Repository navigation
Lift tsup and tn-forms to clear 21 Dependabot alerts - #3
Merged
Merged
Conversation
All 21 alerts were dev scope, and they came from two chains. The larger one was not this repo's doing. The lockfile held @thinknimble/tn-forms 3.3.4, which declares babel-loader as a runtime dependency and so drags webpack, ajv, browserslist, serialize-javascript and terser into every install. tn-forms 3.4.0 dropped babel-loader, so moving to it removes that whole branch. The peer range still accepts 3.3.3 and later, so a consumer is free to stay on an older version. The smaller chain is tsup's own: sucrase to glob to minimatch to brace-expansion, plus esbuild. tsup 6.5.0 to 8.5.1 does not move those far enough on its own, so four pnpm overrides lift them. - @thinknimble/tn-forms: 3.3.4 to 3.4.0 - tsup: 6.5.0 to 8.5.1 - Add pnpm overrides for glob, minimatch, brace-expansion and esbuild - Add a GitHub Actions workflow, because the repo had no CI `pnpm audit` reports no known vulnerabilities. The build output holds: dist/index.js and dist/index.mjs export the same two names, FormProvider and useTnForm, and the diff against the previous build is esbuild formatting plus one internal variable rename. The type declaration changes by one line, where ConvertToFieldTuple now carries the `type` modifier.
pnpm/action-setup needs a version from either its own config or a packageManager field in package.json. Neither was present, so the job failed before it installed anything.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What This Does
Clears all 21 open Dependabot alerts. Every one was
developmentscope, and they arrived through two separate chains.The larger chain was not this repo's doing. The lockfile held
@thinknimble/tn-forms@3.3.4, which declaresbabel-loaderas a runtime dependency and therefore drags webpack, ajv, browserslist, serialize-javascript and terser into every install of this package.tn-forms@3.4.0droppedbabel-loader(along withinstall, another placeholder package), so moving the lock to 3.4.0 removes that branch entirely. That single change accounts for 16 of the 21 alerts.The smaller chain is tsup's own:
sucrase→glob→minimatch→brace-expansion, plusesbuild. Going from tsup 6.5.0 to 8.5.1 does not lift those far enough by itself, so fourpnpm.overridesfinish the job. Three of them sit comfortably inside their depender's range. The fourth does not: tsup 8.5.1 asks foresbuild ^0.27.0and the patched version is 0.28.1, so that override deliberately steps outside. It is a low-severity dev-server advisory, and this package never starts a dev server, so I verified the override by comparing build output rather than by trusting the range.The workflow file is new because this repo had no CI at all.
pnpm auditreports no known vulnerabilities.Note for reviewers
There is no test suite here, so the build output is the evidence.
dist/index.jsanddist/index.mjsexport the same two names as before,FormProvideranduseTnForm, both still functions. The rest of the diff against the previous build is newer-esbuild formatting (if (x) return;collapsed onto one line) and one internal variable rename,tn_forms_react_exportstoindex_exports. The type declaration moves by exactly one line:ConvertToFieldTuplenow carries thetypemodifier, which needs TypeScript 4.5 or later in a consumer.The decision I did not make for you:
peerDependenciesstill reads@thinknimble/tn-forms: >=3.3.3. A consumer who installs this package alongside tn-forms 3.3.4 still pulls the whole webpack tree into their own project, and their own Dependabot will say so. Raising that floor to>=3.4.0would protect them, but it narrows the supported range for everyone, so it is your call rather than mine.Two pre-existing problems I left alone.
npx tsc --noEmitreports three errors insrc/form-provider.tsxline 99 (Object.entriesneedslibat es2017 or later, and two implicitanybindings). They are identical on main before this change, which is why the new workflow runs the build and nottsc. Also,tsup8 now emitsdist/index.d.mtsnext toindex.d.ts; nothing references it, and it improves type resolution for ESM consumers.