Repository navigation
[SDK-766] Upgrade dev toolchain to clear Dependabot alerts - #42
Open
devtools-agent[bot] wants to merge 1 commit into
Open
devtools-agent[bot] wants to merge 1 commit into
devtools-agent[bot] wants to merge 1 commit into
Conversation
Clears all 11 open Dependabot alerts, all of which came from transitive dependencies of the old dev toolchain (eslint 6, mocha 7, nyc 15): - eslint ^6.8 -> ^8.57.1 (drops tmp, flatted, js-yaml 3/argparse 1/sprintf-js) - mocha ^7.2 -> ^11.8 (drops the pinned js-yaml 3.13.1 and minimatch 3.0.4) - nyc -> c8 ^10.1.3 (every nyc release still pulls js-yaml 3 -> sprintf-js, which has no patched version, and uuid 8). Thresholds move from .nycrc.yml to .c8rc.json. - Scoped overrides for mocha's serialize-javascript (^7.0.5) and diff (^8.0.3) so mocha 11 doesn't introduce new advisories. - Use function() for the three test callbacks that call this.timeout(); as arrow functions, `this` was the suite, which mocha 11 rejects. Runtime dependencies are unchanged; Node 18 stays supported in CI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AI Agent Review (openai, openai-astra)Review: nyc to c8, eslint 6 to 8, mocha 7 to 11I found no problems in the changed lines. Lint, tests and coverage were not run here, and nothing in the diff shows they pass under the new toolchain. What I checked:
Notes outside the findings:
|
brianr
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves Linear ticket SDK-766. This clears all 11 open Dependabot alerts on this repo in a single PR.
Why
All 11 alerts are npm, dev-only, and transitive. They come from three outdated dev tools:
tmp(#45, #67),flatted(#52),sprintf-js(#104), the last via js-yaml 3 → argparse 1js-yaml3.13.1 (#46, #75, #80, #86, #88) andminimatch3.0.4 (#50)uuid8 (#66), plussprintf-jsagain via@istanbuljs/load-nyc-config→ js-yaml 3sprintf-js(#104) has no patched version, so the only fix is to remove it from the tree. That means moving off eslint ≤7 and off nyc altogether: every nyc release, including the latest, still pulls in js-yaml 3.What changed
eslint^6.8 → ^8.57.1. The existing.eslintrcworks unchanged.mocha^7.2 → ^11.8. Its engines field allows Node ^18.18.nycreplaced byc8^10.1.3. Thetestscript swapsnycforc8. c8 doesn't read YAML config, so the same 90/80/80/90 thresholds move from.nycrc.ymlto.c8rc.json. c8 has nowatermarksoption, so those report-colouring settings are dropped..nyc_outputis removed from.gitignore.overridesinpackage.json:mocha > serialize-javascript ^7.0.5andmocha > diff ^8.0.3. Without them, mocha 11 brings inserialize-javascript6.0.2 (high and moderate advisories) anddiff7, which would raise new alerts as soon as this merges.test/deploy.test.jsandtest/sourcemaps.test.js: threedone => {test callbacks becomefunction(done) {. They callthis.timeout(5000), and inside an arrow functionthisis the suite rather than the test. Mocha 7 ignored that; mocha 11 leaves a stray timer andnpm testexits non-zero.There are no runtime dependency changes. The production entries in
package-lock.jsonkeep the same versions; three are only hoisted.versionis not bumped, per AGENTS.md.Validation
npm ci:npm auditreports 0 vulnerabilities,npm run lintpasses,npm testgives 47 passing and 1 pending (the existingit.skip), with coverage at 97.04 / 92.35 / 98.07 / 97.04 (statements / branches / functions / lines).npm install(same steps as CI): lint passes and gives the same 47 passing, 1 pending, and same coverage. There are two dev-onlyEBADENGINEwarnings:serialize-javascript@7(only loaded in mocha's--parallelmode, which isn't used here) andbrace-expansion@5(via c8 → test-exclude → minimatch 10, which ran fine on 18).--lines 99makes it exit 1.Caveats
🤖 Generated with Claude Code