fix(security): For bun, enforce frozen lockfile. For yarn, strongly suggest using frozen lockfile. (#5508)

* Updated docs for security information.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2025-10-24 16:48:35 -04:00
1 parent b517944cb5
commit 1009c60911
24 files changed
+69 -25

No files matched your search

+1 -1
View File
@@ -5,7 +5,7 @@ This website is built using [Docusaurus 2](https://docusaurus.io/), a modern sta
## Installation
```console
yarn install
yarn install --frozen-lockfile
```
## Local Development
@@ -156,7 +156,7 @@ inside your `public` folder. Since files are served from your local server the
the dicom files will be
`dicomweb:http://localhost:3000/LIDC-IDRI-0001/01-01-2000-30178/3000566.000000-03192/1-001.dcm`.
After `yarn install` and running `yarn dev` and opening the browser at
After `yarn install --frozen-lockfile` and running `yarn dev` and opening the browser at
`http://localhost:3000/viewer/dicomjson?url=http://localhost:3000/LIDC-IDRI-0001.json`
will display the viewer.
@@ -88,7 +88,7 @@ this repository's root directory, and run:
yarn config set workspaces-experimental true
# Restore dependencies
yarn install
yarn install --frozen-lockfile
# Run our dev command, but with the local orthanc config
yarn run dev:orthanc
@@ -37,7 +37,7 @@ This project contains two main components:
2. **Install Dependencies:**
```bash
yarn install
yarn install --frozen-lockfile
```
## Generating Static DICOMweb Files
+1 -2
View File
@@ -162,7 +162,7 @@ Update the data source configuration file with your Azure Healthcare APIs detail
```bash
cd OHIFViewer
yarn install
yarn install --frozen-lockfile
APP_CONFIG=config/azure.js yarn run dev
```
@@ -175,4 +175,3 @@ Update the data source configuration file with your Azure Healthcare APIs detail
- The `qidoRoot`, `wadoUriRoot`, and `wadoRoot` should point to your Azure DICOM service URL. Replace `{your-dicom-instance}` with your actual instance name.
This setup allows OHIF to interact seamlessly with Azure's Healthcare APIs, enabling robust DICOM management and visualization.
@@ -38,7 +38,7 @@ Next run these commands:
yarn config set workspaces-experimental true
# Restore dependencies
yarn install
yarn install --frozen-lockfile
# Build source code for production
yarn run build
@@ -127,7 +127,7 @@ Images can even be transcoded on the fly if this is desired.
```bash
cd OHIFViewer
yarn install
yarn install --frozen-lockfile
APP_CONFIG=config/google.js yarn run dev
```
@@ -80,11 +80,17 @@ following commands:
```bash
# Restore dependencies
yarn install
yarn install --frozen-lockfile
# Start local development server
yarn run dev
```
:::danger
In general run `yarn install` with the `--frozen-lockfile` flag to help avoid
supply chain attacks by enforcing reproducible dependencies. That is, if the
`yarn.lock` file is clean and does NOT reference compromised packages, then
no compromised packages should land on your machine by using this flag.
:::
You should see the following output:
@@ -113,6 +119,31 @@ You should see the following output:
yarn run build
```
### Updating Dependencies
In general you will typically not be updating the various `package.json` files.
But for the case when you do, you will have to also update the various OHIF lock files
and as such you will have to do both a `yarn` and `bun` `install` without
the `--frozen-lockfile` flag.
:::danger
Updating the package.json must be done with care so as to avoid incorporating
vulnerable, third-party packages and/or versions. Please research the added
packages and/or versions for vulnerabilities.
Here is what you should do when adding new packages and/or versions prior to
committing and pushing your code:
1. Do your due diligence researching the added packages and/or versions for vulnerabilities.
2. Update the `package.json` files.
3. Execute `yarn run install:update-lockfile`. This updates both the `yarn.lock` and
the `bun.lock` files.
4. Execute `yarn run audit` for a last security check. This runs both `yarn audit` and
`bun audit`.
6. Include both the `yarn.lock` and `bun.lock` files as part of your commit.
If any of your research or auditing for vulnerabilities find HIGH risk vulnerabilities
do NOT commit or push your changes! Low and moderate risk vulnerabilities are acceptable.
:::
## Troubleshooting
- If you receive a _"No Studies Found"_ message and do not see your studies, try
+1 -1
View File
@@ -20,7 +20,7 @@ To run the unit test:
yarn run test:unit:ci
```
Note: You should have already installed all the packages with `yarn install`.
Note: You should have already installed all the packages with `yarn install --frozen-lockfile`.
Running unit test will generate a report at the end showing the successful and
unsuccessful tests with detailed explanations.
@@ -57,7 +57,7 @@ yarn run dev
After:
```bash
yarn install
yarn install --frozen-lockfile
yarn run dev
```
@@ -88,7 +88,7 @@ this repository's root directory, and run:
yarn config set workspaces-experimental true
# Restore dependencies
yarn install
yarn install --frozen-lockfile
# Run our dev command, but with the local orthanc config
yarn run dev:orthanc