chore(deps): refresh safe transitive npm dependencies - #73857
bbasketballer75 wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Additional data for this dependency refresh: Registry/source verification:
Runtime PoC against the three installed patched branches, each under
At the time of verification, Recommendation: update every lockfile instance within its existing major ( |
Bumps: @eslint/eslintrc 3.3.5 -> 3.3.6, brace-expansion 5.0.7 -> 5.0.8, postcss 8.5.15 -> 8.5.24, js-yaml 4.1.1 -> 4.3.0. Required by Node engine constraint bump (18 || 20 || >=22) -> (20 || >=22). Lockfile-only, no source changes.
e79a4b3 to
a185ea7
Compare
|
Rebased onto current Thanks for the |
teknium1
left a comment
There was a problem hiding this comment.
Thanks for the focused lockfile-only refresh. The root brace-expansion update is still relevant: current main resolves it to 5.0.7 at package-lock.json:7788, and this PR updates that entry to 5.0.8.
Problems
- The refresh does not cover the older compatible
brace-expansionbranches described in the PR discussion. Current main still has nested1.1.16entries atpackage-lock.json:1491,:2426,:2524,:9431,:10584,:10704, and:11457, plus2.1.2entries at:1831and:11052. The PR diff modifies only the root 5.x instance.
Suggested changes
- Update those nested 1.x and 2.x lockfile entries to the maintenance backports cited in the discussion, alongside the 5.0.8 update, and re-run the stated npm verification.
Automated hermes-sweeper review.
| "integrity": "sha512-7oFy703dxfY3/NLxC1fh2SUCQ0H9rmAY+5EpDVfXjUTTs+HEwR2nYaqLv+GWcTsumwxPfiz6CzCNkwXwBUwqCA==", | ||
| "version": "5.0.8", | ||
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz", | ||
| "integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==", |
There was a problem hiding this comment.
This updates only the root 5.x copy. Please also refresh the nested 1.1.16 and 2.1.2 brace-expansion instances still present on main (for example package-lock.json:1491 and :1831), consistent with the backport coverage discussed above.
scripts/contributor_audit.py resolves Co-authored-by trailers through contributors/emails/, so a co-author with a plain (non-noreply) email and no mapping file silently drops out of the generated release notes. This PR consolidates ~30 open dependency/supply-chain PRs and credits their authors as co-authors on the merge commit. Nine of those emails had no mapping. Added via scripts/add_contributor.py, one file per email: vikyw89@gmail.com -> vikyw89 (#50902) fmy3@qq.com -> superafun (#60201) Steven.Leath@gmail.com -> Leathal1 (#69711) bbasketballer75@gmail.com -> bbasketballer75 (#69864, #73857) mudreac@gmail.com -> mudrii (#66871, #63099) agents@joinsensie.com -> Sensie-agents (#65150) dinmail@gmail.com -> sahlbergalfred4-lgtm (#70003) richard.ham@live.com -> zebadee2kk (#50052) jrcrittenden@gmail.com -> jrcrittenden (#28749) egilewski@egilewski.com, sunsky.lau@gmail.com and 1920071390@campus.ouj.ac.jp were already mapped. Every other co-author uses a GitHub id+login noreply address, which auto-resolves and needs no file. tests/scripts/test_contributor_map.py passes.
|
Superseded: brace-expansion and nanoid already landed on main, and the @eslint/eslintrc entry no longer exists there. Only postcss (8.5.19 to 8.5.24) remains — better as a fresh one-line PR. Closing. |
scripts/contributor_audit.py resolves Co-authored-by trailers through contributors/emails/, so a co-author with a plain (non-noreply) email and no mapping file silently drops out of the generated release notes. This PR consolidates ~30 open dependency/supply-chain PRs and credits their authors as co-authors on the merge commit. Nine of those emails had no mapping. Added via scripts/add_contributor.py, one file per email: vikyw89@gmail.com -> vikyw89 (NousResearch#50902) fmy3@qq.com -> superafun (NousResearch#60201) Steven.Leath@gmail.com -> Leathal1 (NousResearch#69711) bbasketballer75@gmail.com -> bbasketballer75 (NousResearch#69864, NousResearch#73857) mudreac@gmail.com -> mudrii (NousResearch#66871, NousResearch#63099) agents@joinsensie.com -> Sensie-agents (NousResearch#65150) dinmail@gmail.com -> sahlbergalfred4-lgtm (NousResearch#70003) richard.ham@live.com -> zebadee2kk (NousResearch#50052) jrcrittenden@gmail.com -> jrcrittenden (NousResearch#28749) egilewski@egilewski.com, sunsky.lau@gmail.com and 1920071390@campus.ouj.ac.jp were already mapped. Every other co-author uses a GitHub id+login noreply address, which auto-resolves and needs no file. tests/scripts/test_contributor_map.py passes.
scripts/contributor_audit.py resolves Co-authored-by trailers through contributors/emails/, so a co-author with a plain (non-noreply) email and no mapping file silently drops out of the generated release notes. This PR consolidates ~30 open dependency/supply-chain PRs and credits their authors as co-authors on the merge commit. Nine of those emails had no mapping. Added via scripts/add_contributor.py, one file per email: vikyw89@gmail.com -> vikyw89 (NousResearch#50902) fmy3@qq.com -> superafun (NousResearch#60201) Steven.Leath@gmail.com -> Leathal1 (NousResearch#69711) bbasketballer75@gmail.com -> bbasketballer75 (NousResearch#69864, NousResearch#73857) mudreac@gmail.com -> mudrii (NousResearch#66871, NousResearch#63099) agents@joinsensie.com -> Sensie-agents (NousResearch#65150) dinmail@gmail.com -> sahlbergalfred4-lgtm (NousResearch#70003) richard.ham@live.com -> zebadee2kk (NousResearch#50052) jrcrittenden@gmail.com -> jrcrittenden (NousResearch#28749) egilewski@egilewski.com, sunsky.lau@gmail.com and 1920071390@campus.ouj.ac.jp were already mapped. Every other co-author uses a GitHub id+login noreply address, which auto-resolves and needs no file. tests/scripts/test_contributor_map.py passes.
scripts/contributor_audit.py resolves Co-authored-by trailers through contributors/emails/, so a co-author with a plain (non-noreply) email and no mapping file silently drops out of the generated release notes. This PR consolidates ~30 open dependency/supply-chain PRs and credits their authors as co-authors on the merge commit. Nine of those emails had no mapping. Added via scripts/add_contributor.py, one file per email: vikyw89@gmail.com -> vikyw89 (NousResearch#50902) fmy3@qq.com -> superafun (NousResearch#60201) Steven.Leath@gmail.com -> Leathal1 (NousResearch#69711) bbasketballer75@gmail.com -> bbasketballer75 (NousResearch#69864, NousResearch#73857) mudreac@gmail.com -> mudrii (NousResearch#66871, NousResearch#63099) agents@joinsensie.com -> Sensie-agents (NousResearch#65150) dinmail@gmail.com -> sahlbergalfred4-lgtm (NousResearch#70003) richard.ham@live.com -> zebadee2kk (NousResearch#50052) jrcrittenden@gmail.com -> jrcrittenden (NousResearch#28749) egilewski@egilewski.com, sunsky.lau@gmail.com and 1920071390@campus.ouj.ac.jp were already mapped. Every other co-author uses a GitHub id+login noreply address, which auto-resolves and needs no file. tests/scripts/test_contributor_map.py passes.
Summary
Verification
npm cinpm run build --workspace webnpm run build --workspace ui-tuigit diff --check origin/main..HEADNotes
The remaining npm advisories require breaking major-version changes or upstream dependency updates and are intentionally not forced in this maintenance PR.