Repository navigation
Conversation
✅ Deploy Preview for netdata-docusaurus ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 43 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
No issues found across 3 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Architecture diagram
sequenceDiagram
participant Dev as Developer
participant CI as CI Pipeline
participant Yarn as Yarn 1.22.22
participant Resolver as Yarn Resolver
participant NPM as npm Registry
participant Lockfile as yarn.lock
participant Test as Dependency Authority Test
participant Docusaurus as Docusaurus Build
participant Audit as npm Audit
Note over Dev,Audit: Build Dependency Resolution Flow
Dev->>Yarn: yarn install --frozen-lockfile
Yarn->>Resolver: Resolve dependencies
Resolver->>package.json: Read resolutions map
package.json-->>Resolver: Version overrides (js-yaml, joi, svgo, qs)
Note over Resolver,NPM: Resolution Authority Chain
Resolver->>NPM: Fetch package versions honoring resolutions
NPM-->>Resolver: Resolved packages (qs 6.16.0, terser 5.6.1, etc.)
Resolver->>Lockfile: Update lockfile entries
Lockfile-->>Yarn: Locked dependency tree
Yarn-->>Dev: Install complete
Note over Test,Docusaurus: Validation Flow
Test->>package.json: Read expected resolutions
package.json-->>Test: Resolution map
Test->>Lockfile: Verify resolved versions match
Lockfile-->>Test: Version confirmation
alt All resolutions match
Test-->>CI: Pass (490 Vitest + 99 Node checks)
else Mismatch detected
Test-->>CI: Fail - resolution authority violation
end
CI->>Docusaurus: Build documentation site
Docusaurus->>Lockfile: Use locked dependency tree
Lockfile-->>Docusaurus: Dependencies (js-yaml 4.3.2, joi 17.13.8, svgo 3.3.5)
Docusaurus-->>CI: Publication gates (2,032 pages)
CI->>Audit: Run security audit
Audit->>NPM: Query advisory database
NPM-->>Audit: 87 advisory/path rows (10 packages, 14 GHSAs)
Audit-->>CI: Non-clean audit status
Note over CI,Audit: Remaining findings require unsupported parent changes<br/>or have no verified published fix. Separate PR #3129<br/>covers remaining YAML and brace paths.
ktsaou
marked this pull request as draft
October 9, 2026 09:36
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refresh compatible build dependency fixes through Learn's existing version ranges and patch resolutions. The Express/body-parser chain now permits qs 6.16.0, Terser 5.6.1 removes its serialize-javascript dependency, and YAML, Joi, SVGO, selector-parser and Undici use supported updates. Existing resolution-authority assertions name the new patches.
Validation: frozen Yarn install, all 2,032-page publication gates, 490 existing Vitest checks plus one existing skip, and 99 Node checks pass. The rendered redirect file initially ran before its build prerequisite completed; only that file was rerun after publication and passed all 27 checks. A separate direct Terser/Webpack probe minifies a bundle without changing its executable result; production uses SWC/Rspack.
The audit is not clean: 87 advisory/path rows cover ten package names and fourteen GHSAs. Separate Swagger PR #3129 covers the remaining YAML and brace paths. Other findings require unsupported parent changes or have no verified published fix. No forced overrides, direct dependencies, runtime or policy changes are introduced here. This Yarn update does not rewrite prebuilt Swagger assets.
Summary by cubic
Refreshes build dependencies through existing Yarn resolutions and version ranges to their security-fixed releases. The Express/body-parser chain now permits
qs6.16.0, Terser 5.6.1 removes itsserialize-javascriptdependency, andjs-yaml,joi,svgo,postcss-selector-parser, andundicimove to supported patches. The dependency authority test now asserts the new patch versions.Validation
Remaining findings
Written for commit 955a516. Summary will update on new commits.