v1.10.3 — first frontend live-run remediation
Doc-only patch. First live audit run of the frontend stack (Level 2 + verified, against a real Vue 3.5 + Vite 7 + Tailwind 4 + pnpm project) surfaced 7 defects — two serious — now fixed.
Validated on the frontend run
Reproduction wave (re-run-scanner SCA method, static-by-default held), verified mode, audit-bugs.json step 6.6 (schema + integrity PASS), monorepo enumeration (D9: node_modules excluded, correctly identified independent apps).
Fixed (7 defects + package-manager preamble)
- F1 (blocks-run)
npm audithard-fails (ENOLOCK) on a pnpm project → was silently missing real vulns (10 found, 4 HIGH). Vuln scan now lockfile-aware (pnpm/yarn/bun/npm). - F2 (false-PASS)
vue-tsc --noEmiton a solution-style tsconfig (files:[]+references) checks the empty set, exit 0, hiding all type errors → usevue-tsc -b --noEmit. - F3 purgecss false-flags the whole stylesheet on Tailwind 4 (build-generated utilities) → skip_if + manual-grep fallback.
- F4 knip reported ~62 build artifacts as unused once
dist/exists → exclude dist/build +--no-progress. - F5 purgecss
--outputused bash$TMPDIR(unset on Windows) → PowerShell$env:TEMP. - F6 L1 Tests block had no PowerShell twin → added a Select-String detector twin.
- F7 + preamble frontend.md was npm-centric → added a package-manager detection preamble (lockfile → pnpm/yarn/bun/npm;
npxworks under all,pnpm dlxnative).
Verified: lint_docs.py PASS; independent review confirmed all APPLIED-CORRECT, no regressions.