Composer: ~40 Symfony 7.4.x packages patched to 7.4.17, plus four
majors - doctrine/dbal 3->4, phpdocumentor/reflection-docblock 5->6,
symfony/mercure-bundle 0.3->0.5, symfony/monolog-bundle 3->4. Removed
two doctrine.yaml keys (use_savepoints, report_fields_where_declared)
that DBAL 4 deprecated in favor of fixed defaults.
npm: @symfony/webpack-encore 4->6, which required bumping its peers
webpack-cli 5->6 and sass-loader 14->16 together, plus babel-loader
9->10. Fixes the one high-severity audit finding (RCE in
serialize-javascript, via the old css-minimizer-webpack-plugin). One
moderate finding remains in webpack-notifier's dev-only notification
chain - audit's suggested fix would downgrade it, so left alone; it's
build tooling only, never shipped to users.
Verified: full test suite green, lint:container clean, both `encore
dev` and `npm run build` compile without errors, and the production
CSS output was inspected byte-for-byte to confirm the new SVG-minifier
warnings (on Bootstrap's pre-encoded icon data-URIs) don't corrupt
anything.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Uses simple-datatables (vanilla JS, no jQuery needed) on the Users,
Sessions, Email Log, and Feedback tables, since those grow with real
usage. Left Games (small, admin-curated) and Hints (row order is
meaningful - "checked in order" - a sortable column would mislead)
untouched.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The audit fix (presumably run with --force) jumped @symfony/webpack-encore
from ^4.6.1 to ^7.1.0, which requires @babel/core ^8.0.0 as a peer -
but @babel/core was left at ^7.25.0, so a clean `npm install` failed
outright with ERESOLVE. Since docker/setup.sh and docker/restart.sh
both run npm install unconditionally, this would have broken every
future deploy/rebuild.
Reverted webpack-encore (and the incidentally-downgraded
webpack-notifier) back to the versions that were actually working,
regenerated package-lock.json, and verified both `npm install` and
`npm run build` succeed cleanly.