Security: Makes sure serialize-javascript is at latest version#34034
Security: Makes sure serialize-javascript is at latest version#3403450bbx wants to merge 1 commit intostorybookjs:nextfrom
serialize-javascript is at latest version#34034Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
💤 Files with no reviewable changes (2)
📝 WalkthroughWalkthroughThis PR updates dependencies and removes a dependency resolution. Changes include upgrading Angular framework packages from version 19.x to 20.x, aligning webpack versions across multiple package configurations to ^5.105.4, updating terser-webpack-plugin, and removing the serialize-javascript resolution entry. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~5 minutes Tip Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs). Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
serialize-javascript is at latest versionserialize-javascript is at latest version
|
Hi @50bbx, Thank you for your contribution. I've converted this PR to draft as long as CI isn't green. The failure currently is that the |
What I did
Upgraded all necessary dependencies to bump
serialize-javascriptto address GHSA-5c6j-r48x-rmvq.It required to upgrade:
terser-webpack-pluginwhich usedserialize-javascriptdirectlywebpackwhich usedterser-webpack-plugin@angular/*and@angular-devkit/*which usedcopy-webpack-pluginwhich usedserialize-javascriptThe changes in this PR are covered in the following automated tests:
Manual testing
I am unable to run the
yarn startscript locally because ofnxpermission issues.Documentation
MIGRATION.MD
Checklist for Maintainers
When this PR is ready for testing, make sure to add
ci:normal,ci:mergedorci:dailyGH label to it to run a specific set of sandboxes. The particular set of sandboxes can be found incode/lib/cli-storybook/src/sandbox-templates.tsMake sure this PR contains one of the labels below:
Available labels
bug: Internal changes that fixes incorrect behavior.maintenance: User-facing maintenance tasks.dependencies: Upgrading (sometimes downgrading) dependencies.build: Internal-facing build tooling & test updates. Will not show up in release changelog.cleanup: Minor cleanup style change. Will not show up in release changelog.documentation: Documentation only changes. Will not show up in release changelog.feature request: Introducing a new feature.BREAKING CHANGE: Changes that break compatibility in some way with current major version.other: Changes that don't fit in the above categories.🦋 Canary release
This PR does not have a canary release associated. You can request a canary release of this pull request by mentioning the
@storybookjs/coreteam here.core team members can create a canary release here or locally with
gh workflow run --repo storybookjs/storybook publish.yml --field pr=<PR_NUMBER>Summary by CodeRabbit
Release Notes