Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 10 additions & 10 deletions .github/workflows/build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ on:

env:
NODEJS_VERSION: 22
AWS_IAM_AUTHENTICATOR_VERSION: 0.7.16
AWS_IAM_AUTHENTICATOR_VERSION: 0.7.18

jobs:
build:
Expand Down Expand Up @@ -70,7 +70,7 @@ jobs:
#
# To refresh after bumping AWS_IAM_AUTHENTICATOR_VERSION:
#
# V=0.7.16
# V=0.7.18
# for t in darwin_amd64 darwin_arm64 linux_amd64 linux_arm64 windows_amd64.exe; do
# curl -fsSL "https://github.com/kubernetes-sigs/aws-iam-authenticator/releases/download/v${V}/aws-iam-authenticator_${V}_${t}" \
# | shasum -a 256 | sed "s/-/${t}/"
Expand All @@ -81,29 +81,29 @@ jobs:
include:
- os: { name: darwin, runs-on: macos-latest, aws: darwin, exe: "" }
arch: { name: x86_64, aws: amd64, electron: x64 }
authenticator_sha256: 6a3472a37747551a3b9ad7d3cfdb029862088e7dd21f8d282fe5e7120dd1f85e
authenticator_sha256: ccc6756f9d41008e1a643f72e542097952c6f88457425a7b8a2f4500f79bf657
- os: { name: darwin, runs-on: macos-latest, aws: darwin, exe: "" }
arch: { name: arm64, aws: arm64, electron: arm64 }
authenticator_sha256: 7f0703556b9453150218fd115676ede45d8545cb118ecbe9b7c3adab6a51a411
authenticator_sha256: 3704767c72ab56676ea1e398aa90ea42a53b0a9bd215a0babfae8e86bb21cf95
- os: { name: linux, runs-on: ubuntu-latest, aws: linux, exe: "" }
arch: { name: x86_64, aws: amd64, electron: x64 }
authenticator_sha256: c9586953372361f4760cc5cb33bc2a0c7992efd15d6028c2bde45d46a724b369
authenticator_sha256: fbebd5350dd1a5f377097fd1b2e1ca8c5a5e7ecb35cc44ddc694b775d498d7a5
- os: { name: linux, runs-on: ubuntu-latest, aws: linux, exe: "" }
arch: { name: arm64, aws: arm64, electron: arm64 }
authenticator_sha256: 829f48f0d71da8aa43d5ee252f9458c9c51dfeb4089c14cf4f19bcb1838f87e2
authenticator_sha256: 9d77c45e3a7a791ec3eb09a4913f9fff3be6e1d86d6af698ea104e4bbb7c933c
- os: { name: win32, runs-on: windows-latest, aws: windows, exe: ".exe" }
arch: { name: x86_64, aws: amd64, electron: x64 }
authenticator_sha256: 1fb1a49bbcc5ad3ee4da8796d03fe9cd90777c5be9e812a95c83ce165e35618f
authenticator_sha256: 51fe83610dce3fd6efe6f97df91c93ce8f1b9fbb4eab48a541fc2a4016a2b24b
- os: { name: win32, runs-on: windows-latest, aws: windows, exe: ".exe" }
arch: { name: arm64, aws: amd64, electron: arm64 }
authenticator_sha256: 1fb1a49bbcc5ad3ee4da8796d03fe9cd90777c5be9e812a95c83ce165e35618f
authenticator_sha256: 51fe83610dce3fd6efe6f97df91c93ce8f1b9fbb4eab48a541fc2a4016a2b24b
runs-on: ${{ matrix.os.runs-on }}
steps:
- name: 📥 Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: ⚙️ Install Node.js and NPM
uses: actions/setup-node@v6
uses: actions/setup-node@v7
with:
node-version: ${{ env.NODEJS_VERSION }}
cache: npm
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -28,10 +28,10 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: 📥 Checkout sources
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: ⚙️ Install Node.js and NPM
uses: actions/setup-node@v6
uses: actions/setup-node@v7
with:
node-version: ${{ env.NODEJS_VERSION }}
cache: npm
Expand All @@ -44,7 +44,7 @@ jobs:
run: |
npm run build

- name: 🧹 Run eslint
- name: 🧹 Run oxlint
run: |
npm run lint

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/pages.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,16 +27,16 @@ jobs:
url: ${{ steps.deployment.outputs.page_url }}
steps:
- name: 📥 Checkout sources
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: ⚙️ Configure Pages
uses: actions/configure-pages@v5
uses: actions/configure-pages@v6

- name: 📦 Upload artifact
uses: actions/upload-pages-artifact@v4
uses: actions/upload-pages-artifact@v5
with:
path: docs

- name: 🚀 Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v4
uses: actions/deploy-pages@v5
4 changes: 2 additions & 2 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ jobs:
version: ${{ steps.draft.outputs.version }}
steps:
- name: 📥 Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7

- id: draft
name: 🔖 Read the tag off the draft release
Expand Down Expand Up @@ -68,7 +68,7 @@ jobs:
contents: write
steps:
- name: 📥 Checkout code
uses: actions/checkout@v6
uses: actions/checkout@v7

- name: 🚀 Publish the draft
env:
Expand Down
83 changes: 83 additions & 0 deletions .oxlintrc.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
{
"$schema": "./node_modules/oxlint/configuration_schema.json",
"ignorePatterns": [
"dist/**",
"out/**"
],
"plugins": [
"typescript"
],
"categories": {
"correctness": "off"
},
"rules": {
"for-direction": "error",
"no-async-promise-executor": "error",
"no-case-declarations": "error",
"no-compare-neg-zero": "error",
"no-cond-assign": "error",
"no-constant-binary-expression": "error",
"no-constant-condition": "error",
"no-control-regex": "error",
"no-debugger": "error",
"no-delete-var": "error",
"no-dupe-else-if": "error",
"no-duplicate-case": "error",
"no-empty": "error",
"no-empty-character-class": "error",
"no-empty-pattern": "error",
"no-empty-static-block": "error",
"no-ex-assign": "error",
"no-extra-boolean-cast": "error",
"no-fallthrough": "error",
"no-global-assign": "error",
"no-invalid-regexp": "error",
"no-irregular-whitespace": "error",
"no-loss-of-precision": "error",
"no-misleading-character-class": "error",
"no-nonoctal-decimal-escape": "error",
"no-prototype-builtins": "error",
"no-regex-spaces": "error",
"no-self-assign": "error",
"no-shadow-restricted-names": "error",
"no-sparse-arrays": "error",
"no-unassigned-vars": "error",
"no-unexpected-multiline": "error",
"no-unsafe-finally": "error",
"no-unsafe-optional-chaining": "error",
"no-unused-labels": "error",
"no-unused-private-class-members": "error",
"no-useless-assignment": "error",
"no-useless-backreference": "error",
"no-useless-catch": "error",
"no-useless-escape": "error",
"no-var": "error",
"prefer-const": "error",
"prefer-rest-params": "error",
"prefer-spread": "error",
"preserve-caught-error": "error",
"require-yield": "error",
"use-isnan": "error",
"valid-typeof": "error",
"typescript/ban-ts-comment": "error",
"typescript/no-array-constructor": "error",
"typescript/no-duplicate-enum-values": "error",
"typescript/no-empty-object-type": "error",
"typescript/no-explicit-any": "error",
"typescript/no-extra-non-null-assertion": "error",
"typescript/no-misused-new": "error",
"typescript/no-namespace": "error",
"typescript/no-non-null-asserted-optional-chain": "error",
"typescript/no-require-imports": "error",
"typescript/no-this-alias": "error",
"typescript/no-unnecessary-type-constraint": "error",
"typescript/no-unsafe-declaration-merging": "error",
"typescript/no-unsafe-function-type": "error",
"typescript/no-unused-expressions": "error",
"typescript/no-unused-vars": "error",
"typescript/no-wrapper-object-types": "error",
"typescript/prefer-as-const": "error",
"typescript/prefer-namespace-keyword": "error",
"typescript/triple-slash-reference": "error"
}
}
42 changes: 34 additions & 8 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@ framework, not type-checked or linted.
npm only (`package-lock.json`; CI runs `npm ci`). Do not add a `yarn.lock`.

- `npm run build` — `tsc`, then copies the tray icons and `dashboard.html`.
- `npm run lint` — ESLint, flat config.
- `npm run lint` — oxlint, configured by `.oxlintrc.json`.
- `npm start` / `npm run package` / `npm run make` — Electron Forge.

Build and lint both run in CI. Neither proves the app launches; see
Expand All @@ -81,7 +81,7 @@ Build and lint both run in CI. Neither proves the app launches; see
- Relative imports carry a `.js` extension even though the source is `.ts`.
- No `__dirname`/`__filename`; derive it from `import.meta.url`.
- `tsconfig` needs an explicit `rootDir`.
- `forge.config.js` and `eslint.config.js` are ESM; no `require`.
- `forge.config.js` is ESM; no `require`.

## Login window WebAuthn overlay

Expand Down Expand Up @@ -184,14 +184,40 @@ Each platform branch exists for a reason.
**uuid v14**: pure ESM. The k8s client has no default export. It does not
declare `@types/ws` but its types reach `ws` through `isomorphic-ws`, so
`@types/ws` must stay a devDependency or `tsc` fails.
- **ESLint 10**: flat config only, via the `typescript-eslint` umbrella package
and `@eslint/js`. Its `no-unassigned-vars` rule catches pagination loops that
never reassign their continuation token.
- **oxlint, not ESLint.** oxlint has its own parser and never loads the
TypeScript compiler API, which is what lets this repo hold a single
TypeScript — see the TypeScript note below. `eslint`, `typescript-eslint` and
`@eslint/js` are gone; don't reintroduce them without reading that note.
`.oxlintrc.json` **pins the rule set**: `categories.correctness` is off and
`plugins` is just `["typescript"]`, so the 68 listed rules are all that run —
a faithful port of what `js.configs.recommended` plus
`tseslint.configs.recommended` enforced, and immune to a new oxlint release
widening it. Enabling a category is a real decision; make it deliberately,
with the new findings fixed. Only `no-octal` had no equivalent, and it is
unreachable: octal literals are a syntax error in an ES module, so `tsc`
rejects them first. `no-unassigned-vars` still catches pagination loops that
never reassign their continuation token. Type-aware rules are available but
off — `oxlint --type-aware` with `oxlint-tsgolint`, which runs on TS 7 — and
currently report a dozen findings worth fixing on their own terms.
- **js-yaml v5** ships its own types; `@types/js-yaml` was dropped. `@types/ini`
is still needed.
- **TypeScript stays on 6.x.** `typescript-eslint` 8 declares a peer range
below 7, so installing TS 7 fails `npm install` and takes lint — a CI gate —
down with it. Revisit when typescript-eslint supports TS 7.
- **TypeScript 7, and only one of it.** TS 7's package exports `version` and
`versionMajorMinor` from its main entry and nothing else — the TS 6 compiler
API moved behind `typescript/unstable/*` in a different shape. So **any** tool
doing `import ts from "typescript"` needs a TypeScript 6 alongside TS 7; that
is not an eslint quirk, and ts-jest, ts-node and ts-morph are in the same
position. The linter was the only such tool here, which is why it is oxlint.
Before adding a dependency that reaches for the compiler API, grep
`node_modules` for `require("typescript")` — if the answer stops being "none",
the single-TypeScript property is what you are trading away.
- **Electron 44 requires macOS 13.** Chromium dropped Monterey. Nothing in
`src/` used the APIs 44 removed (renderer `clipboard`, `app.isUnityRunning`,
`setProgressBar`/`setBadgeCount`, `net.request`, the
`select-client-certificate` signature) and the build matrix was already
64-bit only, so the OS floor is the whole of the breaking change. `README.md`
and `docs/docs/platforms.html` say so, because the in-place updater does not
check the OS version before installing.

- **No `overrides` block.** The former entries are resolved by upgrading
parents. Prefer that over adding an override, and re-check `npm audit` with
the block empty first.
Expand Down
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,10 @@ Frost runs on macOS, Windows and Linux.
Grab a build from the
[downloads page](https://popen2.github.io/frost/download.html).

**macOS 13 (Ventura) or later is required.** Frost 0.1 and earlier ran on
Monterey; Electron 44 dropped it, so macOS 12 machines should stay on the last
release built against Electron 43 rather than updating.

Frost updates itself in place on macOS and Windows. Electron's `autoUpdater`
has no Linux implementation, so **Linux builds do not self-update** — check the
downloads page and replace the app to upgrade.
Expand Down
11 changes: 11 additions & 0 deletions docs/docs/platforms.html
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,17 @@ <h2 id="builds">Builds</h2>
<a href="../download.html">downloads page</a> reads the latest GitHub
release and highlights the build matching the device you are on.
</p>
<div class="callout callout-warn">
<span class="callout-icon" aria-hidden="true">⚠️</span>
<p>
<strong>macOS 13 (Ventura) or later is required.</strong> Electron 44
dropped macOS 12, so a Monterey machine cannot run current builds.
Frost updates itself in place and the updater does not check the OS
version, so stay on the last release built against Electron 43 rather
than letting a Monterey install update itself into a build that will
not launch.
</p>
</div>

<h2 id="updates">Automatic updates</h2>
<p>
Expand Down
16 changes: 0 additions & 16 deletions eslint.config.js

This file was deleted.

Loading