fix(security): For bun, enforce frozen lockfile. For yarn, strongly suggest using frozen lockfile. (#5508)
* Updated docs for security information.
This commit is contained in:
1 parent
b517944cb5
commit
1009c60911
24 files changed
+69
-25
No files matched your search
@@ -5,7 +5,7 @@ This website is built using [Docusaurus 2](https://docusaurus.io/), a modern sta
|
||||
## Installation
|
||||
|
||||
```console
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
```
|
||||
|
||||
## Local Development
|
||||
|
||||
@@ -156,7 +156,7 @@ inside your `public` folder. Since files are served from your local server the
|
||||
the dicom files will be
|
||||
`dicomweb:http://localhost:3000/LIDC-IDRI-0001/01-01-2000-30178/3000566.000000-03192/1-001.dcm`.
|
||||
|
||||
After `yarn install` and running `yarn dev` and opening the browser at
|
||||
After `yarn install --frozen-lockfile` and running `yarn dev` and opening the browser at
|
||||
`http://localhost:3000/viewer/dicomjson?url=http://localhost:3000/LIDC-IDRI-0001.json`
|
||||
will display the viewer.
|
||||
|
||||
|
||||
@@ -88,7 +88,7 @@ this repository's root directory, and run:
|
||||
yarn config set workspaces-experimental true
|
||||
|
||||
# Restore dependencies
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
|
||||
# Run our dev command, but with the local orthanc config
|
||||
yarn run dev:orthanc
|
||||
|
||||
@@ -37,7 +37,7 @@ This project contains two main components:
|
||||
2. **Install Dependencies:**
|
||||
|
||||
```bash
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
```
|
||||
|
||||
## Generating Static DICOMweb Files
|
||||
|
||||
@@ -162,7 +162,7 @@ Update the data source configuration file with your Azure Healthcare APIs detail
|
||||
|
||||
```bash
|
||||
cd OHIFViewer
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
APP_CONFIG=config/azure.js yarn run dev
|
||||
```
|
||||
|
||||
@@ -175,4 +175,3 @@ Update the data source configuration file with your Azure Healthcare APIs detail
|
||||
- The `qidoRoot`, `wadoUriRoot`, and `wadoRoot` should point to your Azure DICOM service URL. Replace `{your-dicom-instance}` with your actual instance name.
|
||||
|
||||
This setup allows OHIF to interact seamlessly with Azure's Healthcare APIs, enabling robust DICOM management and visualization.
|
||||
|
||||
@@ -38,7 +38,7 @@ Next run these commands:
|
||||
yarn config set workspaces-experimental true
|
||||
|
||||
# Restore dependencies
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
|
||||
# Build source code for production
|
||||
yarn run build
|
||||
|
||||
@@ -127,7 +127,7 @@ Images can even be transcoded on the fly if this is desired.
|
||||
|
||||
```bash
|
||||
cd OHIFViewer
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
APP_CONFIG=config/google.js yarn run dev
|
||||
```
|
||||
|
||||
|
||||
@@ -80,11 +80,17 @@ following commands:
|
||||
|
||||
```bash
|
||||
# Restore dependencies
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
|
||||
# Start local development server
|
||||
yarn run dev
|
||||
```
|
||||
:::danger
|
||||
In general run `yarn install` with the `--frozen-lockfile` flag to help avoid
|
||||
supply chain attacks by enforcing reproducible dependencies. That is, if the
|
||||
`yarn.lock` file is clean and does NOT reference compromised packages, then
|
||||
no compromised packages should land on your machine by using this flag.
|
||||
:::
|
||||
|
||||
You should see the following output:
|
||||
|
||||
@@ -113,6 +119,31 @@ You should see the following output:
|
||||
yarn run build
|
||||
```
|
||||
|
||||
### Updating Dependencies
|
||||
In general you will typically not be updating the various `package.json` files.
|
||||
But for the case when you do, you will have to also update the various OHIF lock files
|
||||
and as such you will have to do both a `yarn` and `bun` `install` without
|
||||
the `--frozen-lockfile` flag.
|
||||
|
||||
:::danger
|
||||
Updating the package.json must be done with care so as to avoid incorporating
|
||||
vulnerable, third-party packages and/or versions. Please research the added
|
||||
packages and/or versions for vulnerabilities.
|
||||
|
||||
Here is what you should do when adding new packages and/or versions prior to
|
||||
committing and pushing your code:
|
||||
1. Do your due diligence researching the added packages and/or versions for vulnerabilities.
|
||||
2. Update the `package.json` files.
|
||||
3. Execute `yarn run install:update-lockfile`. This updates both the `yarn.lock` and
|
||||
the `bun.lock` files.
|
||||
4. Execute `yarn run audit` for a last security check. This runs both `yarn audit` and
|
||||
`bun audit`.
|
||||
6. Include both the `yarn.lock` and `bun.lock` files as part of your commit.
|
||||
|
||||
If any of your research or auditing for vulnerabilities find HIGH risk vulnerabilities
|
||||
do NOT commit or push your changes! Low and moderate risk vulnerabilities are acceptable.
|
||||
:::
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
- If you receive a _"No Studies Found"_ message and do not see your studies, try
|
||||
|
||||
@@ -20,7 +20,7 @@ To run the unit test:
|
||||
yarn run test:unit:ci
|
||||
```
|
||||
|
||||
Note: You should have already installed all the packages with `yarn install`.
|
||||
Note: You should have already installed all the packages with `yarn install --frozen-lockfile`.
|
||||
|
||||
Running unit test will generate a report at the end showing the successful and
|
||||
unsuccessful tests with detailed explanations.
|
||||
|
||||
@@ -57,7 +57,7 @@ yarn run dev
|
||||
|
||||
After:
|
||||
```bash
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
yarn run dev
|
||||
```
|
||||
|
||||
|
||||
@@ -88,7 +88,7 @@ this repository's root directory, and run:
|
||||
yarn config set workspaces-experimental true
|
||||
|
||||
# Restore dependencies
|
||||
yarn install
|
||||
yarn install --frozen-lockfile
|
||||
|
||||
# Run our dev command, but with the local orthanc config
|
||||
yarn run dev:orthanc
|
||||
|
||||
Reference in new issue
Block a user