Repository navigation
Conversation
Converted with `npm install --package-lock-only --lockfile-version=3 --ignore-scripts` (npm 10.9.4). The `packages` section is unchanged; only the legacy npm 6 `dependencies` section is dropped. postInstall's moment check required the legacy section, so it now reads `packages` only, and checks `optionalDependencies` as well, which the legacy `requires` field used to cover. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. 3 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe Moment usage check now scans only the package-lock Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to No concrete merge-blocking risk is introduced by this PR. 🚥 Pre-merge checks | ✅ 5 | ❓ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (5 passed)
Full details: Updates DocsExplanation The pull request changes only CI, post-install logic, the root lockfile, and
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #557 +/- ##
=====================================
Coverage 38% 38%
=====================================
Files 822 822
Lines 41098 41098
Branches 9044 9044
=====================================
Hits 15620 15620
Misses 23405 23405
Partials 2073 2073 🚀 New features to boost your workflow:
|
The v3 root package-lock.json is 1,555,451 bytes, under qlty's 2,098,000-byte file limit, so osv-scanner now scans it for the first time (v2 was 2,789,530 bytes and silently skipped). It reports the three accepted risks .nsprc already excepts for better-npm-audit, so mirror them in osv-scanner.toml with the same expiry dates. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
Summary
Converts the root
package-lock.jsonfromlockfileVersion2 to 3. No package versions change: thepackagessection is byte-for-byte the same data, and the only removal is the legacydependenciessection that v2 kept for npm 5/6.package-lock.json: +1 / −25,367. The diff is thelockfileVersionline plus the deleted legacy section.build/ci/postInstall.js:verifyMomentIsOnlyUsedByJupyterLabCoreUtilsthrew unless the lockfile had bothpackagesanddependencies, so on v3 everynpm install/npm cifailed inpostinstall. It now readspackagesonly, and checksoptionalDependenciesalongsidedependencies. Inmain's lockfile, legacyrequiresequalsdependencies∪optionalDependenciesfrompackagesfor all 1,621 entries that have one, so the check covers the same declarations. Upstream vscode-jupyter has the same check and is still on v2.osv-scanner.toml(new) and the comment above the qlty dependency scan inci.yml: see below.Why
v2 stores every package twice: once in
packagesand again in the nested legacydependenciestree. Only npm 5/6 read the legacy tree. Every supported npm (7+) reads onlypackages, the repo pins Node 22 / npm 10.9.4 via.nvmrc, and the perf-test fixture lockfile is already v3. Dropping the copy shrinks the file from 61,378 to 36,012 lines. It also ends npm 11's rewriting of legacyrequireslines, which used to show up as lock drift.This reduces inflated dependency diffs but doesn't eliminate them. Git's default (Myers) diff stops searching for the best alignment in large, repetitive files. #556's real change of +280/−6,367 renders as +32,095/−38,182 on v2. On v3 the same change renders as +11,860/−15,491 (real: +120/−3,751). Most of the misalignment happens in the
packagessection, which v3 keeps. The legacy section alone diffs almost exactly (+316/−2,772 vs. a real +160/−2,616).qlty now scans the root lockfile
Converting to v3 also turns on qlty's osv-scanner check for the root
package-lock.json. qlty silently skips files over 2,098,000 bytes (MAX_FILE_SIZE):main)mainreports "No issues"The first scan reported the three advisories that
.nsprcalready accepts for better-npm-audit: ellipticGHSA-848j-6mx2-7j84, bracesGHSA-vfj7-8cjw-p6xmand sprintf-jsGHSA-hp3w-g68c-fv3c. They're copied into a rootosv-scanner.tomlwith the same expiry dates; osv-scanner reads it from the lockfile's own directory, so the perf-test fixture is unaffected. Theci.ymlcomment claiming the root lockfile is "too large for qlty to analyze" is updated.From now on:
.nsprcandosv-scanner.toml.How it was converted
Per the npm docs, an existing lockfile is converted when
--lockfile-versionis set (lockfile-version, npm/cli#5605), and--package-lock-onlyworks from the lockfile alone, ignoringnode_modules:npm install --package-lock-only --lockfile-version=3 --ignore-scripts # Node 22.21.1 / npm 10.9.4 (.nvmrc)A full
npm install --lockfile-version=3from the same starting point produces a byte-identical file. No.npmrcis needed: npm 7+ defaults to "maintain current lockfile version" (v8, v10 docs).Verification
assert.deepStrictEqualpasses on thepackagessection (2,909 entries) ofmainvs this branch. Every other top-level field is equal too, exceptlockfileVersionand the removeddependencies.npm ci --ignore-scriptsfrom the v3 lockfile produces anode_modules/.package-lock.jsondeep-equal to an install frommain's v2 lockfile (2,827 packages).postinstall:npm ciwith scripts on this branch passes.momentindependenciesor inoptionalDependencies.Invalid package-lock.json, as it does not contain the key 'dependencies'on v3.npm installleaves the lockfile unchanged with npm 10.9.4 (CI) and with npm 11.19.0. On v2, npm 11 rewrote legacyrequireslines; that section is now gone.npx better-npm-audit audit --productionandnpx better-npm-audit auditboth pass.osv-scanner.toml(no other change in between). Its IDs and expiry dates match.nsprcexactly.npm run formatpasses.Notes
lockfileVersionwhenpackage.jsonhas no npm constraint (source). v2 → npm<9(8.x), so far. v3 → npm>=7, i.e. a current npm. To pin Renovate to the.nvmrcnpm instead,constraints.npmcan be set inrenovate.json. Not done here.src/test/vscode-notebook-perf(already v3), and it has supported v3 since March 2023.checkNpmDependenciesalready skips a missingdependencieskey.🤖 Generated with Claude Code
https://claude.ai/code/session_01USEnGCRP32gQH4AZHbRVqQ
Summary by CodeRabbit