Core: Fix Node 24 deprecation warning#32382
Merged
Merged
Conversation
|
View your CI Pipeline Execution ↗ for commit 88d8246
☁️ Nx Cloud last updated this comment at |
ndelangen
approved these changes
Sep 11, 2025
…ons using '--version' command and improve mock implementations for lock file detection.
ndelangen
approved these changes
Sep 11, 2025
…pe-safe by verifying that the filename is a string before comparison.
This was referenced Sep 11, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #32376
What I did
Checklist for Contributors
Testing
The changes in this PR are covered in the following automated tests:
Manual testing
This section is mandatory for all contributions. If you believe no manual test is necessary, please state so explicitly. Thanks!
Documentation
MIGRATION.MD
Checklist for Maintainers
When this PR is ready for testing, make sure to add
ci:normal,ci:mergedorci:dailyGH label to it to run a specific set of sandboxes. The particular set of sandboxes can be found incode/lib/cli-storybook/src/sandbox-templates.tsMake sure this PR contains one of the labels below:
Available labels
bug: Internal changes that fixes incorrect behavior.maintenance: User-facing maintenance tasks.dependencies: Upgrading (sometimes downgrading) dependencies.build: Internal-facing build tooling & test updates. Will not show up in release changelog.cleanup: Minor cleanup style change. Will not show up in release changelog.documentation: Documentation only changes. Will not show up in release changelog.feature request: Introducing a new feature.BREAKING CHANGE: Changes that break compatibility in some way with current major version.other: Changes that don't fit in the above categories.🦋 Canary release
This PR does not have a canary release associated. You can request a canary release of this pull request by mentioning the
@storybookjs/coreteam here.core team members can create a canary release here or locally with
gh workflow run --repo storybookjs/storybook canary-release-pr.yml --field pr=<PR_NUMBER>Greptile Summary
Updated On: 2025-09-11 11:45:39 UTC
This PR addresses Node 24 deprecation warnings (DEP0190) that occur when using
spawnSyncandspawnwithshell: trueand separate command arguments. The warning flags this pattern as a security vulnerability since arguments are not properly escaped when concatenated.The fix applies two different approaches across the codebase:
Single command string approach: In
upgrade.tsandpostinstall.ts, commands like['npm', 'ls']are consolidated into single strings like'npm ls'when usingshell: true.Array arguments without shell approach: In
JsPackageManagerFactory.ts, the code switches from using shell commands as strings to using command arrays without theshell: trueoption.The changes primarily affect package manager detection and command execution across Storybook's build and setup processes. These are internal operations that run during Storybook initialization, CLI commands, and addon installation. The corresponding test files are updated to match the new command patterns, ensuring mock expectations align with the actual implementation.
Additionally, a
--trace-deprecationflag is added to the storybook:ui npm script to help developers identify similar issues during development.Confidence score: 4/5
JsPackageManagerFactory.tsto ensure package manager detection still works reliably across different environments