@mss-boot-io/admin-web
v1.3.8
Published
Complete React 19 and Ant Design 6 Admin application for mss-boot business hosts.
Downloads
427
Readme
@mss-boot-io/admin-web
v1.3.7 stable status
v1.3.7 is the current stable, adoptable Complete Admin Distribution. The exact
web/antd-v6/v1.3.7 Release and official
@mss-boot-io/[email protected] npmjs package were qualified with the matching
Framework, Admin, Root tools, and images from merged-main commit
77b53d41092741eac62fa6418c0bdbf87413c7cd. Thin Hosts pin this exact package;
the npm latest tag also resolves to 1.3.7.
v1.3.5 and v1.3.6 remain immutable partial trains. web/antd-v6/v1.3.6, its
GitHub Release, and GitHub Packages assets are public and immutable, but the
official npmjs identity @mss-boot-io/[email protected] was not published.
Neither partial train has a supported complete installation path.
Do not substitute a GitHub Packages artifact, Release tarball, local package,
or source checkout for an official npmjs identity. The Docs website publishes
independently and may lag; a docs/v* tag or site deployment does not change
this package's availability or stable identity.
Package contract
Admin Web is the Distribution's single complete browser application: React 19, Ant Design 6, Umi Max, React Query, generated API contracts, authentication shell, page states, locales, and the narrow business-route extension.
The v1.3.7 npm package provides these declared exports:
@mss-boot-io/admin-webor/runtimefor the packaged runtime;/businessfor generated business registration;/presetfor the supported Umi preset;/stylesfor the public style entry;/testingfor package-supported test helpers.
The package also defines the mss-admin-web command used by a generated Thin
Host. Consumers must not import src/*, copy core pages, redirect aliases to
Foundation source, or create a second SPA.
Release builds cap JavaScript and CSS compression at two workers each to avoid allocating separate JavaScript heaps for every available CPU core. The production compression settings, runtime checks, and bundle budgets continue to apply.
Tailwind scans explicit TS/TSX source roots instead of automatically scanning the workspace. Generated Thin Hosts scan both the packaged Admin core and their own business sources; the reference application scans its own source tree.
Business routes register together with their menu projection before the final 403/404 fallbacks. Client access checks improve user experience; backend authorization remains authoritative. Retained pages represent loading, empty, retryable error, denied, and responsive states with synchronized Chinese and English locale keys.
The stable package also contains the statically compiled presentation-configuration console. Its profiles remain strictly data-only, its frontend permission state is advisory to backend RBAC, and production business capability registration is empty so existing pages retain compiled defaults.
Install the official public package with
corepack [email protected] add --save-exact @mss-boot-io/[email protected].
Official npm publication remains credentialless through the exact
npm-release.yml plus npm-auto Trusted Publisher identity; no npm token is
stored. See
package status and
mss-shop status.
Repository-source build and publication commands remain contributor-only in
AGENTS.md and CHANGELOG.md.
Workplace business content
The proposed compile-time contribution interface is described in the adopter guide. It is unreleased and preserves the core workplace.
Candidate dependency maintenance
The next candidate pins Axios 0.34.0 for GHSA-x97p-jq2g-jp4f. Its build graph also pins patched fast-uri 3.1.8, hono 4.13.7, moment 2.31.0, js-yaml 3.15.2/4.3.2, brace-expansion 1.1.21/2.1.7, piscina 4.9.4, and svgo 2.8.4. These overrides travel with the package contract to generated Thin Hosts, so installing the package does not restore the vulnerable transitive versions.
GHSA-vfj7-8cjw-p6xm
has no upstream braces fix. Its exception expires on 2026-11-08, accepts only
the exact declared build version, and requires every dependency path to be
tooling-only. The production bundle check rejects braces; runtime high or
critical advisories remain release blockers. The complete exception ledger is
pnpm-audit-acceptances.json.
