Skip to content

docs: bump npm dependencies to address component vulnerability risks - #984

Merged
delei merged 5 commits into
apache:mainfrom
delei:npm-dependabot-0726
Aug 6, 2026
Merged

docs: bump npm dependencies to address component vulnerability risks#984
delei merged 5 commits into
apache:mainfrom
delei:npm-dependabot-0726

Conversation

@delei

@delei delei commented Aug 2, 2026

Copy link
Copy Markdown
Member

Purpose of the pull request

Update the npm dependencies of the website and handle the npm component vulnerability risks in the Dependabot alerts.

What's changed?

  • bump website dependencies.
  • update pnpm workspace configuration and pnpm-lock.yaml file.

After my local testing, I found that the css-what component cannot be upgraded directly. We need to wait for @docusaurus to submit a new version before proceeding.

Checklist

  • I have read the Contributor Guide.
  • I have written the necessary doc or comment.
  • I have added the necessary unit tests and all cases have passed.

delei and others added 5 commits August 2, 2026 13:38
Update the website package versions for local search, React, and related frontend tooling. This keeps the Docusaurus site dependencies current with recent patch and minor releases.

@bengbengbalabalabeng bengbengbalabalabeng left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@delei
delei merged commit 5384337 into apache:main Aug 6, 2026
5 checks passed
@delei
delei deleted the npm-dependabot-0726 branch August 7, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants