Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved review comments; changes are limited to dependency remediation and a version bump.
Review effort: Lite
Findings: None
What changed in this PR
Updates vulnerable dev-only transitive dependencies and bumps the package version to 5.1.0.
Changes:
- Refreshes patched dependency versions in
yarn.lock. - Updates the package version in
package.json.
| File | Description |
|---|---|
yarn.lock |
Resolves patched transitive dependency versions. |
package.json |
Bumps the package version to 5.1.0. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🤖 Response from codex: Second-opinion review of
Codex found one wrong claim and four gaps in the first PR description. The current description fixes them:
(codex ran locally via |
Re-resolve dev-only transitive deps to patched, in-range versions: - fast-uri 3.1.2 -> 3.1.8 (6 GHSAs, via webpack/terser-webpack-plugin > ajv@8) - js-yaml 3.15.0 -> 3.15.2, 4.3.0 -> 4.3.2 (GHSA-5p4m-2wfm-xmqj, GHSA-2883-xcg3-v3hh) - brace-expansion 1.1.15 -> 1.1.21, 2.1.1 -> 2.1.7, 5.0.6 -> 5.0.12 (GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895) - browserslist 4.28.2 -> 4.29.1 (GHSA-73wf-gq98-2v4g, GHSA-c83g-rgw3-j3cx) - baseline-browser-mapping 2.10.25 -> 2.11.26 (GHSA-w5vr-8v7q-w6rv) browserslist 4.29.1 requires newer caniuse-lite, electron-to-chromium, node-releases, and update-browserslist-db. The lockfile updates them too. No package.json changes. No resolutions. No runtime dependency moves. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Raise devDependency floors in package.json to the latest in-range releases: @types/lodash, @types/semver, @typescript-eslint/*, eslint-import-resolver-typescript, eslint-plugin-unused-imports, jest, prettier, testdouble, ts-jest, ts-loader, typescript, webpack, webpack-cli. Prettier 3.9 prints short union types on one line. Reformat the two affected type aliases. No runtime dependency changes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
f8f22a7 to
5a370f0
Compare
|
🤖 Response from codex: Second review after the branch changed to 3 commits (
Claude checked the final lockfile separately. Each vulnerable package resolves to a patched version: fast-uri 3.1.8, js-yaml 3.15.2 / 4.3.2, brace-expansion 1.1.21 / 2.1.7 / 5.0.12, browserslist 4.29.1, baseline-browser-mapping 2.11.26. (codex ran locally via |
🤖 Generated from Claude
This PR closes the 15 open Dependabot alerts on
js-sdk-common(@eppo/js-client-sdk-common). It also closes 7 related alerts that Dependabot auto-dismissed butyarn auditstill reports. All vulnerable packages are dev-only transitive dependencies. The PR also raises the devDependency floors inpackage.jsonto the latest in-range releases and bumps the package version to 5.0.2.Jira: https://datadoghq.atlassian.net/browse/FFESUPPORT-991
Commits
package.jsonfloors, the lockfile, and a prettier 3.9 reformat of two type aliases.Advisories closed
¹ Dependabot auto-dismissed this alert.
yarn auditstill reported it, so this PR closes it too."First patched" is the lowest version that fixes every listed advisory for that line.
devDependency floors raised (commit 2)
@types/lodash^4.17.25,@types/semver^7.8.0,@typescript-eslint/eslint-pluginand@typescript-eslint/parser^8.70.1,eslint-import-resolver-typescript^4.4.5,eslint-plugin-unused-imports^4.4.1,jest^30.5.2,prettier^3.9.9,testdouble^3.21.0,ts-jest^29.4.14,ts-loader^9.6.2,typescript^5.9.3,webpack^5.111.1,webpack-cli^7.2.3.All are in-range (minor or patch). Major upgrades are deferred; see below.
Prettier 3.9 prints short union types on one line. Commit 2 reformats
EntryandBanditActions. The change is whitespace only.Runtime impact
dependencies(buffer,js-base64,pino,semver,spark-md5,yargs) is identical tomain: 38 lockfile entries at the same versions.tscoutput does not change. Every.jsand.d.tsfile indist/is byte-identical tomain. Only the source maps of the two reformatted files differ. The Node and React Native SDKs consume this output.dist/eppo-sdk.js(the jsdelivr build) differs because webpack moves from 5.107.2 to 5.111.1. A side-by-side run of themainbundle and the new bundle gives:How the tests/CI protect this change
Local runs use Node 24.
yarn install --frozen-lockfilepasses. The lockfile agrees withpackage.json.eslint '**/*.{ts,tsx}'passes with 0 problems.yarn typecheckpasses.yarn testpasses: 758 tests / 36 suites, the same asmain.make prepare(tsc + webpack) passes.yarn auditreports 0 advisories (main: 114 high, 11 moderate).lint-test-sdkandtypecheckon Node 20, 22, and 24.Dependabot closes the alerts when it scans
mainafter the merge.Note for reviewers: the required checks
lint-test-sdk (18),lint-test-sdk (23),typecheck (18), andtypecheck (23)stay "Expected". They are stale branch-protection entries. #327 changed the workflow matrix from Node 18/20/22/23 to 20/22/24, so these jobs never run.Deferred
Advisories: none. This PR closes all open alerts. No alert stays dismissed or auto-dismissed without a fix.
Major devDependency upgrades:
eslint-plugin-importdoes not support eslint 10, so the migration also swaps ineslint-plugin-import-x. Two new recommended rules need source edits, one of them insrc/override-validator.ts. This is a tooling migration, not a version bump, so it goes in a separate PR.ts-jest,ts-loader,ts-node, andtypescript-eslintuse. TypeScript 6 always enablesesModuleInterop. This changes the emitted JavaScript in 12dist/files, so it needs its own PR and review.🤖 Generated with Claude Code