Skip to content

1033 update package lock.json - #1038

Merged
jsjiang merged 7 commits into
developfrom
1033_update_package-lock.json
Aug 3, 2026
Merged

1033 update package lock.json#1038
jsjiang merged 7 commits into
developfrom
1033_update_package-lock.json

Conversation

@jsjiang

@jsjiang jsjiang commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

@sfisher Hi Scott,
The detailed change requests are listed in ticket Update package-lock.json - July 2026. Only the following packages were updated:

  • ws
  • js-yaml
  • sharp

No updated UI files were produced.

Please review and let me know if you have questons.

Thank you

Jing

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Not ready to approve

The Node version change should be pinned/compatible with lockfile engine constraints, and the PR description currently understates the scope of lockfile updates.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.

Pull request overview

Updates the Node-based UI toolkit dependencies/lockfile to address Dependabot security alerts (Issue #1033), primarily by bumping sharp and refreshing package-lock.json, along with a Node version update via .nvmrc.

Changes:

  • Bump sharp in package.json from ^0.34.5 to ^0.35.0.
  • Regenerate package-lock.json, updating sharp, js-yaml, and other resolved (transitive and range-permitted) packages.
  • Update .nvmrc from Node 18.20.8 to 24.
File summaries
File Description
package.json Updates the declared sharp devDependency range.
package-lock.json Refreshes locked dependency graph/versions (including sharp and js-yaml).
.nvmrc Updates the Node version used for UI-tooling development workflows.
Review details
  • Files reviewed: 2/3 changed files
  • Comments generated: 1
  • Review effort level: Low

We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.

Comment thread .nvmrc Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

@sfisher sfisher left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems good to update. Are you updating smaller node versions first? Just curious.

Oh. I see that copilot suggests pinning to a more specific version, so maybe 24 isn't good. I didn't quite understand why we couldn't do something like v24.14.1 instead, though? Is there a library that is incompatible with being more up to date on a 24.x.x version?

@jsjiang

jsjiang commented Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

@sfisher Hi Scott, Copilot left a comment on the node version defined in .nvmrc:

In .nvmrc:

@@ -1 +1 @@
-18.20.8
+24
.nvmrc is set to a floating major version ("24"), which can make installs non-reproducible and may be incompatible with some lockfile engine constraints (e.g., @img/sharp-win32-ia32 declares node "^20.9.0" while stylelint now requires node ">=20.19.0"). Consider pinning to an explicit Node 20.x version that satisfies current engines.

I accepted the recommendation and updated my local environment accordingly. There were no issues running gulp and gulp build following the change.

Jing

@jsjiang
jsjiang merged commit bf88b59 into develop Aug 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants