e981c63a4d
The new dependency scan correctly failed on real advisories. Bump MailKit 4.13.0->4.17.0 (clears MailKit+MimeKit moderates) and add transitive security pins for the .NET 8.0.0 High-severity advisories: System.Text.Json 8.0.6, Microsoft.Extensions.Caching.Memory 8.0.1 (with DependencyInjection.Abstractions 8.0.2), System.Security.Cryptography.Xml 8.0.3. Verified locally: clean vuln scan, Release build OK, all 39 tests pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1.8 KiB
1.8 KiB
Changelog
All notable changes to InboxIntel are documented here. Format follows Keep a Changelog; versions follow Semantic Versioning. See docs/WORKFLOW.md.
Unreleased
Security
- Patched all High/Moderate NuGet advisories the new dependency gate surfaced:
System.Text.Json8.0.0→8.0.6,Microsoft.Extensions.Caching.Memory8.0.0→8.0.1 (+DependencyInjection.Abstractions→8.0.2),System.Security.Cryptography.Xml8.0.1→8.0.3 (transitive pins), andMailKit/MimeKit4.13.0→4.17.0.
Added
- CI/CD pipeline (
.gitea/workflows/):security(gitleaks secret scan + NuGet/npm vulnerability gate),deploy-staging(auto-redeploy local staging ondevelop),deploy-prod(tag-gated production promotion, inactive until the server exists). - Formal Git workflow & environment strategy (
docs/WORKFLOW.md). - Staging environment overlay (
docker-compose.staging.yml) — production-shaped Linux containers on Windows, isolated ports/volumes. - Version-controlled Git hooks (
scripts/git-hooks/) + installer (scripts/install-hooks.ps1): pre-commit secret/format checks, pre-push build+test gate. VERSIONfile as the single source of truth for the release number.
[0.1.0] — scaffold
Added
- .NET 8 Clean Architecture backend (Domain/Application/Infrastructure/Api) + React/Vite SPA.
- Docker Compose stack (Postgres 16, API, frontend, optional nginx proxy).
- Gitea Actions CI (backend build+test, frontend build) on
main/develop+ PRs. - Security hardening: encrypted OAuth tokens, EF global query filters (IDOR), loopback binds, non-root containers, SSRF egress guard.
- One-command deploy scripts (
deploy/up.ps1,deploy/up.sh).