Files
kite/.planning/phases/08-stack-upgrade-backend-decomposition/08-08-SUMMARY.md
T
curo1305andClaude Sonnet 4.6 6bda133c81 chore(08-08): PERF-01 packages + Vite 6 upgrade + pin requirements.txt
- Upgraded vite 5.4.21 → 6.4.3 (fixes CVE-2026-39363, CVE-2026-39364)
- Upgraded @vitejs/plugin-vue 5.2.4 → 6.0.7 (Vite 6 peer dep)
- Installed @vueuse/core@14.3.0, @vueuse/integrations@14.3.0,
  sortablejs@1.15.7, @tailwindcss/forms@0.5.11,
  rollup-plugin-visualizer@7.0.1, @types/sortablejs@1.15.9
- Wired @tailwindcss/forms plugin in tailwind.config.js (VISUAL-02 ready)
- Pinned backend/requirements.txt to exact == versions per D-17 (32 packages)
- Frontend: 136/136 tests pass on Vite 6; 0 npm audit vulnerabilities
- Backend: 408 passed, 4 skipped, 7 xfailed (baseline 405+1)
- Phase 8 complete (8/8 plans)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-12 10:54:34 +02:00

92 lines
3.0 KiB
Markdown

---
phase: 08-stack-upgrade-backend-decomposition
plan: 08
status: complete
completed: 2026-06-12
---
# Plan 08-08 Summary — Dependency Upgrades (Wave 3)
## What Was Done
- Installed all PERF-01 frontend packages; upgraded Vite 5 → 6 resolving 2 moderate CVEs
- Wired `@tailwindcss/forms` plugin in `tailwind.config.js` (required for Phase 11 VISUAL-02)
- Pinned `backend/requirements.txt` from floating `>=` to exact `==` versions per D-17
## Human Checkpoint (Package Legitimacy)
User approved all 8 npm packages after security research instead of manual npmjs.com inspection.
CVE research confirmed:
- **vite 5.4.21 → 6.4.3**: Patched CVE-2026-39363 + CVE-2026-39364 (High, arbitrary file read via dev server). Relevant because `vite.config.js` uses `server.host: '0.0.0.0'`. Vite 8 was evaluated and rejected (breaking Rolldown changes out of phase scope).
- All other packages: no known CVEs in Snyk/OpenCVE as of 2026-06-12.
## Before / After: frontend/package.json
| Package | Before | After |
|---|---|---|
| vite | `^5.2.0` (installed 5.4.21) | `^6.4.3` (installed 6.4.3) |
| @vitejs/plugin-vue | `^5.0.0` (installed 5.2.4) | `^6.0.7` (installed 6.0.7) |
| vue | `^3.4.0` | `^3.5.38` |
| @vueuse/core | — | `^14.3.0` (14.3.0) |
| @vueuse/integrations | — | `^14.3.0` (14.3.0) |
| sortablejs | — | `^1.15.7` (1.15.7) |
| @tailwindcss/forms | — | `^0.5.11` (0.5.11) |
| rollup-plugin-visualizer | — | `^7.0.1` (7.0.1) |
| @types/sortablejs | — | `^1.15.9` (1.15.9) |
## Final backend/requirements.txt (pinned)
```
fastapi==0.128.8
uvicorn[standard]==0.49.0
python-multipart==0.0.32
pydantic-settings==2.14.1
pydantic[email]==2.13.4
anthropic==0.104.0
openai==2.41.0
PyMuPDF==1.27.2.3
python-docx==1.2.0
pytesseract==0.3.13
Pillow==12.2.0
aiofiles==25.1.0
httpx==0.28.1
pytest==9.0.3
pytest-asyncio==1.4.0
sqlalchemy[asyncio]==2.0.49
psycopg[binary]==3.2.13
# alembic pinned to currently-installed 1.16.5 (was >=1.18.4); D-17 mandates pinning to installed
alembic==1.16.5
minio==7.2.20
celery[redis]==5.6.3
redis==6.4.0
aiosqlite==0.22.1
PyJWT==2.13.0
pwdlib[argon2]==0.3.0
pyotp==2.9.0
slowapi==0.1.9
cryptography==48.0.0
google-auth-oauthlib==1.4.0
google-api-python-client==2.197.0
msal==1.37.0
webdavclient3==3.14.7
cachetools==7.1.4
structlog==25.5.0
```
## Test Results
- `cd frontend && npm test` — 136/136 passed on Vite 6 ✅
- `cd frontend && npm run build` — clean production build with Vite 6.4.3 ✅
- `cd frontend && npm audit` — 0 vulnerabilities (was 2 moderate on Vite 5) ✅
- `docker exec backend pytest -v` — 408 passed, 4 skipped, 7 xfailed ✅ (baseline was 405/1)
- `pip install -r requirements.txt --dry-run` — no resolution conflicts ✅
## Acceptance Criteria Met
- [x] All PERF-01 packages installed at correct versions
- [x] `@tailwindcss/forms` wired in `tailwind.config.js` (ready for Phase 11 VISUAL-02)
- [x] Vite 6 production build succeeds
- [x] `backend/requirements.txt` fully `==` pinned per D-17 (0 floating constraints)
- [x] All tests pass
- [x] Human checkpoint approved (CVE-informed, not just npmjs.com visual check)