Conversation
Closes 119 of the 128 open Dependabot alerts, every critical except vitest: - Lockfile refresh for every fix already inside the parent's range (@babel/traverse, cipher-base, elliptic, form-data, handlebars, pbkdf2, sha.js and the rest of the toolchain; vite within 4.x). - Remove unused devDependencies bundle-phobia-cli and vite-plugin-eslint (takes got, tmp and rollup@2 with them) and the deprecated @types/classnames stub. - Bump tsx to 4.23.15 (esbuild 0.28) and lodash to ^4.18.0. - Resolutions where the fix is outside the parent's range: axios, qs and lodash (pinned exactly by @eyeseetea/d2-api / d2-ui-components), linkify-it, node-fetch, node-gettext and styled-components' postcss. Every resolution is documented in the new RESOLUTIONS.md, with what it fixes, how it was verified and when it can be dropped. vitest, vite and esbuild 0.18 need the vite 6 / vitest 3 migration; elliptic has no fix.
… lint rule testing-library/await-async-utils read the wait parameter of a local debounce(func, wait) as Testing Library's deprecated wait(), failing yarn lint and therefore the pre-push hook. Renamed to delayMs; template.js is injected as raw text, so nothing else changes.
Formatting only. The pre-push hook runs yarn prettify and rewrote these four files on every push, leaving them modified in the working tree.
npm deprecates lodash 4.18.0 as a bad release, and ^4.18.0 still admitted it. The installed version stays 4.18.1; only the direct dependency, the resolution and its RESOLUTIONS.md entry change.
BundleMonNo change in files bundle size Groups updated (1)
Final result: ✅ View report in BundleMon website ➡️ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📌 References
📝 Implementation
Triaged from the live Dependabot alerts: 128 open on
development, 39 packages, all on the rootyarn.lock, every one still matching a version in the lockfile.Four remediation types, in order of preference:
yarn.lockentry was deleted and re-resolved. No manifest change.bundle-phobia-cli,vite-plugin-eslint), and the deprecated@types/classnamesstub (classnamesships its own types).lodash(4.17.21→^4.18.1) andtsx(4.21.0→4.23.15).RESOLUTIONS.md.axios@eyeseetea/d2-api(exact1.6.4)qs@eyeseetea/d2-api(exact6.9.7),urlpolyfilllodashd2-apiandd2-ui-components(exact)linkify-itd2-ui-components → react-linkify(^2.0.3)node-fetchd2,d2-ui-components → d2-ui-core(d2;material-ui@0.20 → recompose → fbjs) →isomorphic-fetch(^1.0.1)node-gettext@dhis2/d2-i18n-extract/generate → i18next-conv@6.1.1postcssstyled-components(exact8.4.38) /vitelodash.pickvite-plugin-checker@0.6.2got,tmpbundle-phobia-cli(unused)rollupvite-plugin-eslint(unused) /viteesbuildtsx@4.21.0(~0.27.0)tsxbumpvite^4.2.0)@babel/traverse,cipher-base,form-data,handlebars,pbkdf2,sha.js,elliptic@babel/core, Node polyfills,d2-api/jsdom,@dhis2/d2-i18n-generate@adobe/css-tools,@babel/core/runtime/plugin-transform-modules-systemjs,@tootallnate/once,brace-expansion,braces,browserify-sign,browserslist,ejs,flatted,follow-redirects,js-yaml,minimatch,nanoid,path-to-regexp,picomatch,wsreact-router@5yarn why@babel/traverse,cipher-base,elliptic(GHSA-vjh7-7g9h-fjfh),form-data,handlebars,pbkdf2andsha.jswere all stale lockfile entries with the fix inside their parent's range. The one left isvitest, which needs the vite migration.axios,qsandlodashare pinned exactly by@eyeseetea/d2-api(andlodashalso by@eyeseetea/d2-ui-components), the same cause every other app in #869f1gfjj carries a resolution for. The app uses d2-api'sfetchbackend (src/types/d2-api.ts), which usesqs;axiosis the backend only for scripts withbackend: "xhr". Both backends were driven against a local server (aGETwithfieldsand repeatedfilterparams, aPOST /metadatawith a body, andapi.models.dataSets.get): the requests are byte-identical to the ones sent fromdevelopment.react-linkify/linkify-itbound to nothing on the first attempt. Yarn Classic installed it successfully and leftlinkify-it@2.2.0in place, with no warning; it needed the**/prefix. Recorded under "Rejected pins" inRESOLUTIONS.md. The pinned version was then checked through react-linkify itself: URLs,www.hosts and e-mail addresses still match, and<Linkify>renders the expected<a href>.node-gettextwas verified through the scripts that use it:yarn localize(extract-pot,msgmerge,d2-i18n-generate) produces a byte-identicali18n/en.potandsrc/locales/with 3.0.1 and with 2.1.0.styled-components/postcssreplaces a copy that never runs:styled-components@6.1.11listspostcssas a dependency but nothing in itsdist/loads it. Upgradingstyled-componentsto 6.4.0+ (the first release withoutpostcss) is the preferred fix and was tried: with 6.5.3,tscfails inIndicatorsDataSet.tsx(styled(Checkbox)no longer passes the event type toonChange), and the new styling library across 19 source files needs checking in a running app. Left as a follow-up ticket; the resolution changes nothing that executes.>= 4.5.3, < 5.0.0: 4.4.9 was below it, 4.5.14 is inside it. The same refresh closes 13 vite advisories, including GHSA-c24v-8rfc-w8vw (high). Dependabot will open an alert for it after merge. Fixed only on vite 5.4.21+.yarn auditalso reportedcross-spawn,get-func-name,diff,ajv,bn.js,micromatchandyaml, each with a fix inside its parent's range. Refreshed too.RESOLUTIONS.mdcreated (did not exist before this PR).yarn lintfailed ondevelopmentwith a false positive insrc/data/entry-form/template.js:481.testing-library/await-async-utilsread thewaitparameter of a localdebounce(func, wait)as Testing Library's deprecatedwait(). Renamed todelayMs. Without it, thepre-pushhook (yarn prettify && yarn lint && ...) blocks every push.template.jsis injected into the custom form as raw text, so the rename changes nothing else; the test suite still passes.template.css,Project.ts,SaveDataSetUseCase.tsandmetadata_old_projects_in_cc_deprecated_sqlview.jsonwere left unformatted ondevelopment, so thepre-pushhook'syarn prettifyrewrote them on every push. No behaviour change.📹 Screenshots/Screen capture
None. No UI change.
🔥 Is there anything the reviewer should know to test it?
Run on Node 18.16.1 (
nvm usefirst) / Yarn 1.22.22. Every check was run ondevelopmentfirst, and the results compared.developmentyarn install --frozen-lockfileyarn audityarn linttemplate.jsnote below)npx tsc --noEmityarn testyarn buildyarn localizeen.potandsrc/locales/byte-identicaltsxscripts (--helpon the fourpackage.jsonscripts)template.vmtemplate.vmfailure is pre-existing:tsxcannot load the?rawimport that only Vite understandsFindings that stay open, recorded in
RESOLUTIONS.md:vitest@0.32.4(GHSA-5xrq-8626-4rwp, critical),vite@4.5.14(GHSA-fx2h-pf6j-xcff and GHSA-c27g-q93r-2cwf high, 3 medium, 2 low) andesbuild@0.18.20(GHSA-67mh-4wv8-2f99, medium).vitest@0.32andvite-plugin-node-stdlib-browser@0.2.1(its latest release) both cap vite at 4, and every remaining fix is on 5.x or 6.x. One migration closes all of them. The vitest advisory needs the Vitest UI server, and@vitest/uiis not installed.elliptic@6.6.1(GHSA-848j-6mx2-7j84, low). Every published version is affected. Same accepted finding as dhis2-app-skeleton, metadata-synchronization and user-extended.✅ Notes to the tester
nvm use,yarn install --frozen-lockfile: clean, no new peer-dependency warnings.yarn lint,npx tsc --noEmit,yarn test,yarn build: all clean (lint keeps 4 pre-existing warnings).yarn why axios→ 1.20.x,yarn why qs→ 6.16.x,yarn why lodash→ a single 4.18.x,yarn why linkify-it→ 5.0.2.yarn startagainst a DHIS2 instance: log in, list projects, create and edit a project through every wizard step (setup, indicators, disaggregation, grey fields, sharing, summary) and open its custom data-entry form.📑 Others
axios,qsandlodashcan be dropped fromresolutionsonce@eyeseetea/d2-apiand@eyeseetea/d2-ui-componentsrequest patched versions natively (axios >= 1.18.0,qs >= 6.16.0,lodash >= 4.18.1; both already tracked in #869f1gfjj).