Skip to content

CLDSRV-999: Drop unused and deprecated dependencies, refresh docs/test deps - #6317

Merged
bert-e merged 5 commits into
development/9.5from
improvement/CLDSRV-999
Oct 1, 2026
Merged

bert-e merged 5 commits into
development/9.5from
improvement/CLDSRV-999

Conversation

@francoisferrand

Copy link
Copy Markdown
Contributor

First pass at cleaning up the dependencies behind our remaining CVE alerts. Each change is in its own commit so they can be reviewed (or dropped) independently.

  • Remove unused dependencies: google-auto-auth, request, @aws-sdk/middleware-retry, level-mem, lolex, istanbul, istanbul-api. None of them is required anywhere, including by nested or peer dependencies. yarn audit goes from 61 to 19 advisories.
  • Bump Guidelines to 8.3.3: 19 → 14 advisories.
  • Refresh Python docs requirements: Sphinx >= 7 on Python 3.12, recompiled with hashes; tox.ini updated to match. This clears the ~30 Dependabot alerts on docs/requirements.txt; osv-scanner reports nothing left.
  • Bump junit in jaws functional tests (4.11 → 4.13.2) for CVE-2020-15250. Not built locally since no JDK was available, but 4.13 keeps the same API and jaws isn't run in CI.

The 14 advisories still open need mocha/nyc major bumps (dev only) or new arsenal/utapi releases. Those will be handled separately.

Issue: CLDSRV-999

@bert-e

bert-e commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Hello francoisferrand,

My role is to assist you with the merge of this
pull request. Please type @bert-e help to get information
on this process, or consult the user documentation.

Available options
name description privileged authored
/after_pull_request Wait for the given pull request id to be merged before continuing with the current one.
/bypass_author_approval Bypass the pull request author's approval ⭐
/bypass_build_status Bypass the build and test status ⭐
/bypass_commit_size Bypass the check on the size of the changeset TBA ⭐
/bypass_incompatible_branch Bypass the check on the source branch prefix ⭐
/bypass_jira_check Bypass the Jira issue check ⭐
/bypass_peer_approval Bypass the pull request peers' approval ⭐
/bypass_leader_approval Bypass the pull request leaders' approval ⭐
/bypass_source_branch_lineage Bypass the cross-branch contamination check ⭐
/approve Instruct Bert-E that the author has approved the pull request. ✍️
/create_pull_requests Allow the creation of integration pull requests.
/create_integration_branches Allow the creation of integration branches.
/no_octopus Prevent Wall-E from doing any octopus merge and use multiple consecutive merge instead
/unanimity Change review acceptance criteria from one reviewer at least to all reviewers
/wait Instruct Bert-E not to run until further notice.
Available commands
name description privileged
/help Print Bert-E's manual in the pull request.
/status Print Bert-E's current status in the pull request.
/clear Remove all comments from Bert-E from the history TBA
/retry Re-start a fresh build TBA
/build Re-start a fresh build TBA
/force_reset Delete integration branches & pull requests, and restart merge process from the beginning.
/reset Try to remove integration branches unless there are commits on them which do not appear on the source branch.

Status report is not available.

@bert-e

bert-e commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Incorrect fix version

The Fix Version/s in issue CLDSRV-999 contains:

  • None

Considering where you are trying to merge, I ignored possible hotfix versions and I expected to find:

  • 9.5.0

Please check the Fix Version/s of CLDSRV-999, or the target
branch of this pull request.

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.56%. Comparing base (23a5fc9) to head (ae201f4).
⚠️ Report is 5 commits behind head on development/9.5.
✅ All tests successful. No failed tests found.

Additional details and impacted files

Impacted file tree graph

Files with missing lines Coverage Δ
lib/api/apiUtils/bucket/parseWhere.js 70.00% <ø> (ø)
lib/api/apiUtils/object/corsResponse.js 100.00% <ø> (ø)
lib/api/apiUtils/object/objectLockHelpers.js 81.73% <ø> (ø)
lib/api/objectPutPart.js 89.71% <ø> (-0.94%) ⬇️
lib/routes/veeam/schemas/system.js 100.00% <ø> (ø)
lib/services.js 88.23% <ø> (ø)
lib/utilities/aclUtils.js 84.04% <ø> (ø)
@@                 Coverage Diff                 @@
##           development/9.5    #6317      +/-   ##
===================================================
- Coverage            86.58%   86.56%   -0.02%     
===================================================
  Files                  213      213              
  Lines                14628    14628              
===================================================
- Hits                 12665    12663       -2     
- Misses                1963     1965       +2     
Flag Coverage Δ
checksums-disabled-tests 35.34% <ø> (ø)
file-ft-tests 69.92% <ø> (ø)
file-ft-tests-null-compat 70.54% <ø> (-0.03%) ⬇️
kmip-ft-tests 28.13% <ø> (ø)
mongo-v0-ft-tests 71.32% <ø> (-0.02%) ⬇️
mongo-v1-ft-tests 71.31% <ø> (+0.06%) ⬆️
multiple-backend 36.12% <ø> (ø)
s3c-ft-tests-v0 64.95% <ø> (ø)
s3c-ft-tests-v0-null-compat 65.01% <ø> (-0.02%) ⬇️
s3c-ft-tests-v1 64.93% <ø> (-0.02%) ⬇️
sur-tests 36.75% <ø> (ø)
sur-tests-inflights 39.55% <ø> (ø)
unit 74.33% <ø> (ø)
utapi-v2-tests 35.32% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

'>=': '$gte',
'<=': '$lte',
LIKE: '$regex',
'LIKE': '$regex',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why do you have some prettier sutff ?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as the prettier PR was merged , I have the same question on this

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

prettier PR used an outdated Guidelines PR... with the bump, some things were changed: and code needs to be changed again...

francoisferrand and others added 5 commits October 1, 2026 23:07
google-auto-auth, request, @aws-sdk/middleware-retry, level-mem, lolex,
istanbul and istanbul-api are no longer referenced anywhere in the code
or tests. Several are deprecated upstream, and their transitive trees
brought in 42 of the 61 advisories reported by yarn audit.

Issue: CLDSRV-999
Moves mdlint to markdownlint 0.38, which drops the vulnerable
markdown-it / linkify-it chain (5 dev advisories). ESLint and markdown
lint results are unchanged on the current tree.

Issue: CLDSRV-999
The Sphinx lockfile was last compiled in 2018 for Python 2.7 and carried
30 Dependabot alerts (jinja2, requests, urllib3, certifi, ...). Recompile
it with current pip-tools on Python 3.12 and drop recommonmark, which is
deprecated and not loaded by docs/conf.py.

Issue: CLDSRV-999
junit 4.11 is affected by CVE-2020-15250 (GHSA-269g-pwp5-87pp, TemporaryFolder
information disclosure), fixed in 4.13.1.

Issue: CLDSRV-999
Guidelines 8.3.3 switches the shared Prettier config from
quoteProps 'as-needed' to 'consistent', to match the eslint
quote-props 'consistent-as-needed' rule. Objects that mix keys needing
quotes with plain ones now quote all keys, so reformat the affected
files to keep prettier:check passing after the bump.

Formatting only, no behaviour change.

Issue: CLDSRV-999

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@francoisferrand

Copy link
Copy Markdown
Contributor Author

/approve

@scality scality deleted a comment from bert-e Oct 1, 2026
@bert-e

bert-e commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

I have successfully merged the changeset of this pull request
into targetted development branches:

  • ✔️ development/9.5

The following branches have NOT changed:

  • development/7.10
  • development/7.4
  • development/7.70
  • development/8.8
  • development/9.0
  • development/9.1
  • development/9.2
  • development/9.3
  • development/9.4

This pull request did not target the following hotfix branch(es) so they
were left untouched:

  • hotfix/7.4.9
  • hotfix/9.3.13
  • hotfix/7.4.4
  • hotfix/7.4.8
  • hotfix/7.70.51
  • hotfix/7.70.21
  • hotfix/7.70.11
  • hotfix/7.4.10
  • hotfix/7.4.3
  • hotfix/7.6.0
  • hotfix/9.0.7
  • hotfix/7.10.3
  • hotfix/7.10.1
  • hotfix/7.10.27
  • hotfix/7.10.4
  • hotfix/7.10.28
  • hotfix/7.9.0
  • hotfix/7.10.15
  • hotfix/7.2.0
  • hotfix/7.4.6
  • hotfix/7.8.0
  • hotfix/7.10.0
  • hotfix/7.10.30
  • hotfix/7.10.49
  • hotfix/7.4.1
  • hotfix/7.4.5
  • hotfix/7.70.45
  • hotfix/9.2.24
  • hotfix/6.4.7
  • hotfix/8.8.45
  • hotfix/7.10.8
  • hotfix/7.4.2
  • hotfix/9.2.36
  • hotfix/9.0.32
  • hotfix/7.7.0
  • hotfix/7.70.73
  • hotfix/7.4.0
  • hotfix/7.4.7
  • hotfix/7.10.2

Please check the status of the associated issue CLDSRV-999.

Goodbye francoisferrand.

The following options are set: approve

@bert-e
bert-e merged commit ae201f4 into development/9.5 Oct 1, 2026
37 checks passed
@bert-e
bert-e deleted the improvement/CLDSRV-999 branch October 1, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants