1033 update package lock.json - #1038
Conversation
Mege develop into main branch
Updates to accessibility statement
Merge Develop to main
There was a problem hiding this comment.
🟡 Not ready to approve
The Node version change should be pinned/compatible with lockfile engine constraints, and the PR description currently understates the scope of lockfile updates.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.
Pull request overview
Updates the Node-based UI toolkit dependencies/lockfile to address Dependabot security alerts (Issue #1033), primarily by bumping sharp and refreshing package-lock.json, along with a Node version update via .nvmrc.
Changes:
- Bump
sharpinpackage.jsonfrom^0.34.5to^0.35.0. - Regenerate
package-lock.json, updatingsharp,js-yaml, and other resolved (transitive and range-permitted) packages. - Update
.nvmrcfrom Node18.20.8to24.
File summaries
| File | Description |
|---|---|
| package.json | Updates the declared sharp devDependency range. |
| package-lock.json | Refreshes locked dependency graph/versions (including sharp and js-yaml). |
| .nvmrc | Updates the Node version used for UI-tooling development workflows. |
Review details
- Files reviewed: 2/3 changed files
- Comments generated: 1
- Review effort level: Low
We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Seems good to update. Are you updating smaller node versions first? Just curious.
Oh. I see that copilot suggests pinning to a more specific version, so maybe 24 isn't good. I didn't quite understand why we couldn't do something like v24.14.1 instead, though? Is there a library that is incompatible with being more up to date on a 24.x.x version?
|
@sfisher Hi Scott, Copilot left a comment on the node version defined in In .nvmrc:
I accepted the recommendation and updated my local environment accordingly. There were no issues running Jing |
@sfisher Hi Scott,
The detailed change requests are listed in ticket Update package-lock.json - July 2026. Only the following packages were updated:
No updated UI files were produced.
Please review and let me know if you have questons.
Thank you
Jing