Repository navigation
build(deps): 更新 npm 依赖与 GitHub Actions,修复依赖安全漏洞 - #393
Conversation
- @types/node 26.6.1 -> 26.6.4 - marked 18.0.13 -> 18.0.14 - prettier 3.9.8 -> 3.9.9 - sharp 0.35.4 -> 0.35.5 - subset-font 2.7.0 -> 2.9.0 - shiki 4.4.3 -> 4.5.0(PDF 高亮依赖,保持精确锁定) vite-plugin-pwa 2.0.0 暂不升级:@vite-pwa/vitepress 1.1.0 的 peer 依赖仍要求 ^1.2.0。
- serialize-javascript 7.1.1 -> 7.1.2(GHSA-gfhx-hw2g-v5hg,低危) - source-map-js 1.2.1 -> 1.2.2(GHSA-68fv-2mgg-jv7q,高危) - rollup 4.63.x -> 4.64.0 升级后 pnpm audit 不再报告已知漏洞。
- actions/checkout 统一为 v7(原 v3/v5/v6 混用) - actions/setup-node v4 -> v7 - pnpm/action-setup v4 -> v6 - actions/upload-pages-artifact v3 -> v5 - actions/deploy-pages v4 -> v5 - softprops/action-gh-release v2 -> v3 新版本均运行在 Node 24 上,消除 Node 20 弃用警告。 mlugg/setup-zig 最新仍为 v2,保持不变。
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe repository adds weekly Dependabot checks for GitHub Actions, updates pinned GitHub Actions across workflows, and raises pnpm and listed development dependency versions in package.json. The existing npm Dependabot configuration and Node engine requirement remain unchanged. ChangesRepository maintenance
Priority: ⬆️ High Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable merge-blocking issue is established. The deployment and release workflow updates will run on their configured push and tag events after merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
概述
更新 npm 依赖与 GitHub Actions,修复依赖中的两个已知安全漏洞,并让 Dependabot 同时跟踪 Actions 的版本。
本 PR 覆盖了以下 Dependabot PR 的更新内容:#385、#386、#387、#388、#389、#392。合并后 Dependabot 会自动关闭它们。
npm 依赖
packageManager)@types/nodemarkedprettiersharpsubset-fontshikiserialize-javascript(间接)source-map-js(间接)rollup(间接)升级后
pnpm audit不再报告已知漏洞。暂不升级的依赖:
vite-plugin-pwa2.0.0:@vite-pwa/vitepress1.1.0(当前最新)的 peer 依赖仍要求^1.2.0。workbox-build7.4.1 引入的glob@11.1.0已被标记为弃用,目前workbox-build已经是最新版本,只能等上游更新。GitHub Actions
actions/checkoutactions/setup-nodepnpm/action-setupactions/upload-pages-artifactactions/deploy-pagessoftprops/action-gh-release新版本都运行在 Node 24 上,可以消除 Node 20 的弃用警告。
mlugg/setup-zig的最新版本仍是 v2,保持不变。已逐一核对各大版本的破坏性变更,对本仓库都没有影响:
checkoutv7 禁止在pull_request_target和workflow_run中检出 fork 的代码。本仓库的 workflow 都没有使用这两种触发方式。upload-pages-artifactv4 起默认不再打包隐藏文件。VitePress 的构建产物中没有隐藏文件。setup-nodev5 起检测到packageManager时会自动启用缓存。各 workflow 已经显式设置了cache: pnpm,行为不变。dependabot.yml新增了github-actions生态,以后 Actions 的版本也会每周自动检查。验证
pnpm install --frozen-lockfilepnpm checkpnpm auditpnpm buildpnpm pdf:sample/pnpm pdfpnpm epubdeploy.yml和release.yml只在推送到 main 或打 tag 时运行,这两个 workflow 中的 action 升级要在合并后才能实际验证。Summary by CodeRabbit