Run npm audit; bump node version; add dep cooldown - #2508
Conversation
Run `npm audit fix` to bump ajv, colord, cross-spawn and nanoid within their existing semver ranges. Resolves the 4 vulnerabilities (2 moderate, 2 high) reported during the conda-forge build. Built assets are byte-identical. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FSeWrE1TS8vkxwQDSYYrok
Bump the sphinx-theme-builder node-version from 22.9.0 to 24.21.0 (current LTS), which brings npm from 10.8.3 to 11.19.0. Add an .npmrc setting npm's min-release-age so newly published package versions are only picked up once they are at least 7 days old. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FSeWrE1TS8vkxwQDSYYrok
|
Yeah, certainly a good start. Node 22 is technically EOL in April 2027, but getting on a newer supported LTS is a fine play. With any luck at all, once this lands/is shipped, the As this is "just" a web asset build chain, and shouldn't be compiling anything, or pulling anything other than what it needs. These can likely be in the config file (vs remembering in every invocation), but I don't know the incantations for:
One kinda needs all of these things together, with some aggressive CI checks like |
conda-forge/pydata-sphinx-theme-feedstock#74 (comment)