Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 38 additions & 4 deletions .github/workflows/prepare-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -120,20 +120,54 @@ jobs:

if grep -q "^## \[${VERSION_NO_V}\]" CHANGELOG.md 2>/dev/null; then
echo "changelog_exists=true" >> "$GITHUB_OUTPUT"
echo "from_unreleased=false" >> "$GITHUB_OUTPUT"
echo "Changelog section for [${VERSION_NO_V}] already exists. Skipping generation."
exit 0
fi

echo "changelog_exists=false" >> "$GITHUB_OUTPUT"
# Prefer a curated [Unreleased] section when present: promote it to the release version
# instead of generating entries from the commit history.
FROM_UNRELEASED=false
if grep -q "^## \[Unreleased\]" CHANGELOG.md 2>/dev/null; then
FROM_UNRELEASED=true
echo "changelog_exists=true" >> "$GITHUB_OUTPUT"
echo "from_unreleased=true" >> "$GITHUB_OUTPUT"
echo "Found [Unreleased] section. Promoting it to [${VERSION_NO_V}]."
else
echo "changelog_exists=false" >> "$GITHUB_OUTPUT"
echo "from_unreleased=false" >> "$GITHUB_OUTPUT"
fi
export FROM_UNRELEASED

export COMMITS=$(git log ${COMMIT_RANGE} --format='%s' --no-merges)
export VERSION_NO_V="${{ steps.validate.outputs.version_no_v }}"

node << 'SCRIPT'
const fs = require('fs');
const commits = process.env.COMMITS.split('\n').filter(Boolean);
const version = process.env.VERSION_NO_V;
const today = new Date().toISOString().split('T')[0];
const fromUnreleased = process.env.FROM_UNRELEASED === 'true';

const changelog = fs.readFileSync('CHANGELOG.md', 'utf8');

// Promotion path: turn the curated [Unreleased] section into the new release section,
// assigning it the release version and date while preserving all of its entries.
if (fromUnreleased) {
const unreleasedHeading = /^## \[Unreleased\].*$/m;
if (!unreleasedHeading.test(changelog)) {
console.error('::error::from_unreleased was set but no [Unreleased] section was found.');
process.exit(1);
}

const releaseHeading = `## [${version}] - ${today}`;
const updated = changelog.replace(unreleasedHeading, releaseHeading);
fs.writeFileSync('CHANGELOG.md', updated.endsWith('\n') ? updated : `${updated}\n`);
console.log('Promoted [Unreleased] section to ' + releaseHeading);
process.exit(0);
}

// Fallback path: generate a release section from conventional commits.
const commits = process.env.COMMITS.split('\n').filter(Boolean);

const sections = {
added: [],
Expand Down Expand Up @@ -192,7 +226,6 @@ jobs:
}
}

const changelog = fs.readFileSync('CHANGELOG.md', 'utf8');
const lines = changelog.split('\n');
const header = lines.slice(0, 6).join('\n');
const body = lines.slice(6).join('\n');
Expand Down Expand Up @@ -275,6 +308,7 @@ jobs:
run: |
PREV_TAG="${{ steps.changelog.outputs.prev_tag }}"
CHANGELOG_EXISTS="${{ steps.changelog.outputs.changelog_exists }}"
FROM_UNRELEASED="${{ steps.changelog.outputs.from_unreleased }}"

BODY=$(cat << EOF
## Release Preparation
Expand All @@ -284,7 +318,7 @@ jobs:
### Changes Included

- Version bump to \`${VERSION_NO_V}\` in all package.json files
- Changelog update $(if [[ "${CHANGELOG_EXISTS}" == "true" ]]; then echo "(existing entry preserved)"; else echo "(auto-generated)"; fi)
- Changelog update $(if [[ "${FROM_UNRELEASED}" == "true" ]]; then echo "(promoted from [Unreleased])"; elif [[ "${CHANGELOG_EXISTS}" == "true" ]]; then echo "(existing entry preserved)"; else echo "(auto-generated)"; fi)

### Review Checklist

Expand Down
27 changes: 27 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,33 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [Unreleased]

### Security

- Remediate **high**- and **moderate**-severity dependency vulnerabilities
(8 findings: 2 high, 6 moderate):
- `nodemailer` 9.0.1 → 9.1.1 — **direct production dependency**. Fixes a quadratic (O(n²)) time
complexity in `addressparser` that allows a remote denial of service via a crafted address list
([GHSA-2x7j-588g-ccc2](https://github.com/advisories/GHSA-2x7j-588g-ccc2)), a bypass of
`disableFileAccess`/`disableUrlAccess` when `resolveContent()` is called on a `MailMessage` with
the legacy signature ([GHSA-8m3c-c648-2xjj](https://github.com/advisories/GHSA-8m3c-c648-2xjj)),
an IDN/Punycode domain allow-list bypass that delivers mail to an attacker-controlled domain
([GHSA-wmmp-3585-3rmp](https://github.com/advisories/GHSA-wmmp-3585-3rmp)), and a
recipient-domain validation bypass via RFC 5322 comment mis-parsing
([GHSA-cc9r-2j5m-2m83](https://github.com/advisories/GHSA-cc9r-2j5m-2m83))
- `js-yaml` 4.3.1 → 4.3.2 — fixes `maxTotalMergeKeys` not limiting CPU use for empty merge sources
([GHSA-2883-xcg3-v3hh](https://github.com/advisories/GHSA-2883-xcg3-v3hh)), on top of the
previously pinned `!!omap` quadratic CPU consumption fix (GHSA-52cp-r559-cp3m). It is pulled by
`cosmiconfig` through the commitlint and stylelint toolchains
- `colord` 2.9.3 → 2.10.0 — fixes slow rejection of oversized malformed color strings
([GHSA-2wm5-q62r-hmrv](https://github.com/advisories/GHSA-2wm5-q62r-hmrv)). It is pulled by
`stylelint`
- `vitest` and `@vitest/mocker` 4.1.10 → 4.1.11 — fixes path traversal / arbitrary file read via
the `@vitest/mocker` redirect mock
([GHSA-82fw-gwwq-j7x9](https://github.com/advisories/GHSA-82fw-gwwq-j7x9)). `@vitest/coverage-v8`
and `@vitest/ui` are bumped alongside to keep the Vitest family aligned

## [3.0.1] - 2026-09-05

### Security
Expand Down
54 changes: 39 additions & 15 deletions THIRD-PARTY-NOTICES.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ This document contains the license information for third-party packages used in

**Project:** Scrumooth - Agile Scrum Lifecycle Management System
**License:** Apache-2.0
**Last Updated:** August 16, 2026
**Last Updated:** September 13, 2026

---

Expand All @@ -31,7 +31,7 @@ This document contains the license information for third-party packages used in
| @prisma/adapter-pg | 7.9.1 | Apache-2.0 | Prisma Data, Inc. | https://github.com/prisma/prisma |
| @prisma/client | 7.9.1 | Apache-2.0 | Prisma Data, Inc. | https://github.com/prisma/prisma |
| bcrypt | 6.0.0 | MIT | Nick Campbell | https://github.com/kelektiv/node.bcrypt.js |
| compression | 1.8.1 | MIT | Jonathan Ong | https://github.com/expressjs/compression |
| compression | 1.8.2 | MIT | Jonathan Ong | https://github.com/expressjs/compression |
| cookie-parser | 1.4.7 | MIT | TJ Holowaychuk | https://github.com/expressjs/cookie-parser |
| cors | 2.8.6 | MIT | Troy Goode | https://github.com/expressjs/cors |
| dotenv | 17.4.2 | BSD-2-Clause | Scott Motte | https://github.com/motdotla/dotenv |
Expand All @@ -42,7 +42,7 @@ This document contains the license information for third-party packages used in
| intl-pluralrules | 2.0.1 | ISC | Eemeli Aro | https://github.com/eemeli/intl-pluralrules |
| jsonwebtoken | 9.0.3 | MIT | Auth0, Inc. | https://github.com/auth0/node-jsonwebtoken |
| node-cron | 4.6.0 | MIT | Lucas Merencia | https://github.com/merencia/node-cron |
| nodemailer | 9.0.5 | MIT | Andris Reinman | https://github.com/nodemailer/nodemailer |
| nodemailer | 9.1.1 | MIT-0 | Andris Reinman | https://github.com/nodemailer/nodemailer |
| resolve-accept-language | 3.2.2 | MIT | Nicolas Bouvrette | https://github.com/resolve-accept-language/resolve-accept-language |
| sanitize-html | 2.17.7 | MIT | Apostrophe Technologies, Inc. | https://github.com/apostrophecms/sanitize-html |
| uuid | 14.0.1 | MIT | uuidjs | https://github.com/uuidjs/uuid |
Expand Down Expand Up @@ -71,7 +71,7 @@ This document contains the license information for third-party packages used in
| @types/supertest | 7.2.1 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @typescript-eslint/eslint-plugin | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint |
| @typescript-eslint/parser | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint |
| @vitest/coverage-v8 | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| @vitest/coverage-v8 | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| cross-env | 10.1.0 | MIT | Kent C. Dodds | https://github.com/kentcdodds/cross-env |
| eslint | 10.8.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint |
| eslint-config-prettier | 10.1.8 | MIT | Simon Lydell | https://github.com/prettier/eslint-config-prettier |
Expand All @@ -83,7 +83,7 @@ This document contains the license information for third-party packages used in
| supertest | 7.2.2 | MIT | TJ Holowaychuk | https://github.com/ladjs/supertest |
| tsx | 4.23.12 | MIT | Hiroki Osame | https://github.com/privatenumber/tsx |
| typescript | 6.0.3 | Apache-2.0 | Microsoft Corporation | https://github.com/microsoft/TypeScript |
| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |

---

Expand Down Expand Up @@ -126,8 +126,8 @@ This document contains the license information for third-party packages used in
| @types/react | 19.2.18 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @types/react-dom | 19.2.4 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @vitejs/plugin-react | 6.0.5 | MIT | Vite | https://github.com/vitejs/vite-plugin-react |
| @vitest/coverage-v8 | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| @vitest/ui | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| @vitest/coverage-v8 | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| @vitest/ui | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| cross-env | 10.1.0 | MIT | Kent C. Dodds | https://github.com/kentcdodds/cross-env |
| eslint | 10.8.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint |
| eslint-config-prettier | 10.1.8 | MIT | Simon Lydell | https://github.com/prettier/eslint-config-prettier |
Expand All @@ -145,7 +145,7 @@ This document contains the license information for third-party packages used in
| typescript-eslint | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint |
| vi-axe | 1.0.0 | MIT | Chan Zuckerberg Initiative | https://github.com/chanzuckerberg/vi-axe |
| vite | 8.2.1 | MIT | Vite | https://github.com/vitejs/vite |
| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |

---

Expand Down Expand Up @@ -178,7 +178,7 @@ This document contains the license information for third-party packages used in
| stylelint-no-unsupported-browser-features | 8.1.1 | MIT | Cédric Delpoux | https://github.com/RJWadley/stylelint-no-unsupported-browser-features |
| typescript | 6.0.3 | Apache-2.0 | Microsoft Corporation | https://github.com/microsoft/TypeScript |
| typescript-eslint | 8.67.0 | MIT | TypeScript ESLint | https://github.com/typescript-eslint/typescript-eslint |
| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |

---

Expand All @@ -188,15 +188,15 @@ This document contains the license information for third-party packages used in
| ---------------------- | ------- | ------------ | ---------------------- | -------------------------------------------------- |
| @eslint/js | 10.0.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint |
| @types/node | 24.13.3 | MIT | DefinitelyTyped | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @vitest/coverage-v8 | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| @vitest/coverage-v8 | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| date-fns | 4.4.0 | MIT | Sasha Koss, Lesha Koss | https://github.com/date-fns/date-fns |
| eslint | 10.8.1 | MIT | OpenJS Foundation | https://github.com/eslint/eslint |
| eslint-config-prettier | 10.1.8 | MIT | Simon Lydell | https://github.com/prettier/eslint-config-prettier |
| globals | 17.11.0 | MIT | Sindre Sorhus | https://github.com/sindresorhus/globals |
| prettier | 3.9.6 | MIT | Prettier | https://github.com/prettier/prettier |
| rimraf | 6.1.3 | MIT | Isaac Z. Schlueter | https://github.com/isaacs/rimraf |
| typescript | 6.0.3 | Apache-2.0 | Microsoft Corporation | https://github.com/microsoft/TypeScript |
| vitest | 4.1.10 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |
| vitest | 4.1.11 | MIT | Vladimir Sheremet | https://github.com/vitest-dev/vitest |

---

Expand Down Expand Up @@ -254,6 +254,29 @@ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
```

### MIT No Attribution License (MIT-0)

Used by `nodemailer`.

```
MIT No Attribution

Copyright <YEAR> <COPYRIGHT HOLDER>

Permission is hereby granted, free of charge, to any person obtaining a copy of this
software and associated documentation files (the "Software"), to deal in the Software
without restriction, including without limitation the rights to use, copy, modify,
merge, publish, distribute, sublicense, and/or sell copies of the Software, and to
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF
CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE
OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
```

### Apache License 2.0

```
Expand Down Expand Up @@ -450,10 +473,11 @@ OTHER DEALINGS IN THE FONT SOFTWARE.

| License Type | Package Count | Percentage |
| ------------------ | ------------- | ---------- |
| MIT | 125 | 89.3% |
| MIT | 124 | 88.6% |
| Apache-2.0 | 9 | 6.4% |
| ISC | 2 | 1.4% |
| BSD-2-Clause | 2 | 1.4% |
| MIT-0 | 1 | 0.7% |
| OFL-1.1 | 1 | 0.7% |
| PostgreSQL License | 1 | 0.7% |

Expand All @@ -463,7 +487,7 @@ OTHER DEALINGS IN THE FONT SOFTWARE.

## Compliance Statement

All dependencies listed in this document use OSI-approved open-source licenses that are compatible with the Apache-2.0 license under which Scrumooth is distributed. No copyleft licenses (GPL, LGPL, AGPL) are present in the dependency tree. The bundled Inter font is distributed under the SIL Open Font License 1.1, which permits bundling and redistribution with software and is compatible with Apache-2.0. The PostgreSQL server is distributed under the permissive PostgreSQL License, and nginx under the BSD-2-Clause license, both compatible with Apache-2.0.
All dependencies listed in this document use OSI-approved open-source licenses that are compatible with the Apache-2.0 license under which Scrumooth is distributed. No copyleft licenses (GPL, LGPL, AGPL) are present in the dependency tree. `MIT-0` (MIT No Attribution), used by `nodemailer`, is the permissive MIT license with the attribution clause removed; it is OSI-approved and adds no obligations beyond those of MIT. The bundled Inter font is distributed under the SIL Open Font License 1.1, which permits bundling and redistribution with software and is compatible with Apache-2.0. The PostgreSQL server is distributed under the permissive PostgreSQL License, and nginx under the BSD-2-Clause license, both compatible with Apache-2.0.

### Transitive Dependencies

Expand Down Expand Up @@ -492,5 +516,5 @@ This document should be updated whenever:

---

**Document Version:** 3.0
**Generated:** August 16, 2026
**Document Version:** 3.1
**Generated:** September 13, 2026
2 changes: 1 addition & 1 deletion packages/backend/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@
"intl-pluralrules": "catalog:",
"jsonwebtoken": "^9.0.3",
"node-cron": "^4.2.1",
"nodemailer": "^9.0.1",
"nodemailer": "^9.1.1",
"resolve-accept-language": "^3.2.2",
"sanitize-html": "^2.17.5",
"uuid": "^14.0.0",
Expand Down
Loading