Read the statement by Michael Teeuw here.
Posts
-
RE: Any plan to replace "request" and "moment"?
I think we should open an issue in the github repo to discuss the
momentstuff there, if it should be replaced and with what. Found this article.In the current mm release 2.16.0
requestis still a dev dependency but it is now totally removed on thedevelopbranch (and so in the next release). -
v2.29.0
https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.29.0
[2.29.0] - 2024-10-01
Thanks to: @bugsounet, @dkallen78, @jargordon, @khassel, @KristjanESPERANTO, @MarcLandis, @rejas, @ryan-d-williams, @sdetweil, @skpanagiotis.
⚠️ This release needs nodejs version
v20orv22, minimum version isv20.9.0Added
- [compliments] Added support for cron type date/time format entries mm hh DD MM dow (minutes/hours/days/months and day of week) see https://crontab.cronhub.io for construction (#3481)
- [core] Check config at every start of MagicMirror² (#3450)
- [core] Add spelling check (cspell):
npm run test:spellingand handle spelling issues (#3544) - [core] removed
config.paths.vendor(could not work becausevendoris hardcoded inindex.html), renamedconfig.paths.modulestoconfig.foreignModulesDir, added variableMM_CUSTOMCSS_FILEwhich - if set - overridesconfig.customCss, added variableMM_MODULES_DIRwhich - if set - overridesconfig.foreignModulesDir, added test forMM_MODULES_DIR(#3530) - [core] elements are now removed from
index.htmlwhen loading script or stylesheet files fails - [core] Added
MODULE_DOM_UPDATEDnotification each time the DOM is re-rendered viaupdateDom(#3534) - [tests] added minimal needed node version to tests (currently v20.9.0) to avoid releases with wrong node version info
- [tests] Added
node-libgpiodlibrary to electron-rebuild tests (#3563)
Removed
- [core] removed installer only files (#3492)
- [core] removed raspberry object from systeminformation (#3505)
- [linter] removed
eslint-plugin-import, because it doesn’t support ESLint v9. We will reenter it later when it does. - [tests] removed
onofflibrary from electron-rebuild tests (#3563)
Updated
- [weather] Updated
apiVersiondefault from 2.5 to 3.0 (#3424) - [core] Updated dependencies including stylistic-eslint
- [core] nail down
node-icalversion to0.18.0with exceptionallow-ghsas: GHSA-8hc4-vh64-cxmjindep-review.yaml(which should removed after nextnode-icalupdate) - [core] Updated SocketIO catch all to new API
- [core] Allow custom modules positions by scanning index.html for the defined regions, instead of hard coded (PR #3518 fixes issue #3504)
- [core] Detail optimizations in
config_check.js - [core] Updated minimal needed node version in
package.json(currently v20.9.0) (#3559) and except for v21 (no security updates) (#3561) - [linter] Switch to ESLint v9 and flat config and replace
eslint-plugin-unicornby@eslint/js - [core] fix discovering module positions twice after #3450
Fixed
- Fixed
checksbadge in README.md - [weather] Fixed issue with the UK Met Office provider following a change in their API paths and header info.
- [core] add check for node_helper loading for multiple instances of same module (#3502)
- [weather] Fixed issue for respecting unit config on broadcasted notifications
- [tests] Fixes calendar test by moving it from e2e to electron with fixed date (#3532)
- [calendar] fixed sliceMultiDayEvents getting wrong count and displaying incorrect entries, Europe/Berlin (#3542)
- [tests] ignore
js/positions.jswhen linting (this file is created at runtime) - [calendar] fixed sliceMultiDayEvents showing previous day without config enabled
-
RE: MagicMirror is safe...
it’s not repo specific but attached to the user, see https://github.com/sdetweil
-
RE: `npm ci` instead of `npm install`
yes, and AFAIK you are using
npm install --only=prod. This is may a thing to be mentioned in the docs because 99% of the users don’t need the dev dependencies … -
v2.36.0
Release Notes
Thanks to: @cgillinger, @khassel, @KristjanESPERANTO, @sonnyb9
⚠️ This release needs nodejs version >=22.21.1 <23 || >=24 (no change to previous release)
Compare to previous Release v2.35.0
This release falls outside the quarterly schedule. We opted for an early release due to:
- Security fix for the internal cors proxy
- API change of the weather provider smi
- Several bug fixes
Breaking Changes
The cors proxy is now disabled by default. If required, it must be explicitly enabled in the
config.jsfile. See the documentation.⚠️ Security
You can find several publicly accessible MagicMirror² instances.
This should never be done. Doing so makes your entire configuration, including secrets and API keys, publicly visible. Furthermore, it allows attackers to target the host; this is only prevented beginning with this release.
Public MagicMirror² instances should always run behind a reverse proxy with authentication.
[core]
- Prepare Release 2.36.0 (#4126)
- Allow HTTPFetcher to pass through 304 responses (#4120)
- fix(http-fetcher): fall back to reloadInterval after retries exhausted (#4113)
- config endpoint must handle functions in module configs (#4106)
- fix replaceSecretPlaceholder (#4104)
- restrict replaceSecretPlaceholder to cors with allowWhitelist (#4102)
- fix: prevent crash when config is undefined in socket handler (#4096)
- fix cors function for alpine linux (#4091)
- fix(cors): prevent SSRF via DNS rebinding (#4090)
- add option to disable or restrict cors endpoint (#4087)
- fix: prevent SSRF via /cors endpoint by blocking private/reserved IPs (#4084)
- chore: add permissions section to enforce pull-request rules workflow (#4079)
- update version for develop
[dependencies]
- update dependencies (#4124)
- chore: update dependencies (#4088)
- refactor: enable ESLint rule “no-unused-vars” and handle related issues (#4080)
[modules/newsfeed]
- fix(newsfeed): prevent duplicate parse error callback when using pipeline (#4083)
[modules/updatenotification]
- fix(updatenotification): harden git command execution + simplify checkUpdates (#4115)
- fix(tests): correct import path for git_helper module in updatenotification tests (#4078)
[modules/weather]
- fix(weather): use nearest openmeteo hourly data (#4123)
- fix(weather): avoid loading state after reconnect (#4121)
- weather: fix UV index display and add WeatherFlow precipitation (#4108)
- fix(weather): restore OpenWeatherMap v2.5 support (#4101)
- fix(weather): use stable instanceId to prevent duplicate fetchers (#4092)
- SMHI: migrate to SNOW1gv1 API (replace deprecated PMP3gv2) (#4082)
[testing]
- ci(actions): set explicit token permissions (#4114)
- fix(http_fetcher): use undici.fetch when dispatcher is present (#4097)
- ci(codeql): also scan develop branch on push and PR (#4086)
- refactor: replace implicit global config with explicit global.config (#4085)
-
RE: Alexa implementations now more difficult, and some features will stop working
thats amazon …
had a docker image containing Alexa Voice Service but because of more and more limitations I gave up a few months ago.
-
RE: automatic update module by notification
@bdream said in automatic update module by notification:
I would prefer having an automatic to update in case it’s notified.
option1: Adding a new paramter “forceUpdate” to the notification module so that it does the update instead of the notification (someone has to code this)
option2: Write a bash script which iterates over the module folders doing something like this (in every module folder)
git reset --hard git pull [ -f "package.json" ] && npm installThis script should be executed e.g. daily by e.g. a cronjob.
As Sam already mentioned this would be the hard way, may its better not to change a running system and ignore the notification, your decision.
-
RE: `git clone` with `--depth=1`?
single branch could be another option like here.
But we should update the doc from
npm installtonpm install --only=prod(sam uses this already in his install script), because the devDependencies are really fat. -
RE: I'm getting error -MESA-LOADER: failed to open swrast: /usr/lib/dri/swrast_dri.so: cannot open shared object file: Permission denied
or forgot to run
npm installin the module folder of MMM-FlightsAbove -
RE: ISS tracker
@bhepler said in ISS tracker:
@karsten13 - I don’t know which map framework you’re running, but I’ve been using Leaflet and it gives me a lot of flexibility in maps. Several free tile sources and many more that just require an API key. You can see a simple example at my MMM-Birdnet module. Specifically, check out the map options.
thanks!
I’m using ol (openlayers), with your help I found already the free cards of cartodb, they should work with ol too.
-
RE: Need help for tests suite
from mm folder
npx jest tests/...<filename> -
RE: MMM-Flights
is it possible to locate the list of flights on the right of the map, so I can utilize landscape mode better?
pushed a new version which supports now 4 map positions top, bottom, left, right
-
RE: raspi 64 bit available
If you use the WebUI the changes are made here:
pi@pi4:~ $ cat /usr/share/dispsetup.sh #!/bin/sh if ! grep -q 'Raspberry Pi' /proc/device-tree/model || (grep -q okay /proc/device-tree/soc/v3d@7ec00000/status 2> /dev/null || grep -q okay /proc/device-tree/soc/firmwarekms@7e600000/status 2> /dev/null || grep -q okay /proc/device-tree/v3dbus/v3d@7ec04000/status 2> /dev/null) ; then if xrandr --output HDMI-1 --primary --mode 1920x1080 --rate 60.000 --pos 0x0 --rotate normal --output HDMI-2 --off --dryrun ; then xrandr --output HDMI-1 --primary --mode 1920x1080 --rate 60.000 --pos 0x0 --rotate normal --output HDMI-2 --off fi fi if [ -e /usr/share/tssetup.sh ] ; then . /usr/share/tssetup.sh fi exit 0So editing this script should work for command line.
-
RE: Module for MagicMirror forum
the use of a csrf token is restricted to admins (as already mentioned by @bugsounet), there is a hack described here to open this for all users but I don’t think we should do this.
For accessing the read(-only) api you can use a cookie from your browser, e.g.
curl --cookie "express.sid=xxxxxxx" https://forum.magicmirror.builders/api/unreadbut this would be challenging to use in a module for mm …
-
RE: GIT and updates to Weather Module
2 more things:
- the new branch you are using should start on the mm-branch
develop(notmaster) - when creating the PR on github you have to manually change the base branch from
mastertodevelop
These rules are specific to the mm-repo. Because of quarterly releases the
masterbranch only changes 4 times in a year. The development between the releases is done ondevelop. - the new branch you are using should start on the mm-branch
-
RE: Alt Key Doesn't Open Menu
@sdetweil said in Alt Key Doesn't Open Menu:
I see how to do the disable in code, but we don’t do that.
we are using
frame: falsein electronOptions -
RE: updatenotification
@Ray said in updatenotification:
is it possible to instruct ignoremodules not to look for MagicMirror updates
looking at the sources this is not possible at the moment but it is easy to implement. Can you open an issue on github for this? Thanks.