refactor: Bump npm from 10.9.9 to 11.20.0 - #3477
Conversation
|
🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review. Tip
Note Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect. Caution Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 4 remain after this review. 📝 WalkthroughWalkthrough
ChangesDependency Override
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Merge Risk: ⚪ Minimal · up to The dependency override has no established release-workflow blocker; the PR is mergeable after normal checks. 🚥 Pre-merge checks | ✅ 7✅ Passed checks (7 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Pull Request
Issue
Resolves the security advisories of the dependencies bundled in
npm10.9.9 for the development dependency tree (release tooling):ip-address: GHSA-mwp4-54f8-5fhr (high, fixed in 10.3.1; https://github.com/parse-community/parse-dashboard/security/dependabot/416) and GHSA-v2v4-37r5-5v8g (medium, fixed in 10.1.1; https://github.com/parse-community/parse-dashboard/security/dependabot/329)brace-expansion: GHSA-3jxr-9vmj-r5cp (high, fixed in 2.1.2; https://github.com/parse-community/parse-dashboard/security/dependabot/396)sigstore: GHSA-52v5-jr5w-gjxr (high, fixed in 4.1.1; https://github.com/parse-community/parse-dashboard/security/dependabot/388)@sigstore/core: GHSA-jfc7-64v2-mr8c (medium, fixed in 3.2.1; https://github.com/parse-community/parse-dashboard/security/dependabot/383)picomatch: GHSA-3v7f-55p6-f55p (medium, fixed in 4.0.4; https://github.com/parse-community/parse-dashboard/security/dependabot/274)postcss-selector-parser: GHSA-w9m9-85wc-3x92 (low, fixed in 7.1.3; https://github.com/parse-community/parse-dashboard/security/dependabot/438)Approach
npm10.9.9 is required asnpm ^10.5.0by@semantic-release/npm11.0.3, which is a dependency ofsemantic-release22 under@saithodev/semantic-release-backmerge4.0.1.npm10.9.9 is the latest 10.x release, and@saithodev/semantic-release-backmerge4.0.1 is its final release (the repository is archived), so the bundled dependencies can only be updated with an override.This adds a scoped override so that
npmresolves to 11.20.0 inside the@saithodev/semantic-release-backmergedependency tree only:@semantic-release/npm13.1.4 already requiresnpm ^11.6.2and usesnpm11.20.0, so both now share onenpm11.20.0 copy:node_modules/npm: 10.9.9 → 11.20.0 (the same package and bundled dependencies as the existingnpm11.20.0 copy)node_modules/@semantic-release/npm/node_modules/npm11.20.0: removed (deduplicated)@saithodev/semantic-release-backmergedoes not runnpmor load@semantic-release/npm11; it only runsgitand importssemantic-release/lib/get-git-auth-url.js.Releases will publish with
npm11.20.0. The release workflow's@semantic-release/npm13.1.4 runsnpm whoami,npm publishandnpm dist-tagthrough the rootnode_modules/.bin/npm, which currently resolves tonpm10.9.9 and after this change resolves tonpm11.20.0.Changes
^20.17.0 || >=22.9.0. Publishing a pre-release version requires an explicit--tag, and applying the defaultlatesttag requires a version above the latest published version.--ignore-scriptsalso applies toprepare.allow-scripts,allow-git/allow-file/allow-directory/allow-remote,min-release-age) and bundled dependency updates (ip-address10.5.0,brace-expansion5.0.9,sigstore4.1.1,@sigstore/core3.2.1,picomatch4.0.4,postcss-selector-parser7.1.4,tar7.5.22)Breaking Changes
None for this repository. Publishing with
npm11.20.0 matches thenpm ^11.6.2that@semantic-release/npm13.1.4 requires.@semantic-release/npmalways passes an explicit--tagtonpm publish, so thenpm11 tag requirements do not apply. The release workflow does not grantid-token: write, so publishing continues to useNPM_TOKEN.npm11.20.0 supports all Node versions in the CI matrix.Code Changes Required
None. The change is limited to an
overridesentry inpackage.jsonand the lock file.Tasks
No tasks apply; this PR only changes development dependency resolution.
Summary by CodeRabbit