Skip to content

build(deps-dev): refresh development dependencies and clear security alerts - #98

Merged
dionmunk merged 1 commit into
masterfrom
build/refresh-dependencies
Oct 7, 2026
Merged

dionmunk merged 1 commit into
masterfrom
build/refresh-dependencies

Conversation

@dionmunk

@dionmunk dionmunk commented Oct 7, 2026

Copy link
Copy Markdown
Owner

All 26 open Dependabot security alerts are in development dependencies (the extension's only runtime dependency is vscode-uri). This brings npm audit to 0 vulnerabilities in one change, and covers everything in the open Dependabot PRs: #80 (webpack), #88 (browserslist), #89 (js-yaml), #90 (fast-uri) and #92 (brace-expansion).

Changes

  • npm audit fix, plus npm update brace-expansion picomatch for the two it left, refresh the lockfile within the existing version ranges. This includes webpack 5.98.0 to 5.111.1, which builds the shipped bundle.
  • mocha 10 to 12 and @typescript-eslint/parser and eslint-plugin 7 to 8. These are the only way to update serialize-javascript, braces and micromatch, which they pull in.
  • typescript-eslint 8 removed its formatting rules, so .eslintrc.json uses ESLint's own semi rule instead of @typescript-eslint/semi (it was switched off only to defer to that one). Lint reports 0 warnings and 0 errors.

Testing

  • npm audit: 0 vulnerabilities.
  • npm run compile, npm run lint, npm run vscode:prepublish and npm test (29 passing, on mocha 12).
  • End to end in VS Code 1.140 on macOS with the bundle built by webpack 5.111.1: storage location (notes listed, live change, missing folder), Workspace Notes (shown, New Note, the "where should it go" question), drag and drop within and between sections, Move To, Search Notes, external changes, and typed note extensions all gave the same results as before.

Once this is merged, the Dependabot PRs above can be closed as superseded.

…alerts

All open security alerts were in development dependencies. This brings
`npm audit` to 0 vulnerabilities and covers the updates from the open
Dependabot PRs (webpack, browserslist, js-yaml, fast-uri, brace-expansion):

- npm audit fix and npm update brace-expansion picomatch refresh the lockfile
  within the existing ranges, webpack included (5.98.0 to 5.111.1)
- mocha 10 to 12 and @typescript-eslint/parser and eslint-plugin 7 to 8, the
  only way to update serialize-javascript, braces and micromatch
- typescript-eslint 8 removed its formatting rules, so .eslintrc.json uses
  ESLint's own semi rule in place of @typescript-eslint/semi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant