mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 10:06:15 -08:00
docs(deps): add release note and correct lockfile verification guidance
Addresses both Codex review findings: - P1: add the missing `.changes/` entry. Typed `internal` per `.changes/README.md`, which names dependency bumps with behaviour risk as exactly that category. - P2: the doc claimed pnpm leaves superseded package blocks in the lockfile. It does not — it removes them. The old versions survive only as the overrides' own selector keys in the `overrides:` block at the top of `pnpm-lock.yaml`, which is what a naive grep actually hits. The practical advice is unchanged (resolve on disk, do not grep), but the reason it gives is now correct. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
d2316fafe9
commit
c7e46f880b
2 files changed
+20
-4
No files matched your search
@@ -0,0 +1,8 @@
|
||||
---
|
||||
type: internal
|
||||
area: deps
|
||||
---
|
||||
|
||||
Patched five vulnerable transitive dependencies that ship with the app —
|
||||
including the YAML parser `electron-updater` uses to read update manifests, and
|
||||
the HTTP form encoder behind portal requests. No behaviour change.
|
||||
@@ -45,10 +45,18 @@ npm view <parent>@<version> dependencies --json
|
||||
|
||||
## Verifying an override actually applied
|
||||
|
||||
pnpm leaves the superseded package block in `pnpm-lock.yaml` even when nothing
|
||||
resolves to it any more, so grepping for the old version is misleading — it will
|
||||
still be there. Check the _dependents_ instead, or resolve the real path on
|
||||
disk:
|
||||
Grepping `pnpm-lock.yaml` for the old version still finds it, but that hit is
|
||||
not a leftover package block — pnpm removes those once nothing resolves to them.
|
||||
It is the override's own selector key, echoed in the `overrides:` block at the
|
||||
top of the lockfile:
|
||||
|
||||
```yaml
|
||||
overrides:
|
||||
'@xmldom/xmldom@0.8.11': 0.8.13
|
||||
```
|
||||
|
||||
So a bare grep proves only that the override is declared, never that it took
|
||||
effect. Resolve the real path on disk instead:
|
||||
|
||||
```bash
|
||||
node -e "console.log(require('./node_modules/.pnpm/mpd-parser@1.3.1/node_modules/@xmldom/xmldom/package.json').version)"
|
||||
|
||||
Reference in new issue
Block a user