Conversation
|
The overall changes and local tests look good. However, this branch currently conflicts with the latest master and also includes the already merged ZEPPELIN-6725 commit. Please rebase it onto the latest master and integrate the new regression case into the existing result.component.spec.ts. |
Update compatible dependencies and pin patched transitive releases while retaining Angular 21 and G2 3. Use the official SheetJS 0.20.3 distribution and update highlight.js with an HTML highlighting regression test. Validation: clean installs, Angular/library/React builds, 179 shell tests, 98 React tests, and Chromium G2/React remote rendering pass. Classic UI dependencies are unchanged. Audit remains blocked: the New UI reports 11 high and 2 moderate findings, including unpatched braces and AngularJS plus MathJax 2. The existing React CI audit still reports five high findings through braces; this commit does not satisfy the zero-vulnerability acceptance criterion.
Update ts-loader to 9.6.2 and refresh its lockfile entry. This release uses picomatch instead of micromatch, removing the ts-loader path to the unpatched braces dependency without adding a compatibility layer. Validation: clean installs, 98 React tests, 179 shell tests, React production build, React lint, and changed-file formatting pass. React audit findings decrease from five high entries to four; the remaining development-server path is not addressed by this change.
I have rebased this branch onto the latest master and resolved the merge conflicts. The already merged I also explored a broader remediation that brought both npm audits to zero locally:
|
|
The Playwright tests did not run because the build stopped at the Prettier check. Since the refreshed lockfile updates Prettier to 3.9.9, could you format the two reported files with: cd zeppelin-web-angular
npx prettier --write \
projects/zeppelin-sdk/src/interfaces/message-paragraph.interface.ts \
src/app/services/completion.service.tsThis should allow the E2E jobs to proceed. |
Thanks! I formatted both files with Prettier 3.9.9 and pushed the change (c1e204e). The Playwright E2E jobs are running now. |
What is this PR for?
Partial remediation of the npm audit findings in the New UI (
zeppelin-web-angular). It updates dependencies that have compatible patched releases and pins patched transitive versions, keeping Angular 21 and G2 3.^21.2.25, and bumpvitest/@vitest/coverage-v8to 4.1.11,concurrentlyto 9.2.4 andwsto 8.22.0xlsxfrom the unmaintained npm0.14.3to the official SheetJS0.20.3distribution (cdn.sheetjs.com)highlight.jsfrom 9.x to 10.7.3. Add anHTMLElementtype parameter forhighlightBlockoverridesfor patched transitive releases:fast-uri,js-yaml,nanoid,undici(6/7),minimatch@3,brace-expansion(1/5),fmin,d3-colorpackage-lock.jsonresult.component.spec.ts: HTML results keep their markup, and code blocks are still highlighted with the new highlight.jstest/g2-dependency-compatibility.spec.ts: a G2 3 interval chart still renders with the overriddend3-colorClassic UI (
zeppelin-web) dependencies are unchanged.This PR does not bring
npm auditto zero. After this change:The remaining findings are blocked by:
braces <=3.0.3(GHSA-vfj7-8cjw-p6xm) has no patched release yet. It is pulled in throughmicromatch→http-proxy-middleware/webpack-dev-server, and throughts-loaderin React.angular1.8.x (AngularJS) has no compatible patched npm release.MathJax.Hubconfiguration and bundled assets.webpack-dev-serverandlint-staged.These need upstream fixes or an agreed migration scope, so I'd suggest handling them in follow-up issues.
What type of PR is it?
Improvement
Todos
What is the Jira issue?
How should this be tested?
zeppelin-web-angular:npm ci%htmlcontaining<pre><code>, and check that the code is highlighted. Export a table result to XLSX, and check that the file downloads and opens.Screenshots (if appropriate)
N/A
Questions:
xlsxis still Apache-2.0.