Repository navigation
Bump esbuild and vite in /ki-hypothesen-test - #20
Closed
dependabot[bot] wants to merge 20 commits into
Closed
dependabot[bot] wants to merge 20 commits into
dependabot[bot] wants to merge 20 commits into
Conversation
Aktualisieren von README.md
- Add SECURITY.md with vulnerability reporting guidelines - Add CodeQL workflow for C++ static analysis - Add clang-tidy workflow for code quality checks - Add cppcheck workflow for additional static analysis - Add Dependabot configuration for dependency scanning - Update README.md with security information and links Closes #security-policy Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add SBOM generation workflow with Syft (SPDX and CycloneDX) - Add Fuzzing workflow with AFL++ for kissfft library - Add Trivy vulnerability scanning workflow These workflows complement the existing CodeQL, clang-tidy, and cppcheck workflows for comprehensive security coverage. Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add CONTRIBUTING.md with security guidelines, coding standards, and contribution rules - Add ISSUE_TEMPLATE for bug reports, feature requests, and security vulnerabilities - Add PULL_REQUEST_TEMPLATE.md for standardized PR descriptions - Add CODEOWNERS for repository ownership - Add labeler.yml for automatic issue/PR labeling - Optimize clang-tidy workflow with path filtering and CMake integration - Optimize cppcheck workflow with path filtering and artifact upload - Optimize fuzzing workflow with configurable time and manual dispatch - Add build.yml for Linux/Windows build testing - Add ci.yml for comprehensive CI pipeline Closes #contributing-guidelines Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add CODE_OF_CONDUCT.md based on Contributor Covenant - Add OWASP ZAP workflow for dynamic security analysis - Optimize all workflows with actions/cache for: - clang-tidy (CMake build cache) - cppcheck (cppcheck cache) - build.yml (CMake dependencies cache) - ci.yml (all tool caches) - fuzzing.yml (AFL++ corpus cache) - Adjust fuzzing duration to 600s (10 minutes) default - Add parallel fuzzing support with configurable cores - Add input validation for Fuzzing workflow - Add cache for Trivy and Syft in CI pipeline Closes #owasp-zap Closes #workflow-optimization Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add Snyk workflow for vulnerability scanning (requires SNYK_TOKEN secret) - Add SonarQube workflow for code quality analysis (requires SONAR_TOKEN) - Add sonar-project.properties for SonarQube configuration - Add kodi-addon-checks.yml for Kodi-specific validations: - Addon XML validation - Kodi API compatibility checks - Visualization-specific requirements - Thread safety checks - Performance considerations - Add DEPENDENCY_POLICY.md with: - Approved dependencies list - Dependency update process - Security requirements - License compatibility matrix - Maintenance schedule These additions provide comprehensive security and quality analysis for the visualization.matrix addon, tailored specifically for Kodi addons. Closes #snyk Closes #sonarqube Closes #kodi-checks Closes #dependency-policy Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add Semgrep workflow for custom security rules with .semgrep.yml - Rules for memory safety (malloc, strcpy, sprintf) - Kodi-specific rules (deprecated APIs, required methods) - FFT-specific rules (input validation, power-of-two checks) - Modern C++ best practices (const references, nullptr, auto) - Add CHANGELOG.md following Keep a Changelog format - Add changelog.yml workflow for automatic CHANGELOG generation - Triggered on push to master/Matrix/Nexus - Triggered on tag pushes (v*) - Manual dispatch with version input - Dry-run mode for testing - Add Dockerfile for consistent build environments - Multi-stage build (builder + runtime) - Installs all build dependencies (CMake, g++, Mesa, clang-tidy, cppcheck) - Clones Kodi source for addon building - Supports multi-arch builds (amd64, arm64, arm/v7) - Add docker.yml workflow for Docker builds and security scanning - Builds Docker image with Buildx - Supports multi-platform builds - Scans images with Trivy - Pushes to GitHub Container Registry Closes #semgrep Closes #changelog Closes #docker-builds Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Add comprehensive security, CI/CD, Docker, and changelog framework
- Clamp m_albumX and m_albumY to [-1.0, 1.0] to prevent album art from extending beyond the screen edges in the Album preset. - Fix redundant m_AlbumNeedsUpload assignment (set to false after upload). - Resolves FIXME comment in RenderTo() for proper framing. Closes #N/A Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add new 'Neon' preset (labelId 30108) to g_presets list. - Create neon.frag.glsl shader with: - Pulsing neon grid background - Audio-reactive brightness and glow effects - Cyan/magenta color scheme - Uses only audio channel (no textures required). Closes #N/A Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
…e108b Fix album art framing to stay within screen bounds
…hos² themes - New GLSL shader (odysseus.frag.glsl) combining: - Dynamic matrix grid with falling symbols (⛵ Odysseus, ✈ Hermes, ➕ Helvetia, π) - π-based noise and patterns - Odysseus' spiral path - Hermes' winged shapes - Helvetia's Swiss cross - Mythos² recursive matrix layers - Audio reactivity for all elements - Added preset to main.cpp (ID 30109) - Added localized string for Odysseus preset Closes #751c4c Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
* feat: Major optimizations and modernizations - Modernized CMake build system (3.20+, FetchContent for kissfft) - Consolidated CI/CD workflows into single main.yml - Improved code quality with std::vector and modern C++ practices - Optimized Docker multi-stage build with .dockerignore - Added clang-format configuration and workflow - Added cache management workflow - Removed obsolete Find*.cmake files - Fixed memory management (automatic cleanup with vectors) - Fixed potential bug in m_AlbumNeedsUpload logic - Improved type safety with constexpr and static_cast Closes #optimization-request Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com> * chore: remove trailing whitespace from merged shaders Co-authored-by: MarcelRaschke <42359664+MarcelRaschke@users.noreply.github.com> --------- Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai> Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…nce (#6) - Fix FIXME 1: Clamp album position to prevent overflow over screen edges - Fix FIXME 2: Reset m_AlbumNeedsUpload after upload (only for album shader) - Add Google Test framework and unit tests for BlackmanWindow, LinearToDecibels, SmoothingOverTime - Add SHADERS.md with comprehensive documentation of all shaders, uniforms, and constants - Optimize performance: Only set m_AlbumNeedsUpload for album shader (channel[3] == 2) Closes #N/A Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai> Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Add an independent React + Vite + TypeScript SPA in the ki-hypothesen-test/ subfolder (unrelated to the C++ Kodi addon). Components: - Sidebar: collapsible, searchable topics sidebar (categories + topics) - LessonsTab: knowledge base with category cards, popular & recent lessons - TopicModal: accessible modal for topic details + related lessons Data/types/hooks: - types/hypothesis.ts: Hypothesis type incl. field + status enums - types/topics.ts: Category / Topic / Lesson types - data/topics.json: static categories, topics, lessons - hooks/useTopics.ts: custom hook with derived popular/recent views App.tsx wires tabs (Hypotheses / Knowledge Base), sidebar, modal, hypothesis form with topic dropdown, and filterable hypothesis table. Uses for all type-only imports (verbatimModuleSyntax). Build verified: tsc -b + vite build pass. Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai> Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
…ake (#11) - CMake: activate the BUILD_TESTING path (was a no-op) via add_subdirectory(tests) so ctest actually runs the existing GoogleTest suite. - CMake: make ENABLE_COVERAGE use directory-scoped add_compile/add_link_options (--coverage -O0 -g) ordered before the test subdirectory so the test target inherits coverage flags too; guard against non-GCC/Clang toolchains. - CMake: replace the brittle clang-tidy target-property stub with proper CMAKE_CXX_CLANG_TIDY / CMAKE_CXX_CPPCHECK wiring that finds the tools and gracefully skips when absent (ENABLE_CLANG_TIDY / ENABLE_CPPCHECK). - CMake: add optional ENABLE_TRACY / TRACY_ON_DEMAND options that define TRACY_ENABLE/TRACY_ON_DEMAND and add the tracy include dir when the headers are present, and no-op otherwise. - tests/CMakeLists.txt: convert from a standalone project() to a proper subdirectory; fetch GoogleTest via FetchContent (no system GTest dependency) and register the test with add_test. - src/tracyprofiler.h: dependency-free instrumentation shim that pulls in Tracy zones when TRACY_ENABLE is defined and the headers exist, else expands to no-ops, so sources can be instrumented unconditionally. - .github/workflows/code-coverage.yml: new gcov/lcov CI workflow that builds with BUILD_TESTING+ENABLE_COVERAGE, runs ctest, captures/filters lcov, and uploads an HTML coverage report. Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai> Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
…sistence (#16) * feat: expand topics, customize Tailwind styling, add localStorage persistence - Add 3 new categories (Modellarchitekturen, Datenverarbeitung, Zukunft & Forschung) - Add 12 new topics with 28 lessons (total: 6 categories, 22 topics, 36 lessons) - Customize Tailwind with primary/secondary color palettes, Inter font, animations - Add useLocalStorage hook for hypothesis persistence across sessions - Add delete functionality with confirmation - Update all components to use custom Tailwind classes Closes #14 Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com> * docs: add built KI Hypothesen Test app to docs/ki-hypothesen-test/ Static build of the React/Vite app for GitHub Pages deployment. Serves at: https://MarcelRaschke.github.io/visualization.matrix/ki-hypothesen-test/ Closes #14 Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com> --------- Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai> Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Define 5 phases with clear milestones (2025-2026) - Include prioritization matrix and success metrics (KPIs) - Add Gantt chart for visual timeline - Document risks, dependencies, and resource requirements - Link to existing project documentation Closes #roadmap (if applicable) Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai> Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai> Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Removes [esbuild](https://github.com/evanw/esbuild). It's no longer used after updating ancestor dependency [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). These dependencies need to be updated together. Removes `esbuild` Updates `vite` from 5.4.21 to 8.2.2 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.2/packages/vite) --- updated-dependencies: - dependency-name: esbuild dependency-version: dependency-type: indirect - dependency-name: vite dependency-version: 8.2.2 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
MarcelRaschke
approved these changes
Sep 11, 2026
Owner
|
@copilot, behebe bitte die Mergekonflikte in diesem Pull Request. |
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/ki-hypothesen-test/multi-64d6452dd2
branch
September 11, 2026 21:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Removes esbuild. It's no longer used after updating ancestor dependency vite. These dependencies need to be updated together.
Removes
esbuildUpdates
vitefrom 5.4.21 to 8.2.2Release notes
Sourced from vite's releases.
... (truncated)
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
de1111arelease: v8.2.2cb77e2atest(ssr): add destructing assignment case for moduleRunnerTransform (#23308)9db0b61fix(ssr): rewrite computed key of destructing parameter (#23307)8413052fix: respectresolve.preserveSymlinkswhen resolving root (fix #23197) (#23...05a003efix(config): resolve sourcemap paths against sourcemap location (#23239)495d9fffeat(deps): widen@vitejs/devtoolspeer range to v0.5.0 (#23302)1d9fa39refactor: use JSON import attributes instead of readFileSync in constants (#2...2804636fix(css): don't pass empty targets to lightningcss (#23295)599b44btest(module-runner): simplify server-hmr tests (#23300)4a261f2test(module-runner): add TLA circular import case (#23299)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.