docs(deps): add release note and correct lockfile verification guidance

Addresses both Codex review findings:

- P1: add the missing `.changes/` entry. Typed `internal` per
  `.changes/README.md`, which names dependency bumps with behaviour risk as
  exactly that category.
- P2: the doc claimed pnpm leaves superseded package blocks in the lockfile.
  It does not — it removes them. The old versions survive only as the
  overrides' own selector keys in the `overrides:` block at the top of
  `pnpm-lock.yaml`, which is what a naive grep actually hits. The practical
  advice is unchanged (resolve on disk, do not grep), but the reason it gives
  is now correct.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Opus 5 committed 2026-07-25 22:25:39 +02:00
1 parent d2316fafe9
commit c7e46f880b
2 files changed
+20 -4

No files matched your search

@@ -0,0 +1,8 @@
---
type: internal
area: deps
---
Patched five vulnerable transitive dependencies that ship with the app —
including the YAML parser `electron-updater` uses to read update manifests, and
the HTTP form encoder behind portal requests. No behaviour change.
@@ -45,10 +45,18 @@ npm view <parent>@<version> dependencies --json
## Verifying an override actually applied
pnpm leaves the superseded package block in `pnpm-lock.yaml` even when nothing
resolves to it any more, so grepping for the old version is misleading — it will
still be there. Check the _dependents_ instead, or resolve the real path on
disk:
Grepping `pnpm-lock.yaml` for the old version still finds it, but that hit is
not a leftover package block — pnpm removes those once nothing resolves to them.
It is the override's own selector key, echoed in the `overrides:` block at the
top of the lockfile:
```yaml
overrides:
'@xmldom/xmldom@0.8.11': 0.8.13
```
So a bare grep proves only that the override is declared, never that it took
effect. Resolve the real path on disk instead:
```bash
node -e "console.log(require('./node_modules/.pnpm/mpd-parser@1.3.1/node_modules/@xmldom/xmldom/package.json').version)"