chore: remove unused npm dependencies#641
Conversation
Refreshed against latest master to cover advisories published through Jul 21. Resolves 20 of 47 npm audit findings including both critical ones. Remaining findings need breaking upgrades in the Docusaurus toolchain. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: mesutoezdil The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
✅ Deploy Preview for project-hami ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Warning Review limit reached
Next review available in: 59 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR updates the website’s npm dependency set, primarily aiming to remove unused packages from the Docusaurus-based documentation site.
Changes:
- Remove unused dependencies:
asciinema-player,react-github-btn, and devDependencygh-pages. - Add npm
overridespins for several transitive dependencies (security/compatibility-related). - Regenerate
package-lock.json, resulting in broader transitive dependency updates.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| package.json | Removes the three declared unused packages and adds an overrides section for pinned transitive deps. |
| package-lock.json | Removes the deleted packages from the lockfile and updates a large portion of the resolved dependency tree accordingly. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
9edc6d0 to
8c57ed8
Compare
Add npm overrides scoped to the parents that need them, pinned to exact versions: js-yaml, markdown-it and run-con under markdownlint-cli, serialize-javascript under copy-webpack-plugin and css-minimizer-webpack-plugin, and uuid under sockjs. Scoping keeps unrelated subtrees on their own versions. markdownlint-cli stays at 0.48.0 and run-con at 1.3.2 because their newer releases pull deps requiring Node 22 while CI runs Node 20. npm audit now reports 0 vulnerabilities. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
asciinema-player and react-github-btn are not imported anywhere in the site code. gh-pages is unused since deployment moved to Netlify. Fewer dependencies means a smaller vulnerability surface. Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
8c57ed8 to
8fcad15
Compare
Note
This PR is stacked on #556 and #630, so until those merge, the "Files changed" diff against master also shows their lockfile refresh and
overridesblock. The only change introduced by this PR itself is the removal of three dependencies; see the last commit for the isolated diff. Merge order: #556 -> #630 -> this, each becoming a trivial diff as its parent lands.What
Removes three dependencies that nothing in the repo uses:
asciinema-player(dependency): no import, no CSS reference, no MDX usage anywhere insrc,themes,docs,tutorials,blogori18nreact-github-btn(dependency): the star button is a custom component (src/components/gitHubButton.js) built on Font Awesomegh-pages(devDependency): deployment moved to Netlify (netlify.toml); thedocusaurus deployscript does not use this packageWhy
Every installed package is attack surface for the next supply-chain advisory and noise in
npm audit. These three contribute nothing to the build.Testing
npm run build:fastpasses after removalnpm auditstill reports 0 vulnerabilitiesPart of #628