v1.18.1 — Decenza Import Support & Security Patches
Added
- Decenza import support: The Direct Machine Import feature (Settings → Data) now auto-detects whether the configured machine URL is running de1app or Decenza, and imports shots accordingly — no manual switch needed when changing tablet software. Decenza's shot JSON is consumed directly (Visualizer-compatible format, no conversion needed).
- Parser: enjoyment/notes from JSON-format shots:
parseDecentShotnow readsmeta.shot.enjoymentandmeta.shot.notesfor JSON-format (v2) shots, benefiting both Decenza imports and any future de1app v2 JSON shots.
Changed
- The Direct Machine Import connection status now shows which app was detected (e.g. "Connected — Decenza — 42 shots available").
Fixed
- Dependency security patches:
@fastify/static9.1.3 → 10.1.2 (fixes route-guard bypass and authorization bypass via non-canonical URL paths),react-router-dom7.6.2 → 7.18.2 (fixes denial-of-service via inefficient route matching, open redirect, and other advisories affecting <7.18.0). Transitive dependenciesfind-my-way,fast-uri,postcss, andbrace-expansionrefreshed to their patched versions within existingpackage.jsonranges.
Note: One Dependabot alert remains open — a React Router CSRF advisory (GHSA-qwww-vcr4-c8h2) fixed only in v8, which requires migrating off the
react-router-dompackage entirely. The advisory states it only affects apps using the unstable RSC APIs, which this app does not use.