fix(security): audit batch B — SPA CSP/security headers + vite upgrade
CI / backend (pull_request) Successful in 52s
CI / frontend (pull_request) Successful in 12s
Security / secrets (pull_request) Successful in 3s
Security / dependencies (pull_request) Successful in 54s

Implements AUDIT_REPORT.md M-2 and M-5:
- M-2: CSP (script-src 'self'; frame-ancestors 'none'; object-src 'none'; ...),
  nosniff, X-Frame-Options DENY, Referrer-Policy on the SPA nginx, plus gzip for
  the bundle. The inline theme bootstrap moved to /theme-init.js so script-src
  'self' holds with no inline scripts.
- M-5: vite 5 -> 8 (+ plugin-react 6) — clears the dev-only esbuild advisories;
  npm audit now reports 0 vulnerabilities including dev deps. Build verified.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
cesnimda
2026-07-02 03:21:35 +02:00
parent 2056548702
commit 38a58871ac
5 changed files with 561 additions and 1125 deletions
+2 -2
View File
@@ -35,10 +35,10 @@
"tailwind-merge": "^3.6.0"
},
"devDependencies": {
"@vitejs/plugin-react": "^4.3.1",
"@vitejs/plugin-react": "^6.0.3",
"autoprefixer": "^10.5.2",
"postcss": "^8.5.16",
"tailwindcss": "^3.4.19",
"vite": "^5.3.1"
"vite": "^8.1.2"
}
}