port: apply 7 upstream security/robustness patches

Ports from isolated upstream-port branch (base b3c5a4b), verified in
isolation via baseline-vs-port failure-set diff and re-verified live
(195 pass / 0 fail on affected tests):
- redact Discord bot tokens in outbound (router.ts SECRET_PATTERNS)
- block SSRF to private hosts in MoA base URL (moa.ts)
- refuse public dashboard bind without auth token (web-dashboard-server.ts)
- merge upstream .gitignore rules for python/build/secret noise
- real CPU utilization from /proc/stat instead of load avg (unified-dashboard.ts)
- width-safe placeholder for missing usage window on mobile (unified-dashboard.ts)
- bump direct deps to patch known vulnerabilities (discord.js/yaml/cron-parser)

Risky upstream commits (d5a94af phantom reset-time, patch 6 Codex usage)
intentionally skipped to avoid touching the credential-isolation tree.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Codex
2026-08-24 19:35:59 +09:00
parent b3c5a4b41b
commit c016b9c2fa
11 changed files with 393 additions and 205 deletions

View File

@@ -41,8 +41,8 @@
},
"dependencies": {
"@modelcontextprotocol/sdk": "^1.27.1",
"cron-parser": "^5.5.0",
"discord.js": "^14.18.0",
"cron-parser": "^5.6.1",
"discord.js": "^14.26.4",
"ejclaw-runners-shared": "workspace:*",
"lucide-react": "^1.11.0",
"pino": "^9.6.0",
@@ -51,7 +51,7 @@
"react-dom": "^19.2.5",
"react-markdown": "^10.1.0",
"remark-gfm": "^4.0.1",
"yaml": "^2.8.2",
"yaml": "^2.9.0",
"zod": "^4.3.6"
},
"devDependencies": {
@@ -63,7 +63,7 @@
"@types/react": "^19.2.14",
"@types/react-dom": "^19.2.3",
"@vitejs/plugin-react": "^6.0.1",
"@vitest/coverage-v8": "^4.0.18",
"@vitest/coverage-v8": "^4.1.9",
"better-sqlite3": "^12.8.0",
"eslint": "^10.2.1",
"globals": "^17.5.0",
@@ -72,8 +72,8 @@
"prettier": "^3.8.1",
"typescript": "^5.7.0",
"typescript-eslint": "^8.59.0",
"vite": "^8.0.10",
"vitest": "^4.0.18"
"vite": "^8.1.3",
"vitest": "^4.1.9"
},
"engines": {
"node": ">=20"