Skip to content

Update dependencies to resolve Dependabot alerts - #2128

Open
kayjoosten wants to merge 3 commits into
mainfrom
chore/2121-dependabot-updates
Open

kayjoosten wants to merge 3 commits into
mainfrom
chore/2121-dependabot-updates

Conversation

@kayjoosten

Copy link
Copy Markdown
Contributor

Summary

Updates the Composer, theme Yarn and Cypress Yarn lock files to the latest versions allowed by the current version constraints, resolving most open Dependabot alerts (twig, simplesamlphp/saml2, league/flysystem, js-yaml, svgo, fast-uri, postcss, brace-expansion and more).

  • Major bumps are intentionally left out (phpunit 13, doctrine-bundle 3, Symfony 8, js-yaml 5, webpack-cli 7, babel-loader 10).
  • The newer stylelint flags valid SCSS @mixin preludes, so at-rule-prelude-no-invalid is disabled in theme/.stylelintrc, like media-query-no-invalid already is.
  • CHANGELOG entry added.

Still open

  • guzzlehttp/guzzle and guzzlehttp/psr7: simplesamlphp/assert 1.9.1 pins psr7 to ~2.8.0, while the fixed guzzle 7.15 needs psr7 ^2.13. simplesamlphp/assert 2.x/3.x conflicts with webmozart/assert ^1 required by saml2 4.x. Replacing simplesamlphp/assert in the two legacy validators would unblock this.
  • extract-zip (Cypress) and braces (stylelint) have no patched release yet.

Testing

PHPUnit (unit, eb4, integration, functional), phpmd, phpcs, docheader, Twig lint, theme build and lint, and the Behat default suite (300 scenarios) all pass.

Refs #2121

# If applied, this commit will
update the Composer, theme Yarn and Cypress Yarn lock files to the
latest versions allowed by the current version constraints.

# Why is this change needed?
Prior to this change, many Dependabot PRs and security alerts were
open (twig, simplesamlphp/saml2, league/flysystem, js-yaml, svgo,
fast-uri, postcss, brace-expansion and more).

# How does it address the issue?
This change runs a constraint-respecting update of all three lock
files. Major version bumps (phpunit 13, doctrine-bundle 3, symfony 8,
js-yaml 5, webpack-cli 7, babel-loader 10) are left out. The newer
stylelint flags valid SCSS @mixin preludes, so at-rule-prelude-no-invalid
is disabled in the same way media-query-no-invalid already is.

The guzzlehttp/guzzle and guzzlehttp/psr7 fixes remain blocked by the
~2.8.0 psr7 pin in simplesamlphp/assert 1.9.1. This is documented in the
CHANGELOG. extract-zip and braces have no patched release yet.

# Provide links to any relevant tickets, articles or other resources
Refs #2121
Comment thread CHANGELOG.md Outdated
# If applied, this commit will
remove the notes about what was not updated from the CHANGELOG entry.

# Why is this change needed?
Prior to this change, the entry described the major bumps and the
guzzle/psr7 blocker that were not part of this change. A changelog
should only list what was done.

# How does it address the issue?
This change keeps a single line describing the dependency update.

# Provide links to any relevant tickets, articles or other resources
Refs #2121
Comment thread theme/.stylelintrc Outdated
{
"extends": "stylelint-config-recommended",
"rules": {
"at-rule-prelude-no-invalid": null,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if possbile, remove?

# If applied, this commit will
keep at-rule-prelude-no-invalid enabled and only skip the SCSS
at-rules and the interpolated @media queries in breakpoints.scss.

# Why is this change needed?
Prior to this change, the rule was disabled for the whole theme to get
past false positives on SCSS mixin signatures and interpolation, which
would also hide real mistakes in at-rule preludes.

# How does it address the issue?
This change passes the SCSS-only at-rules (mixin, include, if, each,
for, function, return, use, else) through ignoreAtRules, and disables
the rule for breakpoints.scss only, where @media uses #{$var}
interpolation.

# Provide links to any relevant tickets, articles or other resources
Refs #2121
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants