8.2 KiB
Stack Profile — iot-standards-lab-landing
Reference prototype landing page for the KNU CS IoT Standards Lab. Workspace:
/home/godopu16/PuKi/lab/landing_page/refer_landing_pageProduced as the deliverable for kanban taskt_239791d2.
1. Languages, Frameworks, Package Manager
| Layer | Pin / Range | Installed | Latest | Note |
|---|---|---|---|---|
| Language | TypeScript ^5.5.3 |
5.9.3 | 6.0.3 | Pin is fine; major jump to TS 6 is non-breaking for most code |
| Framework | Next.js 14.2.5 (exact) |
14.2.5 | 16.2.9 | 2 majors behind; line-locked by app's React 18 dep |
| UI runtime | react ^18.3.1, react-dom ^18.3.1 |
18.3.1 | 19.2.7 | React 19 is available but is a major — see §5 |
| Package manager | npm (single package-lock.json, lockfile v3) |
npm 10.9.7 | — | No pnpm-lock.yaml / yarn.lock / bun.lockb present |
| Runtime | Node v22.22.2 (host) | — | — | No engines field declared |
Type system config (tsconfig.json):
strict: true,noEmit: true,incremental: truemoduleResolution: "bundler",jsx: "preserve",isolatedModules: trueplugins: [{ "name": "next" }], path alias@/*→./*
Next.js config (next.config.js):
reactStrictMode: true; no image domains, no redirects, no rewrites, no headers, no experimental flags. Minimal by design.
Styling:
- Tailwind CSS
^3.4.6(installed 3.4.19) — latest line is 4.x; thetailwind.config.tsis rich enough (114 lines, custom theme) that the v3→v4 jump is a planned migration, not anpm update. postcss.config.jswires Tailwind +autoprefixer(^10.4.19).- Font stack is loaded via
next/fontand exposed as CSS variables — no external font loader (Google Fonts, Fontsource) is in the dep tree.
Not present:
- No
Dockerfile/docker-compose*/dockerignore— there is no container image for this app. - No
.env,.env.example,.envrc— the app reads no env vars. - No
.eslintrc*file and noeslintConfigblock inpackage.json. ESLint runs throughnext lint, which useseslint-config-next's defaults (core-web-vitals+next/typescript). - No
.prettierrc*— formatting is not enforced in CI. - No
.github/, no.gitlab-ci.yml, no.circleci/— no CI pipeline.
2. Dependencies
Direct (runtime) — 3 packages
| Package | Pin | Purpose |
|---|---|---|
next |
14.2.5 (exact) |
Framework |
react |
^18.3.1 |
UI library |
react-dom |
^18.3.1 |
DOM renderer |
Dev — 10 packages
| Package | Pin | Purpose |
|---|---|---|
@types/node |
^20.14.0 |
Node typings (dev only) |
@types/react |
^18.3.3 |
React typings |
@types/react-dom |
^18.3.0 |
React DOM typings |
autoprefixer |
^10.4.19 |
PostCSS plugin |
postcss |
^8.4.39 |
CSS pipeline |
tailwindcss |
^3.4.6 |
Utility CSS |
typescript |
^5.5.3 |
Compiler |
eslint |
^8.57.0 |
Linter |
eslint-config-next |
14.2.5 (exact, matches Next) |
Next-flavored ESLint config |
Observations:
- Footprint is intentionally minimal — no
framer-motion, no UI lib (shadcn/Radix/MUI), no icon set, no analytics, no CMS client, no image CDN. nextandeslint-config-nextare pinned exact (no^);reactandreact-domuse^. This is the right call: Next and its ESLint config must move together.- Dev types are pinned to React 18, consistent with the runtime.
package-lock.jsonis 215 KB → transitive tree is fairly clean; the project has no obvious bloat.
3. Scripts
Four npm scripts, all thin wrappers around next:
| Script | Command | Use |
|---|---|---|
npm run dev |
next dev |
Local dev server (default port 3000) |
npm run build |
next build |
Production build → .next/ |
npm start |
next start |
Run the production build |
npm run lint |
next lint |
ESLint via Next's wrapper |
No test, format, typecheck, prepare, pre-commit, or any other lifecycle hooks. The 4-script surface is honest: linting is the only quality gate declared.
4. Configuration / Manifest Inventory
| File | Lines | Notes |
|---|---|---|
package.json |
28 | Single manifest, no engines, no workspaces |
package-lock.json |
(215 KB) | npm v3 lockfile |
tsconfig.json |
22 | strict, bundler resolution, @/* alias |
next.config.js |
6 | reactStrictMode: true only |
tailwind.config.ts |
114 | Editorial design tokens, custom colors, custom animations |
postcss.config.js |
6 | tailwindcss + autoprefixer |
next-env.d.ts |
5 | Next-managed, gitignored |
tsconfig.tsbuildinfo |
(80 KB) | Incremental build cache, gitignored |
.gitignore |
27 | Standard Next.js ignore set |
.kanban-inventory.json |
137 | Upstream inventory artifact (not a config) |
.antigravity-session.md |
46 | Upstream runtime artifact (not a config) |
5. Outdated / Vulnerable Pins (Trivially Obvious)
Vulnerabilities (from npm audit) — 8 advisories, 1 critical
next@14.2.5 is affected by 21 published advisories that are fixed in 14.2.35 (same line, not a major jump):
- Critical (1): Cache poisoning (GHSA-gp8f-8m3g-qvj9)
- High (6): DoS via Server Components, image optimizer, middleware cache poisoning, SSRF via middleware redirect, etc.
- Moderate (1): PostCSS XSS via unescaped
</style>(transitive throughnext/node_modules/postcss)
Plus transitive:
glob10.2.0–10.4.5 — command injection in CLI (only triggered ifglob's CLI is invoked; not a runtime risk for this Next app)minimatch9.0.0–9.6 — ReDoS (transitive via ESLint's glob walker; dev-time only)
Recommended fix (lowest-risk): npm install next@14.2.35 — same major, same line, fixes 21 Next advisories + the transitive postcss advisory. Does not require React changes. npm audit fix --force would jump to Next 16 + React 19 — that's a planned migration, not a security patch.
Outdated-by-major pins (information only — not security)
| Pin | Major delta | Risk profile |
|---|---|---|
next 14 → 16 |
App Router stabilized; some breaking changes (params async, etc.) | Planned migration |
react/react-dom 18 → 19 |
New compiler, ref as prop, async transitions | Requires Next 15+ |
eslint 8 → 10 |
Flat config becoming default | Could be deferred |
typescript 5 → 6 |
Mostly compat, some strictness tightening | Trivial in this codebase |
tailwindcss 3 → 4 |
New engine, config format change | Significant migration (would touch tailwind.config.ts) |
@types/* React 18 → 19, Node 20 → 25 |
Mismatched with installed Node 22 host | Cosmetic |
@types/node 20 → 25 |
Host is Node 22 — current pin still works but 25 would track current Node |
Cosmetic |
The biggest near-term "looks dated" item is the React 18 + Next 14 stack (released mid-2024), but everything is internally consistent — no mixed majors, no version skew between next and eslint-config-next. The stack is intentionally conservative.
Compatibility sketch (host vs declared)
- Host Node 22, npm 10.9.7 — fits Next 14 / React 18 cleanly. No
enginesfield; any contributor on Node ≥18 works. eslint@8is the last v8; thenext lintshim still works in Next 14.2.
6. Build / Toolchain Footprint Summary
- Source files: 25 (14 .tsx, 2 .ts, 2 .js, 1 .css, 2 .json, 4 .md), ~2,605 LOC excluding deps and lockfile (per upstream
.kanban-inventory.json). - Routes: 5 under
app/(/,/lectures,/members,/publications,/standardization). - Shared components: 7 in
components/. - Build artifacts present:
node_modules/(342 dirs) and.next/exist; lockfile andtsconfig.tsbuildinfopresent. - No test runner, no formatter, no CI, no Docker, no env vars, no analytics, no CMS, no icon lib, no motion lib. The dependency tree is the smallest viable Next 14 + React 18 + Tailwind v3 surface.
7. Stack-Profile Verdict
A deliberately minimal Next 14 App Router reference implementation: a small landing page with a hand-rolled design system encoded in tailwind.config.ts and app/globals.css. Dependencies are minimal and internally consistent; the only real-world remediation on the table is bumping next to 14.2.35 (one-line patch) to clear 21 advisories. Major-version upgrades (Next 16, React 19, Tailwind 4) are a separate planned migration, not security work.