Skip to content

build(deps): upgrade docs site toolchain to clear Dependabot alerts - #84

Merged
Roger-luo merged 1 commit into
mainfrom
fix/docs-npm-audit
Jul 12, 2026
Merged

Roger-luo merged 1 commit into
mainfrom
fix/docs-npm-audit

Conversation

@Roger-luo

Copy link
Copy Markdown
Owner

Summary

Resolves all 66 open Dependabot alerts (19 high, 36 medium, 11 low). Every one of them was in docs/package-lock.json — the Astro/Starlight documentation site's npm dependency tree (vite, rollup, esbuild, tar-fs, cross-spawn, astro, nanoid, cookie, path-to-regexp, prismjs, …). None touched the Julia package.

Clearing every alert required Astro ≥ 6.4.6, and the latest Starlight pins Astro 7, so this is a real toolchain upgrade rather than a lockfile patch.

Changes (all under docs/)

File Change
package.json astro ^4.10 → ^7.0.7, @astrojs/starlight ^0.25 → ^0.41.3, @astrojs/check → ^0.9.9, marked → ^18, sharp → ^0.35; typescript pinned ^5.9.3 (TS 7 is unsupported by @astrojs/check). Dropped @astropub/md (unmaintained; its @astrojs/markdown-remark ^5 peer conflicts with Astro 7).
src/components/ApiDoc.astro Render API docstrings with the already-present marked (set:html) instead of @astropub/md's <Markdown>.
src/content.config.ts (renamed from src/content/config.ts) Migrated to Astro's content layer using Starlight's docsLoader().
astro.config.mjs Updated Starlight social to the array-of-links format (0.41 breaking change).
package-lock.json Regenerated.

Verification

  • npm ci → lockfile consistent with package.json.
  • npm audit → found 0 vulnerabilities (same GitHub Advisory DB Dependabot uses).
  • astro check → 0 errors, 0 warnings, 0 hints.
  • astro build → 22 pages built, including the three /api/* pages that use the migrated ApiDoc.astro.

The alerts will auto-close once this lands on main.

🤖 Generated with Claude Code

All 66 open Dependabot alerts were in docs/package-lock.json (the
Astro/Starlight documentation site's npm tree); none touched the Julia
package. Clearing them required Astro >= 6.4.6, and latest Starlight
pins Astro 7, so this is a real toolchain bump rather than a lockfile
patch:

- astro ^4.10 -> ^7.0.7, @astrojs/starlight ^0.25 -> ^0.41.3,
  @astrojs/check -> ^0.9.9, marked -> ^18, sharp -> ^0.35;
  typescript pinned ^5.9.3 (TS 7 unsupported by @astrojs/check).
- Drop @astropub/md (unmaintained; its @astrojs/markdown-remark ^5 peer
  conflicts with Astro 7) and render API docstrings via marked instead.
- Migrate content config to the content layer (src/content.config.ts
  with Starlight's docsLoader()).
- Update Starlight `social` to the array-of-links format (0.41 change).

Verified: `npm audit` reports 0 vulnerabilities and `astro check` +
`astro build` pass (0 errors/warnings/hints, 22 pages).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
moshi-jl Ready Ready Preview, Comment Jul 12, 2026 6:12pm

@codecov

codecov Bot commented Jul 12, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 91.70%. Comparing base (16c3497) to head (acfbfa0).

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #84   +/-   ##
=======================================
  Coverage   91.70%   91.70%           
=======================================
  Files          43       43           
  Lines        1663     1663           
=======================================
  Hits         1525     1525           
  Misses        138      138           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions

Copy link
Copy Markdown
Contributor

Benchmark Results (Julia v1)

Time benchmarks
main acfbfa0... main / acfbfa0...
adt_transform/transform n=100 6.64 ± 0.12 μs 7.08 ± 0.14 μs 0.938 ± 0.025
adt_transform/transform n=1000 0.0647 ± 0.00079 ms 0.0685 ± 0.0009 ms 0.945 ± 0.017
linked_list/sum n=100 0.47 ± 0.01 μs 0.471 ± 0 μs 0.998 ± 0.021
linked_list/sum n=1000 5.12 ± 0.049 μs 5.15 ± 0.05 μs 0.994 ± 0.014
time_to_load 0.0765 ± 0.00047 s 0.0769 ± 0.0012 s 0.994 ± 0.017
Memory benchmarks
main acfbfa0... main / acfbfa0...
adt_transform/transform n=100 0.204 k allocs: 6.34 kB 0.204 k allocs: 6.34 kB 1
adt_transform/transform n=1000 2.02 k allocs: 0.0619 MB 2.02 k allocs: 0.0619 MB 1
linked_list/sum n=100 0 allocs: 0 B 0 allocs: 0 B
linked_list/sum n=1000 0 allocs: 0 B 0 allocs: 0 B
time_to_load 0.145 k allocs: 11 kB 0.145 k allocs: 11 kB 1

@Roger-luo
Roger-luo merged commit d66ec45 into main Jul 12, 2026
8 checks passed
@Roger-luo
Roger-luo deleted the fix/docs-npm-audit branch July 12, 2026 18:16

This branch was successfully deployed

1 active deployment
Preview — acfbfa0f Deployed Jul 12, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant