Repository navigation
Conversation
3.0.1 drops jest from its runtime dependencies, removing 272 packages from the install tree. The nested ws override only targeted jsdom's ws under jest, so it is dead and removed. The braces and sprintf-js audit exception notes no longer attribute their production paths to jest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe manifest upgrades Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to No actionable risk from the dependency update or revised audit notes remains; the change is mergeable after normal checks. 🚥 Pre-merge checks | ✅ 6✅ Passed checks (6 passed)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #556 +/- ##
=====================================
Coverage 38% 38%
=====================================
Files 822 822
Lines 41098 41098
Branches 9044 9044
=====================================
Hits 15620 15620
Misses 23405 23405
Partials 2073 2073 🚀 New features to boost your workflow:
|
Summary
@deepnote/sql-language-server@3.0.1no longer listsjest@^26.0.1underdependencies. The published tarball differs from 3.0.0 only inpackage.json(version and thejestline), anddist/is byte-identical.package.json:^3.0.0→^3.0.1.overrides["@deepnote/sql-language-server"].wspinnedjsdom/node_modules/ws, which jest 26 pulled in through jsdom. That copy is gone, so the override no longer has a target..nsprcnotes corrected: the braces (GHSA-vfj7-8cjw-p6xm) and sprintf-js (GHSA-hp3w-g68c-fv3c) notes said these packages were in the production tree because of sql-language-server's jest. Now braces reaches production only through@jupyterlab/filebrowser→jest-environment-jsdom, and sprintf-js is dev-only (nyc). Both exceptions are still needed by Audit - All, so the entries and expiries are unchanged.Size impact
package-lock.jsonentriesnpm cinode_modules(apparent size)node_modules(disk usage)npm auditfindings (full tree)The VSIX doesn't change because jest never shipped in it.
vsce package --no-dependenciesand.vscodeignore(node_modules/**) keepnode_modulesout.dist/sqlLanguageServer.cjsis an esbuild bundle of the server entry point, and it comes out byte-identical when built from either version (compared after normalizing the build path).dist/sql-lsp-modulesinstalls a fixed list of drivers that doesn't include this package. So the savings are on developer and CI installs, not on users' downloads.Measured with clean
npm ci --ignore-scriptsinstalls of the before and after lockfiles side by side.Reviewing the lockfile
GitHub's default (Myers) diff shows about +32k/−38k lines for
package-lock.jsonbecause the lockfile v2 legacydependenciessection gets re-nested. Withgit diff --histogramthe real change is +280/−6,367. That is the 272 removed entries, plus 95 packages that now get"dev": truebecause jest was their only production consumer.Verification
npm installon a fresh copy with the pinned npm 10.9.4 leaves the lock unchanged (same lock-drift check as CI). A control run onmain's lock is also clean.npx better-npm-audit audit --productionandnpx better-npm-audit auditboth pass.npm run lint,npm run typecheck,npm run format,npm run esbuild-all: all pass.rm -rf out && npm run compile-tsc && npm test: 2,879 passing, 0 failing.🤖 Generated with Claude Code
https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
Summary by CodeRabbit