chore(deps): fix vulnerable dependencies - #16
Merged
Merged
Conversation
Refresh in-range deps via pnpm -r update (no major bumps): wait-on 7.2.0 (axios 0.27.2 -> 1.20.0), concurrently 8.2.2 (shell-quote critical cleared), vite 4.5.14, and other transitive security refreshes. cz-customizable pinned to 7.0.0 to keep the repo patch applying. Also bump rollup-plugin-typescript2 ^0.34.1 -> ^0.37.0: 0.34/0.36 with @rollup/pluginutils 5.x silently skip TS transform (broken extglob include patterns), breaking `rollup -c`. 0.37.0 fixes it upstream; build verified on Node 22 and 26. pnpm audit: 142 -> 14 (critical 3 -> 0). Remaining 14 require major upgrades (vitepress/vite 5+, lint-staged 14+) or have no upstream fix; documented in PR body.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Resolve Node.js engine incompatibilities and the Vue, Element Plus, and VueUse dependency mismatch.
Review effort: Lite
Findings: 1
Open (3)
What changed in this PR
This pull request refreshes workspace dependencies to address security advisories while preserving major-version constraints.
Changes:
- Updates root tooling and commit dependencies.
- Refreshes core Rollup, TypeScript, and HLS dependencies.
- Updates documentation build and UI dependencies.
| File | Description |
|---|---|
packages/doc/package.json |
Updates documentation tooling and UI dependencies. |
packages/core/package.json |
Refreshes the player build toolchain. |
package.json |
Updates root development and commit tooling. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| }, | ||
| "dependencies": { | ||
| "element-plus": "^2.7.2", | ||
| "element-plus": "^2.14.6", |
| "@changesets/cli": "^2.31.1", | ||
| "@commitlint/cli": "^17.8.1", | ||
| "@commitlint/config-conventional": "^17.8.1", | ||
| "commitizen": "^4.3.2", |
| "tailwindcss": "^3.4.3", | ||
| "autoprefixer": "^10.6.1", | ||
| "postcss": "^8.5.28", | ||
| "sass": "^1.105.0", |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


概述
清理 Dependabot 安全告警:对 lockfile 范围内的传递依赖做最小化刷新(
pnpm -r update,全部保持同一主版本,无--latest大版本扫荡),未触碰任何业务代码。改动内容
@changesets/cli、@commitlint/*、commitizen、concurrently、eslint、lint-staged、prettier、wait-on等范围内小版本刷新hls.js、tslib、typescript等范围内刷新;rollup-plugin-typescript2^0.34.1 → ^0.37.0(见下方说明)vite^4.5.3 → ^4.5.14、postcss、sass、element-plus、tailwindcss等范围内刷新cz-customizable精确钉在 7.0.0:保留仓库自带的patches/cz-customizable@7.0.0.patch(范围内最新 7.5.4 会导致 patch 失配)rollup-plugin-typescript2 ^0.34.1 → ^0.37.0 的原因
0.34/0.36 配
@rollup/pluginutils5.x 时,默认 include 模式*.ts+(|x)不再被 picomatch 匹配(extglob 行为变化),导致 rpt2 完全不做 TS 转换、rollup -c直接报Unexpected token。0.37.0 上游已修复(模式改为*.ts{,x}并将 pluginutils 依赖回退到 ^4.1.2)。已实测:升级前构建失败,升级后构建通过。audit 前后对比(pnpm audit,官方 registry)
残留告警及原因(14 条,均需大版本升级或上游无修复,超出本次最小化范围)
vite: ^4.0.0,需连升 vitepress + vue,属大版本升级tmp ^0.0.33,需替换 commit 工具链micromatch: 4.0.5、yaml: 2.3.1,修复需 lint-staged 14/15 大版本^4.0.0,修复版需 ≥7.0.3验证
pnpm install成功(--ignore-scripts:node-sass 9.0.0 的 postinstall 无法在 Node ≥22 编译,基线 main 同样如此;rollup-plugin-ejs 已不依赖它参与构建)pnpm -F tiny-player build(rollup)通过:created dist/index.js, dist/index.min.js, dist/index.umd.js, dist/index.iife.js(Node 22.23.3 与 Node 26.8.1 均验证通过)pnpm -F doc build(vitepress)通过:build complete in 6.5s(存在 element-plus 期望 vue ^3.5 而实际 3.3.2 的非致命 SSR 警告)