Pin patched dependency versions VuePress 1 holds back; add deps:refresh - #78
Merged
Merged
Conversation
Dependabot's version updates only raise direct dependencies, so the transitive ones in yarn.lock stayed at their original versions until they were regenerated by hand. `yarn deps:refresh` runs `yarn upgrade` with install scripts disabled, moving every locked version to the newest its range allows, and then builds the site. AGENTS.md now explains why this is needed, how to check the result before committing it, and how to treat alerts that a refresh can't clear under VuePress 1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VRMtfud4dZEg6cYb8guFe1
A lockfile refresh can't clear alerts whose fix is in a newer major than VuePress 1's dependency ranges allow. Where the newer version keeps the API its caller uses, pin it with `resolutions`: - loader-utils 1.4 under vuepress-html-webpack-plugin (was 0.2.17, which also pulled in json5 0.5.1). Its loader only calls parseQuery and stringifyRequest, both still in 1.x. - serialize-javascript 7, linkify-it 5, node-forge 1.4 (dev server's self-signed certificate helper only). - esbuild 0.25: declared by @vuepress/core but never required. - highlight.js 10: only reached through @types/markdown-it. - form-data, tough-cookie and qs under request, which only the unused Algolia search client depends on. npm's advisory data goes from 61 advisories to 35, and both criticals are gone. The rest (dev server, postcss/svgo, markdown-it 8, braces, Vue 2, ...) have no fix usable under VuePress 1; AGENTS.md lists them. The built site is unchanged apart from the order of the page list in app.js and the 404 page's randomly picked message. docs:dev still starts and serves pages. serialize-javascript 7 requires Node 20+, which CI already uses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VRMtfud4dZEg6cYb8guFe1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #77. That PR refreshed the lockfile within the existing version ranges. The alerts it couldn't clear have their fixes in newer major versions than VuePress 1's dependency ranges allow.