Skip to content

v0.3.3 — offline saves land on History instead of leaving a re-submittable form

Choose a tag to compare

@varunpan varunpan released this 11 Aug 12:46
· 16 commits to main since this release

Docker image: ghcr.io/varunpan/quicklogger:v0.3.3 (and :latest)

Pull with docker compose pull && docker compose up -d if you're tracking :latest.


[0.3.3] — 2026-08-11

Changed

  • Cleared both open npm audit advisories and refreshed every in-range
    dependency.
    Two high severity findings were failing CI's
    npm audit --audit-level=high gate: undici (five advisories, worst a
    cross-user information disclosure and parse-time crash via degenerate private
    cache directives —
    GHSA-4cwx-7wf7-3272,
    alongside response desynchronization, CRLF injection and cookie-attribute
    injection) and brace-expansion (a DoS via unbounded intermediate arrays that
    bypasses the earlier CVE-2026-14257 mitigation —
    GHSA-rgw5-rvv9-x895).
    Both reach the tree only through dev tooling (jsdom → undici, eslint →
    minimatch → brace-expansion) — neither ships in the runtime image, whose
    sole production dependency remains rotating-file-stream. The undici fix
    needed the overrides.jsdom.undici pin lifted from ^7.28.0 to ^7.29.0;
    everything else is lockfile-only: undici 7.28.0 → 7.29.0, brace-expansion
    5.0.8 → 5.0.9, plus in-range refreshes of svelte 5.56.3 → 5.56.8, vite
    8.0.16 → 8.2.1, @sveltejs/kit 2.70.1 → 2.70.2, @sveltejs/adapter-node
    5.5.4 → 5.5.7, eslint 10.5.0 → 10.8.1, @playwright/test 1.61.0 → 1.62.1,
    prettier 3.8.4 → 3.9.6, vitest 4.1.9 → 4.1.10 and the rest of the
    npm outdated "Wanted" column. npm audit now reports 0 vulnerabilities;
    the Trivy image scan was already clean at every severity. Dev/build
    dependencies only — no runtime or behaviour change. Major bumps available but
    deliberately deferred: @testing-library/jest-dom 7, jsdom 30,
    typescript 7.

Fixed

  • Photo OCR now reads kilometer odometers correctly. On an instance
    configured for kilometers, the vision model is now told the reading is in
    kilometers instead of miles.
  • The Log Fuel form opens on the vehicle you last picked. It used to always
    fall back to the first vehicle in your list, while History, Maintenance and
    Stats correctly remembered your choice.
  • The app no longer makes a failing network request for server settings when
    offline.
    The instance's units, currency and locale were already remembered
    between sessions; the boot refresh now reads them from the offline cache
    instead of failing silently.
  • Photos staged for attachment are cleared after an offline save. The next
    fill-up no longer inherits the previous entry's photos.
  • Saving a fill-up offline no longer leaves you on a full form, so it can't be
    queued twice.
    The save now clears the form and takes you to History, where
    the entry sits under an amber Queued badge as proof it landed — previously
    only a brief toast changed, so a second tap queued an identical fill-up. If a
    duplicate ever does reach the server, it's marked with a grey Skipped badge
    ("Already in LubeLogger — not written twice") instead of showing as a second
    real fill-up.
  • Documentation corrected throughout. The README quick start, the deployment
    and UAT guides, and the technical and user guides now match the shipped app.

Full changelog: CHANGELOG.md