Skip to content

Run npm audit; bump node version; add dep cooldown - #2508

Merged
drammock merged 2 commits into
mainfrom
claude/github-comment-pr-ucpxgj
Sep 25, 2026
Merged

drammock merged 2 commits into
mainfrom
claude/github-comment-pr-ucpxgj

Conversation

@Yann-P

@Yann-P Yann-P commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator
Run `npm audit fix` to bump ajv, colord, cross-spawn and nanoid within
their existing semver ranges. Resolves the 4 vulnerabilities (2 moderate,
2 high) reported during the conda-forge build. Built assets are
byte-identical.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FSeWrE1TS8vkxwQDSYYrok
Bump the sphinx-theme-builder node-version from 22.9.0 to 24.21.0 (current
LTS), which brings npm from 10.8.3 to 11.19.0. Add an .npmrc setting npm's
min-release-age so newly published package versions are only picked up
once they are at least 7 days old.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FSeWrE1TS8vkxwQDSYYrok
@Yann-P Yann-P self-assigned this Sep 25, 2026
@Yann-P Yann-P added the kind: maintenance Improving maintainability and reducing technical debt label Sep 25, 2026
@Yann-P

Yann-P commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator Author
@Yann-P Yann-P added this to the 0.23.0 milestone Sep 25, 2026
@github-actions

Copy link
Copy Markdown

Coverage report

This PR does not seem to contain any modification to coverable code.

@bollwyvl

Copy link
Copy Markdown
Collaborator

Yeah, certainly a good start. Node 22 is technically EOL in April 2027, but getting on a newer supported LTS is a fine play.

With any luck at all, once this lands/is shipped, the conda-forge feedstock will explode due to some mismatches, which will be a nice indicator.

As this is "just" a web asset build chain, and shouldn't be compiling anything, or pulling anything other than what it needs. These can likely be in the config file (vs remembering in every invocation), but I don't know the incantations for:

  • disabling lifecycle scripts
  • avoiding optional dependencies

npm ci can further be used to do a full install without potentially changing the lockfile, likely more appropriate for inside a wheel build.

One kinda needs all of these things together, with some aggressive CI checks like npm audit, in this "modern" era.

@drammock
drammock merged commit 9cfdc3e into main Sep 25, 2026
27 checks passed
@drammock
drammock deleted the claude/github-comment-pr-ucpxgj branch September 25, 2026 15:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind: maintenance Improving maintainability and reducing technical debt

4 participants