Skip to content

Fix CI release warnings and patch vulnerable dependencies - #221

Open
jantimon wants to merge 3 commits into
mainfrom
fix/ci-release-warnings
Open

jantimon wants to merge 3 commits into
mainfrom
fix/ci-release-warnings

Conversation

@jantimon

@jantimon jantimon commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

CI and release jobs should use supported Node 24 actions and install dependencies without deprecation or audit warnings.

  • Use actions/checkout@v7 and actions/setup-node@v7 in both workflows. These target Node 24; setup-node also omits the obsolete always-auth setting.
  • Use Node 24's bundled npm for trusted publishing. Keep the release job on the same npm as CI and avoid pulling a new npm major through npm@latest.
  • Approve the pinned Puppeteer install script for browser tests and deny it in the browser-free smoke fixture.
  • Require TOON ^2.3.1 and update both js-yaml copies to patched releases. Include a patch changeset for the TOON dependency floor.

Validation: clean install with zero audit findings; lint, format, unused-code checks, build, and all 774 unit tests, and the package smoke test pass. Both workflow files parse as YAML.

A clean install and the package smoke test also pass without npm warnings under npm 11.19.0, matching the GitHub runner.

GitHub validation: CI, Chrome end-to-end tests, and package smoke test all pass. The completed run has no npm warnings, Node deprecation warnings, or workflow warning annotations. The release job runs only on pushes to main, so it is skipped for this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant