Skip to content

Regenerate yarn.lock to pick up patched transitive dependencies - #77

Merged
mynode-dev merged 1 commit into
masterfrom
claude/blissful-gates-71df1x
Sep 30, 2026
Merged

mynode-dev merged 1 commit into
masterfrom
claude/blissful-gates-71df1x

Conversation

@mynode-dev

@mynode-dev mynode-dev commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Dependabot's grouped npm PRs only bump the direct dependencies in package.json. Yarn keeps the existing yarn.lock entries for everything those packages pull in, so most of the dependency tree was still at 2020-era versions. That is why the Dependabot security tab lists ~60 vulnerable packages.

This PR:

  • Regenerates yarn.lock, so every transitive dependency resolves to the newest version its declared range allows. This clears most open alerts: serialize-javascript, lodash, prismjs, express/body-parser/qs/send/serve-static/cookie, pbkdf2/cipher-base/sha.js/elliptic/browserify-sign, follow-redirects, js-yaml, minimist, json5, ws, sockjs, url-parse, loader-utils, @babel/core and @babel/traverse, browserslist, websocket-driver, min-document, form-data (not the copy under request), and others.
  • Pins toml to ^4.1.2 via resolutions. VuePress 1 asks for ^3.0.0, which has no patched release. 4.x keeps the same CommonJS parse() API that VuePress calls.

Dependabot's grouped updates bump direct dependencies, but yarn keeps
existing lockfile entries for transitive ones, so most of the tree was
still pinned at 2020-era versions. Regenerating the lockfile resolves
each dependency to the newest version its declared range allows, which
clears most of the open Dependabot alerts (serialize-javascript,
lodash, prismjs, express/body-parser/qs, pbkdf2/cipher-base/sha.js,
elliptic, follow-redirects, js-yaml, minimist, json5, ...).

Also pin toml to ^4.1.2 via resolutions. VuePress 1 asks for ^3.0.0,
which has no patched release; 4.x keeps the same CommonJS parse() API.

Built output is unchanged apart from Prism 1.30's finer bash
tokenization in code blocks and the 404 page's randomly picked
message. Meta tags are identical to the previous build.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VRMtfud4dZEg6cYb8guFe1
@mynode-dev
mynode-dev merged commit 1a5169e into master Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants