mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
* fix(security): xlsx CVE bump and bundled security hardening * fix(stripe): use configured secret key for SDK init Avoids leaving a recognisable placeholder string in heap dumps and error serialisations. Webhook verification remains a purely local HMAC operation; the SDK's constructor key is unused by it. Addresses Greptile feedback on #4481. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(stripe): use static Stripe.webhooks for verification Avoids instantiating a Stripe client just to access constructEvent. The webhook signing secret is per-trigger (user-provided whsec_…) and unrelated to our billing STRIPE_SECRET_KEY, so coupling them was wrong. Stripe.webhooks is exposed as a static — no client, no API key needed. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(ci): revert client-bundled tools to avoid .server import in client * fix(security): collapse 403 to 404 on v1 detail-by-ID routes * chore(security): remove unused validateAgiloftInstanceUrl helper * fix(security): bump minimatch + clean up scripts/ workspace Resolves CVE-2026-27903 (GHSA-7r86-cg39-jmmj) by adding a root-level minimatch ^10.2.5 override. Also resolves CVE-2026-0969 in next-mdx-remote (bumped to ^6.0.0). Cleanup: - Make scripts/ a proper bun workspace (root workspaces array) - Remove duplicate scripts/package-lock.json (this repo uses bun) - Remove redundant scripts/bun.lock (now hoisted to root) - Remove vestigial scripts/setup-doc-generator.sh - Slim scripts/package.json to its real deps (glob, yaml) - Gitignore stray package-lock.json files - Update scripts/README.md Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
87 lines
1.1 KiB
Plaintext
87 lines
1.1 KiB
Plaintext
# See https://help.github.com/articles/ignoring-files/ for more about ignoring files.
|
|
|
|
# dependencies
|
|
/node_modules
|
|
/apps/**/node_modules
|
|
/packages/**/node_modules
|
|
/scripts/node_modules
|
|
|
|
# bun specific
|
|
bun-debug.log*
|
|
|
|
# this repo uses bun.lock; package-lock.json files are accidental
|
|
package-lock.json
|
|
|
|
# testing
|
|
/coverage
|
|
/apps/**/coverage
|
|
|
|
# next.js
|
|
/.next/
|
|
/apps/**/out/
|
|
/apps/**/.next/
|
|
/apps/**/build
|
|
|
|
# production
|
|
/build
|
|
/dist
|
|
**/dist/
|
|
**/standalone/
|
|
sim-standalone.tar.gz
|
|
|
|
# redis
|
|
dump.rdb
|
|
|
|
# misc
|
|
.DS_Store
|
|
*.pem
|
|
|
|
# env files
|
|
.env
|
|
*.env
|
|
.env.local
|
|
.env.development
|
|
.env.test
|
|
.env.production
|
|
|
|
# vercel
|
|
.vercel
|
|
|
|
# typescript
|
|
*.tsbuildinfo
|
|
next-env.d.ts
|
|
|
|
# cursorrules
|
|
# .cursorrules
|
|
|
|
# docs
|
|
/apps/docs/.source
|
|
/apps/docs/.contentlayer
|
|
/apps/docs/.content-collections
|
|
|
|
# database instantiation
|
|
**/postgres_data/
|
|
|
|
# collector configuration
|
|
collector-config.yaml
|
|
docker-compose.collector.yml
|
|
start-collector.sh
|
|
|
|
# Turborepo
|
|
.turbo
|
|
|
|
# VSCode
|
|
.vscode
|
|
|
|
# IntelliJ
|
|
.idea
|
|
|
|
## Helm Chart Tests
|
|
helm/sim/test
|
|
i18n.cache
|
|
|
|
## Claude Code
|
|
.claude/launch.json
|
|
.claude/worktrees/
|
|
.claude/scheduled_tasks.lock
|