Skip to content

1033 update package lock.json - #1038

Open
jsjiang wants to merge 7 commits into
developfrom
1033_update_package-lock.json
Open

1033 update package lock.json#1038
jsjiang wants to merge 7 commits into
developfrom
1033_update_package-lock.json

Conversation

@jsjiang

@jsjiang jsjiang commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

@sfisher Hi Scott,
The detailed change requests are listed in ticket Update package-lock.json - July 2026. Only the following packages were updated:

  • ws
  • js-yaml
  • sharp

No updated UI files were produced.

Please review and let me know if you have questons.

Thank you

Jing

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Not ready to approve

The Node version change should be pinned/compatible with lockfile engine constraints, and the PR description currently understates the scope of lockfile updates.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.

Pull request overview

Updates the Node-based UI toolkit dependencies/lockfile to address Dependabot security alerts (Issue #1033), primarily by bumping sharp and refreshing package-lock.json, along with a Node version update via .nvmrc.

Changes:

  • Bump sharp in package.json from ^0.34.5 to ^0.35.0.
  • Regenerate package-lock.json, updating sharp, js-yaml, and other resolved (transitive and range-permitted) packages.
  • Update .nvmrc from Node 18.20.8 to 24.
File summaries
File Description
package.json Updates the declared sharp devDependency range.
package-lock.json Refreshes locked dependency graph/versions (including sharp and js-yaml).
.nvmrc Updates the Node version used for UI-tooling development workflows.
Review details
  • Files reviewed: 2/3 changed files
  • Comments generated: 1
  • Review effort level: Low

We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.

Comment thread .nvmrc Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants