Skip to content

[ZEPPELIN-6656] Patch New UI dependencies and refresh lockfile - #5546

Open
gjenfwo wants to merge 3 commits into
apache:masterfrom
gjenfwo:ZEPPELIN-6656
Open

gjenfwo wants to merge 3 commits into
apache:masterfrom
gjenfwo:ZEPPELIN-6656

Conversation

@gjenfwo

@gjenfwo gjenfwo commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

What is this PR for?

Partial remediation of the npm audit findings in the New UI (zeppelin-web-angular). It updates dependencies that have compatible patched releases and pins patched transitive versions, keeping Angular 21 and G2 3.

  • Bump Angular packages to ^21.2.25, and bump vitest / @vitest/coverage-v8 to 4.1.11, concurrently to 9.2.4 and ws to 8.22.0
  • Switch xlsx from the unmaintained npm 0.14.3 to the official SheetJS 0.20.3 distribution (cdn.sheetjs.com)
  • Upgrade highlight.js from 9.x to 10.7.3. Add an HTMLElement type parameter for highlightBlock
  • Add overrides for patched transitive releases: fast-uri, js-yaml, nanoid, undici (6/7), minimatch@3, brace-expansion (1/5), fmin, d3-color
  • Refresh package-lock.json
  • Add regression tests:
    • result.component.spec.ts: HTML results keep their markup, and code blocks are still highlighted with the new highlight.js
    • test/g2-dependency-compatibility.spec.ts: a G2 3 interval chart still renders with the overridden d3-color

Classic UI (zeppelin-web) dependencies are unchanged.

This PR does not bring npm audit to zero. After this change:

  • New UI: 11 high and 2 moderate findings
  • React remote (existing CI audit job): 5 high findings

The remaining findings are blocked by:

  • braces <=3.0.3 (GHSA-vfj7-8cjw-p6xm) has no patched release yet. It is pulled in through micromatch → http-proxy-middleware / webpack-dev-server, and through ts-loader in React.
  • angular 1.8.x (AngularJS) has no compatible patched npm release.
  • MathJax 2: moving to a patched major requires reworking the MathJax.Hub configuration and bundled assets.
  • Other findings come through webpack-dev-server and lint-staged.

These need upstream fixes or an agreed migration scope, so I'd suggest handling them in follow-up issues.

What type of PR is it?

Improvement

Todos

  • - Update compatible dependencies and pin patched transitive releases
  • - Add regression tests for highlight.js and G2 rendering
  • - Resolve remaining audit findings (braces, AngularJS, MathJax 2), possibly in follow-up issues

What is the Jira issue?

How should this be tested?

  • CI passes.
  • Run locally in zeppelin-web-angular:
    • npm ci
    • Production build (notebook-core, SDK, visualization, React remote and Angular app) passes.
    • Shell tests: 29 files, 179 tests pass.
    • React tests: 14 files, 98 tests pass.
    • In Chromium, G2 charts and the React remote render correctly.
  • Manually: run a paragraph that returns %html containing <pre><code>, and check that the code is highlighted. Export a table result to XLSX, and check that the file downloads and opens.

Screenshots (if appropriate)

N/A

Questions:

  • Does the license files need to update? No. SheetJS xlsx is still Apache-2.0.
  • Is there breaking changes for older versions? No user-facing changes are intended. Angular and G2 major versions are unchanged.
  • Does this needs documentation? No.

@voidmatcha

Copy link
Copy Markdown
Member

The overall changes and local tests look good. However, this branch currently conflicts with the latest master and also includes the already merged ZEPPELIN-6725 commit. Please rebase it onto the latest master and integrate the new regression case into the existing result.component.spec.ts.

Update compatible dependencies and pin patched transitive releases while retaining Angular 21 and G2 3. Use the official SheetJS 0.20.3 distribution and update highlight.js with an HTML highlighting regression test.

Validation: clean installs, Angular/library/React builds, 179 shell tests, 98 React tests, and Chromium G2/React remote rendering pass. Classic UI dependencies are unchanged.

Audit remains blocked: the New UI reports 11 high and 2 moderate findings, including unpatched braces and AngularJS plus MathJax 2. The existing React CI audit still reports five high findings through braces; this commit does not satisfy the zero-vulnerability acceptance criterion.
Update ts-loader to 9.6.2 and refresh its lockfile entry. This release
uses picomatch instead of micromatch, removing the ts-loader path to
the unpatched braces dependency without adding a compatibility layer.

Validation: clean installs, 98 React tests, 179 shell tests, React
production build, React lint, and changed-file formatting pass.
React audit findings decrease from five high entries to four; the
remaining development-server path is not addressed by this change.
@gjenfwo

gjenfwo commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

The overall changes and local tests look good. However, this branch currently conflicts with the latest master and also includes the already merged ZEPPELIN-6725 commit. Please rebase it onto the latest master and integrate the new regression case into the existing result.component.spec.ts.

I have rebased this branch onto the latest master and resolved the merge conflicts. The already merged ZEPPELIN-6725 commit is no longer included in the PR diff, and I have integrated the new regression case into the existing result.component.spec.ts.

I also explored a broader remediation that brought both npm audits to zero locally:

  • Replace the New UI AngularJS runtime with a security-patched maintenance fork.
  • Migrate MathJax 2 to locally served MathJax 3 components, including asynchronous typesetting and cleanup.
  • Remove the remaining braces dependency through build dependency updates and a scoped Picomatch adapter for proxy path matching.
    The prototype passed local builds, unit tests and browser smoke checks. However, it introduces a new maintenance provider and a compatibility layer, which deserve separate review and maintainer agreement.
    I have therefore kept this PR focused on the available dependency updates. The current audit reports 13 entries for the New UI (11 high, 2 moderate) and 4 high entries for the React remote. Would it be okay for me to work on the remaining remediation as well?

@voidmatcha

Copy link
Copy Markdown
Member

The Playwright tests did not run because the build stopped at the Prettier check. Since the refreshed lockfile updates Prettier to 3.9.9, could you format the two reported files with:

cd zeppelin-web-angular
npx prettier --write \
  projects/zeppelin-sdk/src/interfaces/message-paragraph.interface.ts \
  src/app/services/completion.service.ts

This should allow the E2E jobs to proceed.

@gjenfwo

gjenfwo commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

The Playwright tests did not run because the build stopped at the Prettier check. Since the refreshed lockfile updates Prettier to 3.9.9, could you format the two reported files with:

cd zeppelin-web-angular
npx prettier --write \
  projects/zeppelin-sdk/src/interfaces/message-paragraph.interface.ts \
  src/app/services/completion.service.ts

This should allow the E2E jobs to proceed.

Thanks! I formatted both files with Prettier 3.9.9 and pushed the change (c1e204e). The Playwright E2E jobs are running now.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants