Regenerate yarn.lock to pick up patched transitive dependencies - #77
Merged
Merged
Conversation
Dependabot's grouped updates bump direct dependencies, but yarn keeps existing lockfile entries for transitive ones, so most of the tree was still pinned at 2020-era versions. Regenerating the lockfile resolves each dependency to the newest version its declared range allows, which clears most of the open Dependabot alerts (serialize-javascript, lodash, prismjs, express/body-parser/qs, pbkdf2/cipher-base/sha.js, elliptic, follow-redirects, js-yaml, minimist, json5, ...). Also pin toml to ^4.1.2 via resolutions. VuePress 1 asks for ^3.0.0, which has no patched release; 4.x keeps the same CommonJS parse() API. Built output is unchanged apart from Prism 1.30's finer bash tokenization in code blocks and the 404 page's randomly picked message. Meta tags are identical to the previous build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VRMtfud4dZEg6cYb8guFe1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Dependabot's grouped npm PRs only bump the direct dependencies in
package.json. Yarn keeps the existingyarn.lockentries for everything those packages pull in, so most of the dependency tree was still at 2020-era versions. That is why the Dependabot security tab lists ~60 vulnerable packages.This PR:
yarn.lock, so every transitive dependency resolves to the newest version its declared range allows. This clears most open alerts: serialize-javascript, lodash, prismjs, express/body-parser/qs/send/serve-static/cookie, pbkdf2/cipher-base/sha.js/elliptic/browserify-sign, follow-redirects, js-yaml, minimist, json5, ws, sockjs, url-parse, loader-utils, @babel/core and @babel/traverse, browserslist, websocket-driver, min-document, form-data (not the copy underrequest), and others.tomlto^4.1.2viaresolutions. VuePress 1 asks for^3.0.0, which has no patched release. 4.x keeps the same CommonJSparse()API that VuePress calls.