CLDSRV-999: Drop unused and deprecated dependencies, refresh docs/test deps - #6317
Conversation
Hello francoisferrand,My role is to assist you with the merge of this Available options
Available commands
Status report is not available. |
Incorrect fix versionThe
Considering where you are trying to merge, I ignored possible hotfix versions and I expected to find:
Please check the |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files
@@ Coverage Diff @@
## development/9.5 #6317 +/- ##
===================================================
- Coverage 86.58% 86.56% -0.02%
===================================================
Files 213 213
Lines 14628 14628
===================================================
- Hits 12665 12663 -2
- Misses 1963 1965 +2
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
| '>=': '$gte', | ||
| '<=': '$lte', | ||
| LIKE: '$regex', | ||
| 'LIKE': '$regex', |
There was a problem hiding this comment.
why do you have some prettier sutff ?
There was a problem hiding this comment.
as the prettier PR was merged , I have the same question on this
There was a problem hiding this comment.
prettier PR used an outdated Guidelines PR... with the bump, some things were changed: and code needs to be changed again...
google-auto-auth, request, @aws-sdk/middleware-retry, level-mem, lolex, istanbul and istanbul-api are no longer referenced anywhere in the code or tests. Several are deprecated upstream, and their transitive trees brought in 42 of the 61 advisories reported by yarn audit. Issue: CLDSRV-999
Moves mdlint to markdownlint 0.38, which drops the vulnerable markdown-it / linkify-it chain (5 dev advisories). ESLint and markdown lint results are unchanged on the current tree. Issue: CLDSRV-999
The Sphinx lockfile was last compiled in 2018 for Python 2.7 and carried 30 Dependabot alerts (jinja2, requests, urllib3, certifi, ...). Recompile it with current pip-tools on Python 3.12 and drop recommonmark, which is deprecated and not loaded by docs/conf.py. Issue: CLDSRV-999
junit 4.11 is affected by CVE-2020-15250 (GHSA-269g-pwp5-87pp, TemporaryFolder information disclosure), fixed in 4.13.1. Issue: CLDSRV-999
Guidelines 8.3.3 switches the shared Prettier config from quoteProps 'as-needed' to 'consistent', to match the eslint quote-props 'consistent-as-needed' rule. Objects that mix keys needing quotes with plain ones now quote all keys, so reformat the affected files to keep prettier:check passing after the bump. Formatting only, no behaviour change. Issue: CLDSRV-999 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
00ce65e to
ae201f4
Compare
|
/approve |
|
I have successfully merged the changeset of this pull request
The following branches have NOT changed:
This pull request did not target the following hotfix branch(es) so they
Please check the status of the associated issue CLDSRV-999. Goodbye francoisferrand. The following options are set: approve |
First pass at cleaning up the dependencies behind our remaining CVE alerts. Each change is in its own commit so they can be reviewed (or dropped) independently.
yarn auditgoes from 61 to 19 advisories.docs/requirements.txt; osv-scanner reports nothing left.The 14 advisories still open need mocha/nyc major bumps (dev only) or new arsenal/utapi releases. Those will be handled separately.
Issue: CLDSRV-999