chore: resolve all lockfile packages from the official npm registry#643
chore: resolve all lockfile packages from the official npm registry#643mesutoezdil wants to merge 5 commits into
Conversation
Refreshed against latest master to cover advisories published through Jul 21. Resolves 20 of 47 npm audit findings including both critical ones. Remaining findings need breaking upgrades in the Docusaurus toolchain. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: mesutoezdil The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
✅ Deploy Preview for project-hami ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Warning Review limit reached
Next review available in: 59 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
📝 WalkthroughWalkthrough
ChangesDependency manifest
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR updates the npm dependency lockfile to eliminate third‑party mirror tarball URLs, ensuring installs fetch packages from the official npm registry and reducing supply-chain/availability risk.
Changes:
- Rewrites
package-lock.jsonresolvedtarball URLs tohttps://registry.npmjs.org/...(no remainingnpmmirrorreferences found). - Removes unused dependencies (
asciinema-player,react-github-btn,gh-pages) frompackage.json. - Adds npm
overridespins inpackage.jsonfor specific transitive packages (e.g.,js-yaml,markdown-it,serialize-javascript,uuid,run-con).
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| package-lock.json | Normalizes all resolved tarball URLs to the official registry.npmjs.org host. |
| package.json | Drops unused deps and adds overrides to pin vulnerable / compatibility-sensitive transitive versions. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
🧹 Nitpick comments (1)
package.json (1)
67-72: 🗄️ Data Integrity & Integration | 🔵 Trivial | ⚡ Quick winScope the overrides that only affect
markdownlint-cli.
markdown-itandrun-cononly appear undermarkdownlint-cli, so they can be nested there instead of applying globally.js-yaml,serialize-javascript, anduuidare shared by multiple consumers, so keeping those root-level is still reasonable.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@package.json` around lines 67 - 72, Update the package.json overrides so markdown-it and run-con are nested under the markdownlint-cli-specific override scope rather than applied globally; keep js-yaml, serialize-javascript, and uuid at the root level.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@package.json`:
- Around line 67-72: Update the package.json overrides so markdown-it and
run-con are nested under the markdownlint-cli-specific override scope rather
than applied globally; keep js-yaml, serialize-javascript, and uuid at the root
level.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 3c63c95b-2cf6-4485-97e1-28037956e1c0
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (1)
package.json
a0a8dc7 to
7351f4d
Compare
Add npm overrides scoped to the parents that need them, pinned to exact versions: js-yaml, markdown-it and run-con under markdownlint-cli, serialize-javascript under copy-webpack-plugin and css-minimizer-webpack-plugin, and uuid under sockjs. Scoping keeps unrelated subtrees on their own versions. markdownlint-cli stays at 0.48.0 and run-con at 1.3.2 because their newer releases pull deps requiring Node 22 while CI runs Node 20. npm audit now reports 0 vulnerabilities. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
asciinema-player and react-github-btn are not imported anywhere in the site code. gh-pages is unused since deployment moved to Netlify. Fewer dependencies means a smaller vulnerability surface. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
502 entries pointed at registry.npmmirror.com, a third party mirror, so every install fetched tarballs from it. Rewritten to registry.npmjs.org and verified with a clean npm ci, which checks every integrity hash against the official tarballs. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
7351f4d to
4f42432
Compare
Note
Stacked on #556 -> #630 -> #641; until those merge, their changes appear in this diff too. The change specific to this PR is the registry URL rewrite in
package-lock.json(last commit).What
Rewrites 502
resolvedURLs inpackage-lock.jsonfromregistry.npmmirror.com(a third party mirror) to the officialregistry.npmjs.org.Why
With mirror URLs in the lockfile, every
npm cion CI, Netlify and contributor machines downloads tarballs from a third party host. That adds an unnecessary party to the supply chain and a single foreign point of failure for all builds. The integrity hashes stayed unchanged, so this swaps only the download source, not any package content.Noticed while reviewing #632, where fresh lockfile entries kept inheriting the mirror URLs.
Testing
rm -rf node_modules && npm cisucceeds, meaning every package downloaded from the official registry matches the existing sha512 integrity hashnpm run build:fastpassesnpmmirrorreferences remain in the lockfilePart of #628
Summary by CodeRabbit