Skip to content

v1.19.1 — Decaid Import Support & Port Fallback

Choose a tag to compare

@TomSchmidtDev TomSchmidtDev released this 05 Sep 11:35
· 3 commits to main since this release

Added

  • Decaid import support: The Direct Machine Import feature (Settings → Data) now also auto-detects Decaid alongside de1app and Decenza, and imports shots accordingly — no manual switch needed when changing tablet software. Decaid's shot history REST API (/api/v1/shots) is fully paginated, so the entire history is imported regardless of size, and a new parser converts Decaid's row-oriented measurement snapshots into the same shot format used internally for de1app/Decenza imports. Coffee name, roaster, and barista are read from the shot's workflow context when present, and Decaid's device-reported gravimetric flow rate (scale.weightFlow) is mapped to the same channel de1app/Decenza expose. The connection test reads the shot count from a single request rather than paging through the full history, and listing/preview stop paging early once results (sorted newest-first) fall before the requested start date, instead of always walking the entire history.
  • Automatic port fallback for Direct Machine Import: de1app/Decenza and Decaid conventionally listen on different default ports (8888 vs. 8080). If the configured machine URL doesn't respond, Visualizer Lite now automatically retries the other port, and — once that succeeds — saves the corrected URL so later connections go straight to the working port.

Fixed

  • Dependency security patches: fastify bumped from 5.8.5 to 5.12.1 (security release; fixes GHSA-w2qp-rph6-63g4 and GHSA-3m5p-2c4r-xxw2). fast-uri (transitive, via ajv/fast-json-stringify) bumped from 3.1.5 to 3.1.7 within existing package.json ranges — fixes four GHSA advisories (host confusion via skipped IDN canonicalization, SSRF via malformed IPv6 normalization, SSRF via repeated hostname percent-decoding, host confusion via percent-encoded scheme normalization).

Known issue (deferred): deepmerge-ts <8.0.0 (GHSA-ggr8-5vv4-36mx, stack exhaustion via recursive merge), pulled in by prisma's (devDependency, CLI only) @prisma/config. No 6.x release fixes this — the only upstream fix ships in Prisma 7/8, a major version with its own breaking-change migration, and latest currently points at an 8.0.0 release candidate, not a stable release. prisma is dev-only and pruned from the production image; the vulnerable merge only ever processes local, trusted config/schema files at deploy time, never user-supplied input, so real-world exploitability in this deployment is effectively nil.