mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-02 15:38:22 +00:00
Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| c7b05a4487 | |||
| 971a7295ca | |||
| bd0329d162 | |||
| cedaa32ab7 |
+2
-1
@@ -15,9 +15,10 @@ and this project adheres to
|
|||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- 🐛(frontend) omit the default speaker id sent to LiveKit
|
|
||||||
- 🐛(frontend) enforce recording-mode permissions on the checkboxes
|
- 🐛(frontend) enforce recording-mode permissions on the checkboxes
|
||||||
- 🔒️(agents) fix util-linux CVEs reported by Cyberwatch
|
- 🔒️(agents) fix util-linux CVEs reported by Cyberwatch
|
||||||
|
- 🔒️(backend) fix HIGH CVEs in Django and urllib3
|
||||||
|
- 🔒️(agents) upgrade libpcre2-8-0 to fix CVE-2026-103111
|
||||||
|
|
||||||
## [1.33.0] - 2026-09-30
|
## [1.33.0] - 2026-09-30
|
||||||
|
|
||||||
|
|||||||
+2
-3
@@ -37,14 +37,13 @@ RUN --mount=type=cache,target=/root/.cache/uv \
|
|||||||
uv sync --locked --no-dev
|
uv sync --locked --no-dev
|
||||||
|
|
||||||
# ---- mails ----
|
# ---- mails ----
|
||||||
FROM node:22 AS mail-builder
|
FROM node:22-alpine AS mail-builder
|
||||||
|
|
||||||
COPY ./src/mail /mail/app
|
COPY ./src/mail /mail/app
|
||||||
|
|
||||||
WORKDIR /mail/app
|
WORKDIR /mail/app
|
||||||
|
|
||||||
RUN yarn install --frozen-lockfile && \
|
RUN npm ci --ignore-scripts && npm run build
|
||||||
yarn build
|
|
||||||
|
|
||||||
|
|
||||||
# ---- static link collector ----
|
# ---- static link collector ----
|
||||||
|
|||||||
+2
-2
@@ -172,7 +172,7 @@ services:
|
|||||||
working_dir: /app
|
working_dir: /app
|
||||||
|
|
||||||
node:
|
node:
|
||||||
image: node:22
|
image: node:22-alpine
|
||||||
user: "${DOCKER_USER:-1000}"
|
user: "${DOCKER_USER:-1000}"
|
||||||
environment:
|
environment:
|
||||||
HOME: /tmp
|
HOME: /tmp
|
||||||
@@ -271,7 +271,7 @@ services:
|
|||||||
- /app/.venv
|
- /app/.venv
|
||||||
|
|
||||||
redis-summary:
|
redis-summary:
|
||||||
image: redis
|
image: redis:5
|
||||||
ports:
|
ports:
|
||||||
- "6379:6379"
|
- "6379:6379"
|
||||||
|
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ RUN sed -i "s|^URIs: http://|URIs: https://|" /etc/apt/sources.list.d/debian.sou
|
|||||||
&& apt-get update && apt-get install -y --no-install-recommends \
|
&& apt-get update && apt-get install -y --no-install-recommends \
|
||||||
libglib2.0-0 \
|
libglib2.0-0 \
|
||||||
libgobject-2.0-0 \
|
libgobject-2.0-0 \
|
||||||
|
libpcre2-8-0 \
|
||||||
libssl3t64 \
|
libssl3t64 \
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
|||||||
@@ -40,7 +40,7 @@ dependencies = [
|
|||||||
"django-storages[s3]==1.14.6",
|
"django-storages[s3]==1.14.6",
|
||||||
"django-timezone-field>=5.1",
|
"django-timezone-field>=5.1",
|
||||||
"django-pydantic-field==0.5.4",
|
"django-pydantic-field==0.5.4",
|
||||||
"django==5.2.16",
|
"django==5.2.17",
|
||||||
"djangorestframework==3.18.0",
|
"djangorestframework==3.18.0",
|
||||||
"drf_spectacular==0.30.0",
|
"drf_spectacular==0.30.0",
|
||||||
"dockerflow==2026.3.4",
|
"dockerflow==2026.3.4",
|
||||||
@@ -62,7 +62,7 @@ dependencies = [
|
|||||||
"mozilla-django-oidc==5.0.2",
|
"mozilla-django-oidc==5.0.2",
|
||||||
"livekit-api==1.2.0",
|
"livekit-api==1.2.0",
|
||||||
"aiohttp==3.14.3",
|
"aiohttp==3.14.3",
|
||||||
"urllib3==2.7.0",
|
"urllib3==2.8.0",
|
||||||
"phonenumbers==9.0.37",
|
"phonenumbers==9.0.37",
|
||||||
"cryptography==50.0.1", # CVE-2026-69247
|
"cryptography==50.0.1", # CVE-2026-69247
|
||||||
]
|
]
|
||||||
|
|||||||
Generated
+8
-8
@@ -700,16 +700,16 @@ wheels = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "django"
|
name = "django"
|
||||||
version = "5.2.16"
|
version = "5.2.17"
|
||||||
source = { registry = "https://pypi.org/simple" }
|
source = { registry = "https://pypi.org/simple" }
|
||||||
dependencies = [
|
dependencies = [
|
||||||
{ name = "asgiref" },
|
{ name = "asgiref" },
|
||||||
{ name = "sqlparse" },
|
{ name = "sqlparse" },
|
||||||
{ name = "tzdata", marker = "sys_platform == 'win32'" },
|
{ name = "tzdata", marker = "sys_platform == 'win32'" },
|
||||||
]
|
]
|
||||||
sdist = { url = "https://files.pythonhosted.org/packages/a9/26/889449d521ae508b26de715954faecd8bcf3f740affb81b2d146a83b42a5/django-5.2.16.tar.gz", hash = "sha256:59ea02020c3136fce14bef0bbece21a10a4febef5eed1c51c22ae468efa22200", size = 10890894, upload-time = "2026-07-07T13:52:17.005Z" }
|
sdist = { url = "https://files.pythonhosted.org/packages/d5/d8/43e9d000519adceb189620b6869ff88031e046df91c2e9da72f8f6918399/django-5.2.17.tar.gz", hash = "sha256:9d4d93be539a18ab80d058eb515900e10951e04c537c5a6b394fc49528d3251f", size = 10889740, upload-time = "2026-08-04T15:04:03.173Z" }
|
||||||
wheels = [
|
wheels = [
|
||||||
{ url = "https://files.pythonhosted.org/packages/4e/13/1e5e3e4c15dcecb04281b3cb2a46a4670e1cef131068e202f6040df19224/django-5.2.16-py3-none-any.whl", hash = "sha256:04f354bf9d807a86ad1a8392fe3808d362358a8eafc322848e0e43e59b24371d", size = 8311943, upload-time = "2026-07-07T13:52:11.223Z" },
|
{ url = "https://files.pythonhosted.org/packages/df/f8/ce120525ca78f12b07daf65786679c5d0b54a75285a8958d3ae55e39da35/django-5.2.17-py3-none-any.whl", hash = "sha256:f04fb3b36ee119e1af4fa1d397d5fd6cf12700f49321e84d4f4c642c5b1973db", size = 8315563, upload-time = "2026-08-04T15:03:59.1Z" },
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -1372,7 +1372,7 @@ requires-dist = [
|
|||||||
{ name = "celery", extras = ["redis"], specifier = "==5.6.3" },
|
{ name = "celery", extras = ["redis"], specifier = "==5.6.3" },
|
||||||
{ name = "cryptography", specifier = "==50.0.1" },
|
{ name = "cryptography", specifier = "==50.0.1" },
|
||||||
{ name = "dj-database-url", specifier = "==3.1.2" },
|
{ name = "dj-database-url", specifier = "==3.1.2" },
|
||||||
{ name = "django", specifier = "==5.2.16" },
|
{ name = "django", specifier = "==5.2.17" },
|
||||||
{ name = "django-configurations", specifier = "==2.5.1" },
|
{ name = "django-configurations", specifier = "==2.5.1" },
|
||||||
{ name = "django-cors-headers", specifier = "==4.9.0" },
|
{ name = "django-cors-headers", specifier = "==4.9.0" },
|
||||||
{ name = "django-countries", specifier = "==9.0.0" },
|
{ name = "django-countries", specifier = "==9.0.0" },
|
||||||
@@ -1404,7 +1404,7 @@ requires-dist = [
|
|||||||
{ name = "redis", specifier = "==5.2.1" },
|
{ name = "redis", specifier = "==5.2.1" },
|
||||||
{ name = "requests", specifier = "==2.34.2" },
|
{ name = "requests", specifier = "==2.34.2" },
|
||||||
{ name = "sentry-sdk", specifier = "==2.68.1" },
|
{ name = "sentry-sdk", specifier = "==2.68.1" },
|
||||||
{ name = "urllib3", specifier = "==2.7.0" },
|
{ name = "urllib3", specifier = "==2.8.0" },
|
||||||
{ name = "whitenoise", specifier = "==6.12.0" },
|
{ name = "whitenoise", specifier = "==6.12.0" },
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -2529,11 +2529,11 @@ wheels = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "urllib3"
|
name = "urllib3"
|
||||||
version = "2.7.0"
|
version = "2.8.0"
|
||||||
source = { registry = "https://pypi.org/simple" }
|
source = { registry = "https://pypi.org/simple" }
|
||||||
sdist = { url = "https://files.pythonhosted.org/packages/53/0c/06f8b233b8fd13b9e5ee11424ef85419ba0d8ba0b3138bf360be2ff56953/urllib3-2.7.0.tar.gz", hash = "sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c", size = 433602, upload-time = "2026-05-07T16:13:18.596Z" }
|
sdist = { url = "https://files.pythonhosted.org/packages/e3/05/b17359e1cefb4f909b5e40b1b90a496d987258916dbbf88e842c729f510e/urllib3-2.8.0.tar.gz", hash = "sha256:63bf2ead4c879426ebf22ef2a781eeb4aa3b4ae798a0435506f8687fd5bb9b63", size = 458972, upload-time = "2026-09-15T19:29:36.253Z" }
|
||||||
wheels = [
|
wheels = [
|
||||||
{ url = "https://files.pythonhosted.org/packages/7f/3e/5db95bcf282c52709639744ca2a8b149baccf648e39c8cc87553df9eae0c/urllib3-2.7.0-py3-none-any.whl", hash = "sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897", size = 131087, upload-time = "2026-05-07T16:13:17.151Z" },
|
{ url = "https://files.pythonhosted.org/packages/92/9d/c4e665119135114480843e7ab388fa94d8480650450e6f8e26b70d323a4c/urllib3-2.8.0-py3-none-any.whl", hash = "sha256:0cf3cae568d36aa9576b28dfb35f11328f1cb974ca7647d9475ebb86c75ac6e3", size = 135717, upload-time = "2026-09-15T19:29:34.577Z" },
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
|
|||||||
@@ -8,10 +8,6 @@ const IGNORED_EXCEPTION_PATTERNS = [
|
|||||||
// the close reason is already logged by the SDK.
|
// the close reason is already logged by the SDK.
|
||||||
// See: https://github.com/livekit/client-sdk-js/issues/2062
|
// See: https://github.com/livekit/client-sdk-js/issues/2062
|
||||||
/^Event captured as exception with keys: isTrusted$/,
|
/^Event captured as exception with keys: isTrusted$/,
|
||||||
// LiveKit logs a rejected setSinkId on remote audio attach and already
|
|
||||||
// swallows it. capture_console_errors turns that log into an exception
|
|
||||||
// and stringifies the real error as [object Object].
|
|
||||||
/^Failed to set sink id on remote audio track/,
|
|
||||||
]
|
]
|
||||||
|
|
||||||
const shouldIgnoreException = (value: unknown): boolean =>
|
const shouldIgnoreException = (value: unknown): boolean =>
|
||||||
|
|||||||
@@ -45,7 +45,6 @@ import { userStore } from '@/stores/user'
|
|||||||
import { WatchMediaDeviceErrors } from './WatchMediaDeviceErrors'
|
import { WatchMediaDeviceErrors } from './WatchMediaDeviceErrors'
|
||||||
import { MeetDevtools } from '@/features/devtools'
|
import { MeetDevtools } from '@/features/devtools'
|
||||||
import { VOICE_AUDIO_CONSTRAINTS } from '@/features/rooms/livekit/utils/constants'
|
import { VOICE_AUDIO_CONSTRAINTS } from '@/features/rooms/livekit/utils/constants'
|
||||||
import { resolveAudioOutputDeviceId } from '@/features/rooms/utils/resolveAudioOutputDeviceId'
|
|
||||||
|
|
||||||
export const Conference = ({
|
export const Conference = ({
|
||||||
roomId,
|
roomId,
|
||||||
@@ -121,7 +120,7 @@ export const Conference = ({
|
|||||||
...VOICE_AUDIO_CONSTRAINTS,
|
...VOICE_AUDIO_CONSTRAINTS,
|
||||||
},
|
},
|
||||||
audioOutput: {
|
audioOutput: {
|
||||||
deviceId: resolveAudioOutputDeviceId(userConfig.audioOutputDeviceId),
|
deviceId: userConfig.audioOutputDeviceId ?? undefined,
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
// do not rely on the userConfig object directly as its reference may change on every render
|
// do not rely on the userConfig object directly as its reference may change on every render
|
||||||
|
|||||||
@@ -1,11 +0,0 @@
|
|||||||
/**
|
|
||||||
* `'default'` means "use the system output". Firefox has no device with that
|
|
||||||
* id, so LiveKit's setSinkId('default') rejects on every remote audio attach.
|
|
||||||
* Omit it and the browser keeps the OS default, which is the same result.
|
|
||||||
*/
|
|
||||||
export const resolveAudioOutputDeviceId = (
|
|
||||||
deviceId: string | undefined
|
|
||||||
): string | undefined => {
|
|
||||||
if (!deviceId || deviceId === 'default') return undefined
|
|
||||||
return deviceId
|
|
||||||
}
|
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
#!/usr/bin/env bash
|
#!/bin/sh
|
||||||
set -eo pipefail
|
set -e
|
||||||
# Run html-to-text to convert all html files to text files
|
# Run html-to-text to convert all html files to text files
|
||||||
DIR_MAILS="../backend/core/templates/mail/"
|
DIR_MAILS="../backend/core/templates/mail/"
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
#!/usr/bin/env bash
|
#!/bin/sh
|
||||||
|
|
||||||
# Run mjml command to convert all mjml templates to html files
|
# Run mjml command to convert all mjml templates to html files
|
||||||
DIR_MAILS="../backend/core/templates/mail/html/"
|
DIR_MAILS="../backend/core/templates/mail/html/"
|
||||||
|
|||||||
@@ -9,8 +9,8 @@
|
|||||||
},
|
},
|
||||||
"private": true,
|
"private": true,
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"build-mjml-to-html": "bash ./bin/mjml-to-html",
|
"build-mjml-to-html": "sh ./bin/mjml-to-html",
|
||||||
"build-html-to-plain-text": "bash ./bin/html-to-plain-text",
|
"build-html-to-plain-text": "sh ./bin/html-to-plain-text",
|
||||||
"build": "npm run build-mjml-to-html && npm run build-html-to-plain-text"
|
"build": "npm run build-mjml-to-html && npm run build-html-to-plain-text"
|
||||||
},
|
},
|
||||||
"volta": {
|
"volta": {
|
||||||
|
|||||||
Reference in New Issue
Block a user