Skip to content

v1.18.1 — Decenza Import Support & Security Patches

Choose a tag to compare

@TomSchmidtDev TomSchmidtDev released this 31 Jul 19:52
· 7 commits to main since this release

Added

  • Decenza import support: The Direct Machine Import feature (Settings → Data) now auto-detects whether the configured machine URL is running de1app or Decenza, and imports shots accordingly — no manual switch needed when changing tablet software. Decenza's shot JSON is consumed directly (Visualizer-compatible format, no conversion needed).
  • Parser: enjoyment/notes from JSON-format shots: parseDecentShot now reads meta.shot.enjoyment and meta.shot.notes for JSON-format (v2) shots, benefiting both Decenza imports and any future de1app v2 JSON shots.

Changed

  • The Direct Machine Import connection status now shows which app was detected (e.g. "Connected — Decenza — 42 shots available").

Fixed

  • Dependency security patches: @fastify/static 9.1.3 → 10.1.2 (fixes route-guard bypass and authorization bypass via non-canonical URL paths), react-router-dom 7.6.2 → 7.18.2 (fixes denial-of-service via inefficient route matching, open redirect, and other advisories affecting <7.18.0). Transitive dependencies find-my-way, fast-uri, postcss, and brace-expansion refreshed to their patched versions within existing package.json ranges.

Note: One Dependabot alert remains open — a React Router CSRF advisory (GHSA-qwww-vcr4-c8h2) fixed only in v8, which requires migrating off the react-router-dom package entirely. The advisory states it only affects apps using the unstable RSC APIs, which this app does not use.