Moves phases 08–11 execution artifacts from .planning/phases/ to .planning/milestones/v0.2-phases/ to keep .planning/phases/ clean for the next milestone. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
3.0 KiB
3.0 KiB
phase, plan, status, completed
| phase | plan | status | completed |
|---|---|---|---|
| 08-stack-upgrade-backend-decomposition | 08 | complete | 2026-06-12 |
Plan 08-08 Summary — Dependency Upgrades (Wave 3)
What Was Done
- Installed all PERF-01 frontend packages; upgraded Vite 5 → 6 resolving 2 moderate CVEs
- Wired
@tailwindcss/formsplugin intailwind.config.js(required for Phase 11 VISUAL-02) - Pinned
backend/requirements.txtfrom floating>=to exact==versions per D-17
Human Checkpoint (Package Legitimacy)
User approved all 8 npm packages after security research instead of manual npmjs.com inspection. CVE research confirmed:
- vite 5.4.21 → 6.4.3: Patched CVE-2026-39363 + CVE-2026-39364 (High, arbitrary file read via dev server). Relevant because
vite.config.jsusesserver.host: '0.0.0.0'. Vite 8 was evaluated and rejected (breaking Rolldown changes out of phase scope). - All other packages: no known CVEs in Snyk/OpenCVE as of 2026-06-12.
Before / After: frontend/package.json
| Package | Before | After |
|---|---|---|
| vite | ^5.2.0 (installed 5.4.21) |
^6.4.3 (installed 6.4.3) |
| @vitejs/plugin-vue | ^5.0.0 (installed 5.2.4) |
^6.0.7 (installed 6.0.7) |
| vue | ^3.4.0 |
^3.5.38 |
| @vueuse/core | — | ^14.3.0 (14.3.0) |
| @vueuse/integrations | — | ^14.3.0 (14.3.0) |
| sortablejs | — | ^1.15.7 (1.15.7) |
| @tailwindcss/forms | — | ^0.5.11 (0.5.11) |
| rollup-plugin-visualizer | — | ^7.0.1 (7.0.1) |
| @types/sortablejs | — | ^1.15.9 (1.15.9) |
Final backend/requirements.txt (pinned)
fastapi==0.128.8
uvicorn[standard]==0.49.0
python-multipart==0.0.32
pydantic-settings==2.14.1
pydantic[email]==2.13.4
anthropic==0.104.0
openai==2.41.0
PyMuPDF==1.27.2.3
python-docx==1.2.0
pytesseract==0.3.13
Pillow==12.2.0
aiofiles==25.1.0
httpx==0.28.1
pytest==9.0.3
pytest-asyncio==1.4.0
sqlalchemy[asyncio]==2.0.49
psycopg[binary]==3.2.13
# alembic pinned to currently-installed 1.16.5 (was >=1.18.4); D-17 mandates pinning to installed
alembic==1.16.5
minio==7.2.20
celery[redis]==5.6.3
redis==6.4.0
aiosqlite==0.22.1
PyJWT==2.13.0
pwdlib[argon2]==0.3.0
pyotp==2.9.0
slowapi==0.1.9
cryptography==48.0.0
google-auth-oauthlib==1.4.0
google-api-python-client==2.197.0
msal==1.37.0
webdavclient3==3.14.7
cachetools==7.1.4
structlog==25.5.0
Test Results
cd frontend && npm test— 136/136 passed on Vite 6 ✅cd frontend && npm run build— clean production build with Vite 6.4.3 ✅cd frontend && npm audit— 0 vulnerabilities (was 2 moderate on Vite 5) ✅docker exec backend pytest -v— 408 passed, 4 skipped, 7 xfailed ✅ (baseline was 405/1)pip install -r requirements.txt --dry-run— no resolution conflicts ✅
Acceptance Criteria Met
- All PERF-01 packages installed at correct versions
@tailwindcss/formswired intailwind.config.js(ready for Phase 11 VISUAL-02)- Vite 6 production build succeeds
backend/requirements.txtfully==pinned per D-17 (0 floating constraints)- All tests pass
- Human checkpoint approved (CVE-informed, not just npmjs.com visual check)