Skip to content

docs: replace ASCII architecture with Mermaid diagram - #10

Merged
Vishnu2707 merged 5 commits into
mainfrom
dev
Apr 25, 2026
Merged

Vishnu2707 merged 5 commits into
mainfrom
dev

Conversation

@Vishnu2707

Copy link
Copy Markdown
Collaborator

No description provided.

@Vishnu2707 Vishnu2707 self-assigned this Apr 25, 2026
@Vishnu2707 Vishnu2707 added the documentation Improvements or additions to documentation label Apr 25, 2026
@Vishnu2707
Vishnu2707 merged commit a5fbb71 into main Apr 25, 2026
Vishnu2707 pushed a commit that referenced this pull request Jul 31, 2026
* fix: resolve all open security alerts (8 Dependabot + 1 CodeQL)

Closes #221.

Dependency vulnerabilities:
- react-router-dom (root and frontend) replaced with react-router 8.3.0.
  react-router v8 dropped the react-router-dom re-export package, so this
  is an import migration, not just a version bump: all 9 files that
  imported from react-router-dom (BrowserRouter, Routes, Route, Navigate,
  useLocation, useNavigate, NavLink, Outlet) now import from react-router
  directly, matching v8's actual export surface (react-router/dom only
  ships RouterProvider/HydratedRouter, which nothing here uses). Fixes
  Dependabot alerts #12, #10, #8, #7, #6, #5.
- postcss bumped to 8.5.18+ (resolved to 8.5.25). Fixes alert #9.
- brace-expansion bumped to 5.0.9 via npm audit fix, clearing both the
  originally reported alert #4 (exponential-time expansion DoS) and a
  second advisory affecting versions up to and including 5.0.7
  (out-of-memory DoS) that the requested 5.0.7 floor would not have
  cleared on its own.

CodeQL alert #31 (py/clear-text-logging-sensitive-data):
- scanner/rules/az_idn_006.py logged the raw endDateTime value from a
  service principal's password credential when it failed to parse.
  Drops the value from the log line entirely; app_id alone is sufficient
  to correlate the failure. Matches the fix already proposed in draft PR
  #220, which this supersedes.
- Strengthened the existing regression test to also assert the malformed
  endDateTime value itself never reaches the logs (it previously only
  checked keyId), and verified the test fails against the pre-fix code
  before restoring the fix.

Added node_modules/ to the root .gitignore - the root package.json exists
only to give Dependabot a manifest to track react-router against, but
running npm install there to regenerate its lockfile was leaving an
untracked node_modules/ with nothing preventing it from being committed.

Verified: npm audit clean (root and frontend, 0 vulnerabilities each),
frontend build and lint pass, ruff check/format clean, full pytest suite
passes (437 passed, 2 pre-existing failures unrelated to this change -
local chromadb version mismatch, not present in CI).

Signed-off-by: Tanvir Farhad <tamimtarafder12@gmail.com>

* style: fix ruff format drift on markdown-embedded Python examples

CI's ruff (unpinned) reformatted the embedded code fences in
CONTRIBUTING.md, docs/adding-a-rule.md, and docs/architecture.md again
since the last fix in b9d4538 - whitespace only, no content changes.

Signed-off-by: Tanvir Farhad <tamimtarafder12@gmail.com>

* fix: declare react-router 8.3.0's runtime requirements per review

react-router@8.3.0 requires Node >=22.22.0 and react/react-dom
>=19.2.7 (peer deps). Bump the declared React floors, add an
engines.node field to frontend/package.json, and pin CI's frontend
job to Node 22.22.0 so the requirement is enforced rather than
relying on "latest 22.x" happening to be new enough.

Addresses ritiksah141's CHANGES_REQUESTED review on PR #222.

Signed-off-by: Tanvir Farhad <tamimtarafder12@gmail.com>

---------

Signed-off-by: Tanvir Farhad <tamimtarafder12@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant