Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 29 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ yarn docs:dev # serve locally with hot reload (port 8080, or next available
yarn docs:build # build static site to docs/.vuepress/dist
yarn docs:lint # reject Markdown that VuePress would compile into executable code
yarn docs:check # render every page and check what Vue will compile against an allowlist
yarn deps:refresh # update every locked dependency within its range, then build
```

`docs:dev` and `docs:build` run through `node --openssl-legacy-provider` because the bundled VuePress 1 uses webpack 4, which is incompatible with OpenSSL 3 in newer Node releases. Don't remove that flag.
Expand Down Expand Up @@ -90,6 +91,34 @@ Install is `yarn install --frozen-lockfile --ignore-scripts`, in CI and in `depl
Those PRs only get the Markdown check, not a build, and merging deploys. Before merging
an npm update, build the branch, compare the pages' `<meta>` tags with the current
build, and look at a page in a browser.
- Dependabot's version updates only raise the packages listed in `package.json`. Yarn
keeps every other `yarn.lock` entry as long as it still satisfies its range, so the
~1,200 transitive dependencies don't move on their own and pile up security alerts.
Every few months, and whenever the alert list grows, run `yarn deps:refresh`. It
runs `yarn upgrade` (every locked version moves to the newest its range allows;
`package.json` is not touched) and then builds. Before committing the new
`yarn.lock`, compare `docs/.vuepress/dist` with a build from the old lockfile: the
same files, the same `<meta>` tags, and in the HTML only expected changes such as
code highlighting. Merge it on its own PR, since merging deploys.
- Alerts that remain after a refresh are capped by VuePress 1's own dependency ranges
(VuePress 1 is end-of-life). `resolutions` in `package.json` forces patched versions
past those ranges where the newer version keeps the API its caller uses: `toml`,
`loader-utils` (under `vuepress-html-webpack-plugin`, which also drops `json5` 0.5),
`serialize-javascript`, `linkify-it`, `node-forge`, `esbuild` (declared by
`@vuepress/core` but never loaded), `highlight.js` (types only), and `form-data`,
`tough-cookie` and `qs` under `request` (Algolia search client, unused here). A
path such as `**/request/qs` needs the `**/` prefix or yarn ignores it. Before
adding one, check the new version still loads with `require()` (several are now
ES-module-only, e.g. `decode-uri-component` 0.5) and exports the same shape
(`nth-check` 2 doesn't), then build and compare. `serialize-javascript` 7 needs
Node 20+, so `deploy.sh` does too.
- What is still flagged after that has no fix, or only one in a major version that
VuePress 1 can't use: the dev server (`webpack-dev-server`, `webpack-dev-middleware`,
`http-proxy-middleware`, `ip`, `uuid`), the CSS pipeline (`postcss` 7, `svgo` 1,
`nth-check`), `markdown-it` 8, globbing (`braces`, `micromatch`), Vue 2 itself,
`html-minifier`, `request`, `got`, `elliptic` and `decode-uri-component`. Dismiss
those in the Dependabot UI rather than forcing them. Removing them needs a move off
VuePress 1.
- `vuepress-plugin-seo` is held below 0.2.0. 0.2.0 targets VuePress 2 and on this site
silently drops all Open Graph, Twitter and verification tags while the build still
passes.
Expand Down
12 changes: 11 additions & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,13 +13,23 @@
"scripts": {
"docs:lint": "node scripts/check-markdown.js",
"docs:check": "node scripts/check-templates.js",
"deps:refresh": "yarn upgrade --ignore-scripts && yarn docs:build",
"docs:dev": "node --openssl-legacy-provider node_modules/vuepress/cli.js dev docs",
"docs:build": "node scripts/check-templates.js && node --openssl-legacy-provider node_modules/vuepress/cli.js build docs && node docs/.vuepress/plugins/canonical.js docs/.vuepress/dist https://docs.mynodebtc.com && node docs/.vuepress/plugins/structured-data.js docs/.vuepress/dist https://docs.mynodebtc.com && mkdir -p docs/.vuepress/dist/error && cp docs/.vuepress/dist/404.html docs/.vuepress/dist/error/404.html"
},
"dependencies": {
"vuepress-plugin-seo": "^0.1.4"
},
"resolutions": {
"toml": "^4.1.2"
"toml": "^4.1.2",
"**/vuepress-html-webpack-plugin/loader-utils": "^1.4.2",
"serialize-javascript": "^7.0.5",
"linkify-it": "^5.0.2",
"node-forge": "^1.4.0",
"esbuild": "^0.25.0",
"highlight.js": "^10.7.3",
"**/request/form-data": "^2.5.6",
"**/request/tough-cookie": "^4.1.3",
"**/request/qs": "^6.16.0"
}
}
Loading
Loading