From 746e7b7c2f22214699f61d1d4e8e844fa67f6793 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 10:32:00 +0000 Subject: [PATCH 1/2] fix(deps-dev): bump force-graph from 1.51.4 to 1.51.5 Bumps [force-graph](https://github.com/vasturiano/force-graph) from 1.51.4 to 1.51.5. - [Commits](https://github.com/vasturiano/force-graph/compare/v1.51.4...v1.51.5) --- updated-dependencies: - dependency-name: force-graph dependency-version: 1.51.5 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index 22539e52..f31c3893 100644 --- a/package-lock.json +++ b/package-lock.json @@ -10,7 +10,7 @@ "devDependencies": { "@axe-core/playwright": "^4.10.0", "@playwright/test": "^1.63.0", - "force-graph": "1.51.4", + "force-graph": "1.51.5", "impeccable": "4.1.0" } }, @@ -430,9 +430,9 @@ } }, "node_modules/force-graph": { - "version": "1.51.4", - "resolved": "https://registry.npmjs.org/force-graph/-/force-graph-1.51.4.tgz", - "integrity": "sha512-TdJ2KbkoiDQ7NIRx8IPGD0mAXXpLhamS7c+b7W98b0MHG7lphnda1VOQX/98UDTsttIAdH4TcP0l0MauSnLK8w==", + "version": "1.51.5", + "resolved": "https://registry.npmjs.org/force-graph/-/force-graph-1.51.5.tgz", + "integrity": "sha512-MvpxTSIOKyTYZz7XPVGGCSb9VePhyIvmCiDyPswjsiTZKlWDfFL0FDqyduWTLPk/UdOnulQESNGxTbWH0yM2cA==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index a17c8aa6..51ff9f9c 100644 --- a/package.json +++ b/package.json @@ -1 +1 @@ -{"name":"engraphis-tests","version":"1.0.0","private":true,"description":"Browser accessibility, e2e, vendored bundle provenance, and design-quality dependencies for Engraphis","scripts":{"test:e2e":"playwright test"},"devDependencies":{"@playwright/test":"^1.63.0","@axe-core/playwright":"^4.10.0","force-graph":"1.51.4","impeccable":"4.1.0"}} \ No newline at end of file +{"name":"engraphis-tests","version":"1.0.0","private":true,"description":"Browser accessibility, e2e, vendored bundle provenance, and design-quality dependencies for Engraphis","scripts":{"test:e2e":"playwright test"},"devDependencies":{"@playwright/test":"^1.63.0","@axe-core/playwright":"^4.10.0","force-graph":"1.51.5","impeccable":"4.1.0"}} \ No newline at end of file From 9c165fe9f296b3d2eab48c71de66bb52ca33d6d4 Mon Sep 17 00:00:00 2001 From: Coding-Dev-Tools Date: Thu, 1 Oct 2026 06:46:31 -0400 Subject: [PATCH 2/2] fix(deps): require complete force-graph vendor upgrades --- .github/dependabot.yml | 8 +++++++ docs/DASHBOARD_VENDOR_ASSETS.md | 40 +++++++++++++++++++++++++++++++++ package-lock.json | 8 +++---- package.json | 2 +- 4 files changed, 53 insertions(+), 5 deletions(-) create mode 100644 docs/DASHBOARD_VENDOR_ASSETS.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml index b01fdefe..f29e84be 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -20,6 +20,14 @@ updates: schedule: interval: "weekly" open-pull-requests-limit: 3 + # The shipped force-graph bundle has local CSP patches and locked provenance. + # Version upgrades follow docs/DASHBOARD_VENDOR_ASSETS.md; security updates remain enabled. + ignore: + - dependency-name: "force-graph" + update-types: + - "version-update:semver-major" + - "version-update:semver-minor" + - "version-update:semver-patch" labels: - "dependencies" - package-ecosystem: "docker" diff --git a/docs/DASHBOARD_VENDOR_ASSETS.md b/docs/DASHBOARD_VENDOR_ASSETS.md new file mode 100644 index 00000000..c558ea21 --- /dev/null +++ b/docs/DASHBOARD_VENDOR_ASSETS.md @@ -0,0 +1,40 @@ +# Dashboard vendor updates + +The dashboard serves committed browser bundles. The force-graph npm dependency +records their reviewed upstream version; changing that dependency alone does not +update the served code and breaks the version/provenance checks. + +The reviewed force-graph version is 1.51.4. All three shipped copies contain two +local CSP changes that disable runtime stylesheet insertion. Equivalent static +rules live in the dashboard stylesheets. The bundle also has an exact upstream +commit, npm integrity, source lock and dependency license inventory. + +The [upstream 1.51.5 comparison](https://github.com/vasturiano/force-graph/compare/v1.51.4...v1.51.5) +changes examples, development tooling, package version and yarn lock, with no +graph runtime source change. Retaining the reviewed bundle avoids presenting a +metadata-only dependency bump as a shipped runtime upgrade. + +Dependabot ignores automatic force-graph version updates. The three +`version-update:semver-*` rules do not disable security updates. A security update +still needs the complete vendor review below before merge. + +For a deliberate force-graph upgrade: + +1. Verify the exact upstream release artifact, npm integrity, source commit and + source lock. Review the runtime diff and the locked dependency closure. +2. Preserve both CSP patches and their equivalent static CSS. Update the bundles + and license copies in `engraphis/dashboard_assets/vendor/`, + `engraphis/classic_assets/vendor/` and `engraphis/static/vendor/` together. +3. Regenerate the vendor manifest's version, source and hashes, plus the complete + locked dependency license inventory in `deploy/`. Record actual artifact and + source-lock hashes; do not relabel the previous bundle or inventory. +4. Update `package.json`, `package-lock.json`, `NOTICE`, and the explicit license + inventory/source-lock packaging references in `MANIFEST.in`, `pyproject.toml` + and `scripts/verify_distribution_contents.py`. Update the corresponding exact + provenance assertions in `tests/test_packaging.py` to the reviewed new inputs. +5. Run the vendor integrity, packaging and asset externalization tests. Run the + browser graph/CSP suite against the real vendored bundle, then build a wheel + and source archive and verify them with `scripts/verify_distribution_contents.py`. + +Keep version, hash, license and CSP checks enabled throughout the upgrade. No +current dependency pin or upstream release alone proves those validations. diff --git a/package-lock.json b/package-lock.json index f31c3893..22539e52 100644 --- a/package-lock.json +++ b/package-lock.json @@ -10,7 +10,7 @@ "devDependencies": { "@axe-core/playwright": "^4.10.0", "@playwright/test": "^1.63.0", - "force-graph": "1.51.5", + "force-graph": "1.51.4", "impeccable": "4.1.0" } }, @@ -430,9 +430,9 @@ } }, "node_modules/force-graph": { - "version": "1.51.5", - "resolved": "https://registry.npmjs.org/force-graph/-/force-graph-1.51.5.tgz", - "integrity": "sha512-MvpxTSIOKyTYZz7XPVGGCSb9VePhyIvmCiDyPswjsiTZKlWDfFL0FDqyduWTLPk/UdOnulQESNGxTbWH0yM2cA==", + "version": "1.51.4", + "resolved": "https://registry.npmjs.org/force-graph/-/force-graph-1.51.4.tgz", + "integrity": "sha512-TdJ2KbkoiDQ7NIRx8IPGD0mAXXpLhamS7c+b7W98b0MHG7lphnda1VOQX/98UDTsttIAdH4TcP0l0MauSnLK8w==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index 51ff9f9c..a17c8aa6 100644 --- a/package.json +++ b/package.json @@ -1 +1 @@ -{"name":"engraphis-tests","version":"1.0.0","private":true,"description":"Browser accessibility, e2e, vendored bundle provenance, and design-quality dependencies for Engraphis","scripts":{"test:e2e":"playwright test"},"devDependencies":{"@playwright/test":"^1.63.0","@axe-core/playwright":"^4.10.0","force-graph":"1.51.5","impeccable":"4.1.0"}} \ No newline at end of file +{"name":"engraphis-tests","version":"1.0.0","private":true,"description":"Browser accessibility, e2e, vendored bundle provenance, and design-quality dependencies for Engraphis","scripts":{"test:e2e":"playwright test"},"devDependencies":{"@playwright/test":"^1.63.0","@axe-core/playwright":"^4.10.0","force-graph":"1.51.4","impeccable":"4.1.0"}} \ No newline at end of file