Claude/magical franklin d6gsu5 - #12
Merged
Merged
Conversation
The README and the extension README linked to the latest release, which GitHub never resolves to a pre-release, so a reader was sent past the test build of the next version. Both now link to the releases page. doc/STANDALONE.md says that the one-line installers skip pre-releases and that a pre-release is tried by building the code. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
All 42 open Dependabot alerts (21 high, 16 medium, 5 low) were in the extension's package-lock.json, and every one came through @vscode/vsce, the packaging tool: undici, fast-uri, js-yaml, brace-expansion, markdown-it, linkify-it, form-data, tmp, qs, uuid, and lodash. These are development dependencies; the extension has no runtime dependencies and is packaged with --no-dependencies, so none of them is in the .vsix. npm audit fix updated them within the ranges package.json already allows, so only the lock file changes. Every alert's vulnerable range matched the old lock file and none matches the new one; npm audit reports no vulnerabilities. A clean npm ci compiles, the extension's 38 tests pass, and vsce packages the .vsix. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…ed up front msgpack-core 0.9.8 has CVE-2026-21452 (GHSA-cw39-r4h6-8j3x, high): readPayload(int) allocates the declared length before reading, so a header declaring 2 GB over a few bytes of data exhausts the heap. The parsed-log disk cache reader calls it for binary and extension values. That reader is not on the load path and reads only the server's own CRC-checked files, so the exposure was small, but the OutOfMemoryError escaped read()'s catch (Exception) instead of rejecting the file. 0.9.12 reads a declared length over 64 MB in chunks and fails when the input ends. A parameterized test writes a valid, checksummed cache file whose one value declares about 2 GB in BIN32 or EXT32 form, and checks that read() returns null while this thread allocates under 32 MB. On 0.9.8 it aborts the test run with "Java heap space"; on 0.9.12 it passes. Dependabot does not see Gradle dependencies, so this was found by querying OSV for the runtime classpath; the other eight runtime libraries have no known vulnerabilities. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…tests npm test ran node --test out/test/, and Node 21 and later reject a directory there, so the extension's tests could not run on a current Node. No single command line works everywhere: Node 20 takes a directory but no wildcard, Windows' shell does not expand one, and with no argument Node 22 also runs the TypeScript sources and declaration files. src/test/runTests.ts lists the compiled *.test.js files beside it and runs them in one node --test process; finding none is a failure. It is compiled into out/test, which is not packaged. CI only compiled the extension, which is why the failure went unseen. It now runs npm test on Linux and Windows. The 38 tests pass on Node 20.20 and 22.22; a failing test and an empty test directory each fail the run. doc/DEVELOPMENT.md and the changelog say so. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…'s libraries GitHub's dependency graph does not read build.gradle, so Dependabot only ever alerted on the extension's npm packages; the msgpack-core vulnerability in the server JAR was found by hand. A new CI job, on pushes to main only, runs gradle/actions/dependency-submission, which submits the dependencies Gradle resolves (runtime, test, and build plugins). It needs contents: write, granted to that job alone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
Without an order, the Settings editor lists an extension's settings alphabetically, which put Additional Log Directories before Log Directory. Each setting now has an order: the log directory, the additional directories, the team number, the TBA API key, Claude Code, then the Java path, the WPILib year, and the heap. The TBA API key setting was marked deprecated, and the Settings editor hides a deprecated setting that has no value, so there was no field for the key. It is now a write-only field: a key pasted into it is moved into VS Code's secret storage and the setting is cleared, so no settings file keeps it, and ignoreSync keeps Settings Sync from uploading it in the meantime. Its description links the commands that set the key in a masked box and remove it. The Settings editor writes a text setting each time typing pauses for a second, so a key is moved only after the field has been unchanged for three seconds; a key still being typed is not stored in pieces. Moves run one at a time, and no longer wait for their notification: one that nobody closed held up every later move. A key in the user's settings now replaces the stored key (it was ignored when one was stored, while the message said it was saved). A key in a workspace's settings still never replaces a stored key, since it may be a teammate's committed with the project, and the message now says which key is in use. The editor refreshes a focused field only once the user leaves it, so a key pasted into a field still showing the stored one is appended to it; the part after the stored key is taken as the new key. Changing the key field no longer restarts the server; storing the key does. The decisions are in src/tbaKey.ts, without the VS Code API, with tests; the manifest tests check the order, the field's declaration, and that every command a description links to is declared. In VS Code 1.101 and 1.140, driven through the real Settings editor: the order is as listed, a pasted key, a key typed with a pause, and a key pasted into a stale field each end up in secret storage exactly (read back from VS Code's store after it quit), settings.json keeps none of them, the description's link removes the stored key, and a key in a project's committed settings is removed from that file with a warning. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
build.gradle and, through syncExtensionVersion, the extension's package.json and lock file. The release workflow publishes a tag only when it matches this version. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…r once Found by the extension tests' first run on Windows CI. A relative log folder resolved inside the project has backslashes (C:\robot\logs), while the same folder given as an absolute path kept its forward slashes (C:/robot/logs). The paths were compared as strings, so the folder was passed to the server twice and its logs listed twice. A trailing separator, a .. segment, or another letter case did the same. Directories are now compared as the file system names them: normalized, without a trailing separator, and ignoring case on Windows. Each is passed normalized, the first spelling kept. combineLogDirectories takes the platform's path rules as an optional argument, so the tests check the Windows and the POSIX rules on every platform. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
The previous commit also passed every folder normalized, so on Windows "/logs" became "\logs", which changed what four tests pin down and failed them on Windows CI. Folders are compared as the file system names them, as before, but each is passed as written, the first spelling of a folder kept. Checked by running the directory tests with Node's Windows path rules in place of the platform's: they reproduce the five failures Windows CI reported against the previous commit, and pass with this one, except the home-folder test, which fails there only because this machine's home folder is a POSIX path; it passes on Windows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.