs-extra](https://github.com/jprichardson/node-fs-extra) from 11.3.3 to 11.3.4.
- [Changelog](https://github.com/jprichardson/node-fs-extra/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jprichardson/node-fs-extra/compare/11.3.3...11.3.4)

---
updated-dependencies:
- dependency-name: fs-extra
  dependency-version: 11.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
dependabot[bot] e3938c7432 Bump docker/setup-qemu-action from 3 to 4 in /.github/workflows
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3 to 4.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](https://github.com/docker/setup-qemu-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
dependabot[bot] 47782a9ecc Bump docker/login-action from 3 to 4 in /.github/workflows
Bumps [docker/login-action](https://github.com/docker/login-action) from 3 to 4.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
voc0der ea09a8a9c9 Fix OIDC handling for hash-based share links 2 months ago
voc0der be179d8376
Merge pull request #100 from voc0der/fix/lowdb-v7-compat
chore: consolidate backend dependency bumps and lowdb v7 compatibility
2 months ago
voc0der 9b2278b9b3 chore: include md5 and axios bumps in consolidated update 2 months ago
dependabot[bot] b9d2ff2c01 Bump body-parser from 1.20.4 to 2.2.2 in /backend
Bumps [body-parser](https://github.com/expressjs/body-parser) from 1.20.4 to 2.2.2.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](https://github.com/expressjs/body-parser/compare/1.20.4...v2.2.2)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
voc0der d867bf6fed fix: add lowdb v7 compatibility layer for legacy API 2 months ago
dependabot[bot] 9c34ef0b65 Bump lowdb from 1.0.0 to 7.0.1 in /backend
Bumps [lowdb](https://github.com/typicode/lowdb) from 1.0.0 to 7.0.1.
- [Release notes](https://github.com/typicode/lowdb/releases)
- [Commits](https://github.com/typicode/lowdb/compare/v1.0.0...v7.0.1)

---
updated-dependencies:
- dependency-name: lowdb
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
voc0der 47d5124e5d
Merge pull request #94 from voc0der/chore/dependency-bumps-oidc-multiuser-docs
chore: consolidate package bumps with OIDC/multiuser docs
2 months ago
voc0der 6b943749a3 chore: consolidate dependency bumps and OIDC/multiuser docs 2 months ago
voc0der 621a02dde5 fix(docker): fail fast when ffprobe is missing in utils stage 2 months ago
voc0der d5581e1012 chore: patch multer and transitive security advisories 2 months ago
voc0der f99edc816e
Merge pull request #85 from voc0der/feature/oidc
feat: OIDC SSO with multi-user enforcement and ownership isolation
2 months ago
voc0der 798b7d083c fix: migrate unassigned playlists with OIDC ownership mapping 2 months ago
voc0der f6afb52808 fix: harden shared access checks for playlists and files 2 months ago
voc0der a84d08e64f feat: add OIDC auth flow with multi-user enforcement 2 months ago
voc0der 90dd796f18
Merge pull request #83 from voc0der/dependabot/npm_and_yarn/backend/multi-5d5195985e
Bump minimatch in /backend
2 months ago
dependabot[bot] 6f7787a670
Bump minimatch in /backend
Bumps  and [minimatch](https://github.com/isaacs/minimatch). These dependencies needed to be updated together.

Updates `minimatch` from 9.0.6 to 9.0.9
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](https://github.com/isaacs/minimatch/compare/v9.0.6...v9.0.9)

Updates `minimatch` from 5.1.7 to 5.1.9
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](https://github.com/isaacs/minimatch/compare/v9.0.6...v9.0.9)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-version: 9.0.9
  dependency-type: indirect
- dependency-name: minimatch
  dependency-version: 5.1.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
voc0der 491ddd3da8
Merge pull request #82 from voc0der/chore/depupgrade27
chore: consolidate open dependabot upgrades
2 months ago
voc0der c12572f5e1 fix: make twitchdownloader download resilient to transient 5xx 2 months ago
voc0der 8fef327c84 fix: tolerate non-zero exit in twitchdownloader smoke test 2 months ago
voc0der b90b34ada1 chore: consolidate dependabot upgrades and fix docker build 2 months ago
voc0der 3cd1b3f8f1
Merge pull request #70 from voc0der/fix/frontend-tests-zero-fail
Fix frontend Karma test discovery and shallow spec failures
2 months ago
voc0der 184dc2f4f7 Fix frontend test harness and flaky shallow specs 2 months ago
voc0der aba5346523 Consolidate dependabot dependency updates 2 months ago
voc0der 48706bd075 Refresh docs and Docker Compose defaults 2 months ago
voc0der e17456fdc1 Fix immediate notification card removal 2 months ago