Skip to content

build(deps): 更新 npm 依赖与 GitHub Actions,修复依赖安全漏洞 - #393

Merged
jinzhongjia merged 5 commits into
mainfrom
chore/update-deps
Oct 6, 2026
Merged

jinzhongjia merged 5 commits into
mainfrom
chore/update-deps

Conversation

@jinzhongjia

@jinzhongjia jinzhongjia commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

概述

更新 npm 依赖与 GitHub Actions,修复依赖中的两个已知安全漏洞,并让 Dependabot 同时跟踪 Actions 的版本。

本 PR 覆盖了以下 Dependabot PR 的更新内容:#385、#386、#387、#388、#389、#392。合并后 Dependabot 会自动关闭它们。

npm 依赖

包 原版本 新版本 说明
pnpm(packageManager) 11.3.0 11.28.2 11.x 最新稳定版
@types/node 26.6.1 26.6.4
marked 18.0.13 18.0.14
prettier 3.9.8 3.9.9 仓库内文件在新版本下格式检查全部通过
sharp 0.35.4 0.35.5
subset-font 2.7.0 2.9.0
shiki 4.4.3 4.5.0 PDF 高亮依赖,保持精确锁定
serialize-javascript(间接) 7.1.1 7.1.2 修复 GHSA-gfhx-hw2g-v5hg(低危)
source-map-js(间接) 1.2.1 1.2.2 修复 GHSA-68fv-2mgg-jv7q(高危)
rollup(间接) 4.63.x 4.64.0 与 #392 一致

升级后 pnpm audit 不再报告已知漏洞。

暂不升级的依赖:

  • vite-plugin-pwa 2.0.0:@vite-pwa/vitepress 1.1.0(当前最新)的 peer 依赖仍要求 ^1.2.0。
  • Vite 6.4.4:发布时间不足一小时,pnpm 默认不安装刚发布的版本,因此保持 6.4.3。之后由 Dependabot 跟进。

workbox-build 7.4.1 引入的 glob@11.1.0 已被标记为弃用,目前 workbox-build 已经是最新版本,只能等上游更新。

GitHub Actions

action 原版本 新版本
actions/checkout v3 / v5 / v6 v7
actions/setup-node v4 v7
pnpm/action-setup v4 v6
actions/upload-pages-artifact v3 v5
actions/deploy-pages v4 v5
softprops/action-gh-release v2 v3

新版本都运行在 Node 24 上,可以消除 Node 20 的弃用警告。mlugg/setup-zig 的最新版本仍是 v2,保持不变。

已逐一核对各大版本的破坏性变更,对本仓库都没有影响:

  • checkout v7 禁止在 pull_request_target 和 workflow_run 中检出 fork 的代码。本仓库的 workflow 都没有使用这两种触发方式。
  • upload-pages-artifact v4 起默认不再打包隐藏文件。VitePress 的构建产物中没有隐藏文件。
  • setup-node v5 起检测到 packageManager 时会自动启用缓存。各 workflow 已经显式设置了 cache: pnpm,行为不变。
  • 其余 action 的大版本变更只涉及运行时升级到 Node 24。

dependabot.yml 新增了 github-actions 生态,以后 Actions 的版本也会每周自动检查。

验证

项目 结果
pnpm install --frozen-lockfile 通过
pnpm check 通过
pnpm audit 无已知漏洞
pnpm build 成功,371 个文件,Service Worker 与 manifest 正常生成,产物中没有隐藏文件
pnpm pdf:sample / pnpm pdf 成功,完整版 452 页,代码高亮正常
pnpm epub 成功,57 个章节

deploy.yml 和 release.yml 只在推送到 main 或打 tag 时运行,这两个 workflow 中的 action 升级要在合并后才能实际验证。

Summary by CodeRabbit

  • Chores
    • Updated the project’s automated build, check, deployment, and release processes.
    • Added weekly checks for GitHub Actions updates.
    • Updated development tooling versions; the minimum supported Node.js version is unchanged.

- @types/node 26.6.1 -> 26.6.4
- marked 18.0.13 -> 18.0.14
- prettier 3.9.8 -> 3.9.9
- sharp 0.35.4 -> 0.35.5
- subset-font 2.7.0 -> 2.9.0
- shiki 4.4.3 -> 4.5.0(PDF 高亮依赖,保持精确锁定)

vite-plugin-pwa 2.0.0 暂不升级:@vite-pwa/vitepress 1.1.0 的 peer 依赖仍要求 ^1.2.0。
- serialize-javascript 7.1.1 -> 7.1.2(GHSA-gfhx-hw2g-v5hg,低危)
- source-map-js 1.2.1 -> 1.2.2(GHSA-68fv-2mgg-jv7q,高危)
- rollup 4.63.x -> 4.64.0

升级后 pnpm audit 不再报告已知漏洞。
- actions/checkout 统一为 v7(原 v3/v5/v6 混用)
- actions/setup-node v4 -> v7
- pnpm/action-setup v4 -> v6
- actions/upload-pages-artifact v3 -> v5
- actions/deploy-pages v4 -> v5
- softprops/action-gh-release v2 -> v3

新版本均运行在 Node 24 上,消除 Node 20 弃用警告。
mlugg/setup-zig 最新仍为 v2,保持不变。
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 1523a7cc-2956-47f8-b19b-896c188b87b9
📥 Commits

Reviewing files that changed from the base of the PR and between 00ddf31 and dfda49b.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (9)
  • .github/dependabot.yml
  • .github/workflows/autocorrect.yml
  • .github/workflows/build.yml
  • .github/workflows/check.yml
  • .github/workflows/deploy.yml
  • .github/workflows/mirror.yml
  • .github/workflows/opencode.yml
  • .github/workflows/release.yml
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The repository adds weekly Dependabot checks for GitHub Actions, updates pinned GitHub Actions across workflows, and raises pnpm and listed development dependency versions in package.json. The existing npm Dependabot configuration and Node engine requirement remain unchanged.

Changes

Repository maintenance

Layer / File(s) Summary
Dependency update configuration and package tooling
.github/dependabot.yml, package.json
Dependabot adds weekly GitHub Actions checks. package.json updates the pnpm version and listed development dependencies.
CI and utility workflow actions
.github/workflows/autocorrect.yml, .github/workflows/build.yml, .github/workflows/check.yml, .github/workflows/mirror.yml, .github/workflows/opencode.yml
These workflows update their GitHub Actions references. Existing workflow settings described in the changes remain unchanged.
Deployment and release workflow actions
.github/workflows/deploy.yml, .github/workflows/release.yml
The deployment and release workflows update their checkout, setup, artifact upload, deployment, and release action versions.

Priority: ⬆️ High

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to dfda4

No actionable merge-blocking issue is established. The deployment and release workflow updates will run on their configured push and tag events after merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the dependency and GitHub Actions updates and the security fixes described in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jinzhongjia
jinzhongjia merged commit 3ce0bce into main Oct 6, 2026
44 checks passed
@jinzhongjia
jinzhongjia deleted the chore/update-deps branch October 6, 2026 06:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant