Skip to content

Pin patched dependency versions VuePress 1 holds back; add deps:refresh - #78

Merged
mynodebtc merged 2 commits into
masterfrom
claude/blissful-gates-71df1x
Sep 30, 2026
Merged

mynodebtc merged 2 commits into
masterfrom
claude/blissful-gates-71df1x

Conversation

@mynode-dev

@mynode-dev mynode-dev commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Follow-up to #77. That PR refreshed the lockfile within the existing version ranges. The alerts it couldn't clear have their fixes in newer major versions than VuePress 1's dependency ranges allow.

Dependabot's version updates only raise direct dependencies, so the
transitive ones in yarn.lock stayed at their original versions until
they were regenerated by hand. `yarn deps:refresh` runs `yarn upgrade`
with install scripts disabled, moving every locked version to the
newest its range allows, and then builds the site.

AGENTS.md now explains why this is needed, how to check the result
before committing it, and how to treat alerts that a refresh can't
clear under VuePress 1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VRMtfud4dZEg6cYb8guFe1
A lockfile refresh can't clear alerts whose fix is in a newer major
than VuePress 1's dependency ranges allow. Where the newer version
keeps the API its caller uses, pin it with `resolutions`:

- loader-utils 1.4 under vuepress-html-webpack-plugin (was 0.2.17,
  which also pulled in json5 0.5.1). Its loader only calls parseQuery
  and stringifyRequest, both still in 1.x.
- serialize-javascript 7, linkify-it 5, node-forge 1.4 (dev server's
  self-signed certificate helper only).
- esbuild 0.25: declared by @vuepress/core but never required.
- highlight.js 10: only reached through @types/markdown-it.
- form-data, tough-cookie and qs under request, which only the
  unused Algolia search client depends on.

npm's advisory data goes from 61 advisories to 35, and both criticals
are gone. The rest (dev server, postcss/svgo, markdown-it 8, braces,
Vue 2, ...) have no fix usable under VuePress 1; AGENTS.md lists them.

The built site is unchanged apart from the order of the page list in
app.js and the 404 page's randomly picked message. docs:dev still
starts and serves pages.

serialize-javascript 7 requires Node 20+, which CI already uses.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VRMtfud4dZEg6cYb8guFe1
@mynodebtc
mynodebtc merged commit 4f435cf into master Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants