Skip to content

chore(deps): fix vulnerable dependencies - #16

Merged
wangrongding merged 1 commit into
mainfrom
chore/security-deps
Sep 27, 2026
Merged

wangrongding merged 1 commit into
mainfrom
chore/security-deps

Conversation

@wangrongding

Copy link
Copy Markdown
Owner

概述

清理 Dependabot 安全告警:对 lockfile 范围内的传递依赖做最小化刷新(pnpm -r update,全部保持同一主版本,无 --latest 大版本扫荡),未触碰任何业务代码。

改动内容

  • 根目录:@changesets/cli、@commitlint/*、commitizen、concurrently、eslint、lint-staged、prettier、wait-on 等范围内小版本刷新
  • packages/core:rollup 插件链、hls.js、tslib、typescript 等范围内刷新;rollup-plugin-typescript2 ^0.34.1 → ^0.37.0(见下方说明)
  • packages/doc:vite ^4.5.3 → ^4.5.14、postcss、sass、element-plus、tailwindcss 等范围内刷新
  • cz-customizable 精确钉在 7.0.0:保留仓库自带的 patches/cz-customizable@7.0.0.patch(范围内最新 7.5.4 会导致 patch 失配)
  • 重点修复来源:
    • axios 0.27.2(来自 wait-on ^7.0.1)→ wait-on 7.2.0 + axios 1.20.0
    • shell-quote CRITICAL(来自 concurrently)→ concurrently 8.2.2 + shell-quote 1.10.0
    • tar / js-yaml / minimatch / nanoid / brace-expansion / browserslist / form-data / immutable / lodash 等随范围内刷新一并清除

rollup-plugin-typescript2 ^0.34.1 → ^0.37.0 的原因

0.34/0.36 配 @rollup/pluginutils 5.x 时,默认 include 模式 *.ts+(|x) 不再被 picomatch 匹配(extglob 行为变化),导致 rpt2 完全不做 TS 转换、rollup -c 直接报 Unexpected token。0.37.0 上游已修复(模式改为 *.ts{,x} 并将 pluginutils 依赖回退到 ^4.1.2)。已实测:升级前构建失败,升级后构建通过。

audit 前后对比(pnpm audit,官方 registry)

  • 前:142 条(critical 3 / high 72 / moderate 56 / low 11)
  • 后:14 条(critical 0 / high 5 / moderate 6 / low 3)

残留告警及原因(14 条,均需大版本升级或上游无修复,超出本次最小化范围)

包 条数 原因
vite 7 现为 4.5.14(^4 范围内最新);剩余告警需 vite ≥5.4.9/6.x,而 vitepress 1.0.0-beta.1 锁定 peer vite: ^4.0.0,需连升 vitepress + vue,属大版本升级
esbuild 1 随 vite 4 捆绑(esbuild 0.18.20),修复需 esbuild ≥0.25(即 vite 5+)
tmp 2 inquirer 6.5.2 → external-editor 3.1.0 锁定 tmp ^0.0.33,需替换 commit 工具链
micromatch / yaml 各 1 lint-staged 13.3.0 锁定精确版本 micromatch: 4.0.5、yaml: 2.3.1,修复需 lint-staged 14/15 大版本
serialize-javascript 1 rollup-plugin-terser 7.0.2(已停止维护)锁定 ^4.0.0,修复版需 ≥7.0.3
html-minifier 1 上游无任何修复版本(advisory patched: <0.0.0),rollup-plugin-ejs 的可选 peer

验证

  • pnpm install 成功(--ignore-scripts:node-sass 9.0.0 的 postinstall 无法在 Node ≥22 编译,基线 main 同样如此;rollup-plugin-ejs 已不依赖它参与构建)
  • pnpm -F tiny-player build(rollup)通过:created dist/index.js, dist/index.min.js, dist/index.umd.js, dist/index.iife.js(Node 22.23.3 与 Node 26.8.1 均验证通过)
  • pnpm -F doc build(vitepress)通过:build complete in 6.5s(存在 element-plus 期望 vue ^3.5 而实际 3.3.2 的非致命 SSR 警告)
  • 基线对比:原始 main 在本机构建失败(node-sass "Unsupported runtime"),与本次更新无关

Refresh in-range deps via pnpm -r update (no major bumps):
wait-on 7.2.0 (axios 0.27.2 -> 1.20.0), concurrently 8.2.2
(shell-quote critical cleared), vite 4.5.14, and other
transitive security refreshes. cz-customizable pinned to 7.0.0
to keep the repo patch applying.

Also bump rollup-plugin-typescript2 ^0.34.1 -> ^0.37.0: 0.34/0.36
with @rollup/pluginutils 5.x silently skip TS transform (broken
extglob include patterns), breaking `rollup -c`. 0.37.0 fixes it
upstream; build verified on Node 22 and 26.

pnpm audit: 142 -> 14 (critical 3 -> 0). Remaining 14 require
major upgrades (vitepress/vite 5+, lint-staged 14+) or have no
upstream fix; documented in PR body.
Copilot AI lite review requested due to automatic review settings September 27, 2026 12:22
@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
tiny-player Building Building Preview Sep 27, 2026 12:22pm UTC

@wangrongding
wangrongding merged commit abb07e6 into main Sep 27, 2026
2 of 3 checks passed
@wangrongding
wangrongding deleted the chore/security-deps branch September 27, 2026 12:22

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Resolve Node.js engine incompatibilities and the Vue, Element Plus, and VueUse dependency mismatch.

Review effort: Lite
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

This pull request refreshes workspace dependencies to address security advisories while preserving major-version constraints.

Changes:

  • Updates root tooling and commit dependencies.
  • Refreshes core Rollup, TypeScript, and HLS dependencies.
  • Updates documentation build and UI dependencies.
File Description
packages/​doc/​package.json Updates documentation tooling and UI dependencies.
packages/​core/​package.json Refreshes the player build toolchain.
package.json Updates root development and commit tooling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/doc/package.json
},
"dependencies": {
"element-plus": "^2.7.2",
"element-plus": "^2.14.6",
Comment thread package.json
"@changesets/cli": "^2.31.1",
"@commitlint/cli": "^17.8.1",
"@commitlint/config-conventional": "^17.8.1",
"commitizen": "^4.3.2",
Comment thread packages/doc/package.json
"tailwindcss": "^3.4.3",
"autoprefixer": "^10.6.1",
"postcss": "^8.5.28",
"sass": "^1.105.0",

This branch was successfully deployed

1 active deployment
Preview — 5c61f8fb Deployed Sep 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants