fix(deps): pin webpack and diff, scope npm pins per lockfile - #917
Merged
Merged
Conversation
Closes the three Scorecard vulnerability warnings left open by the previous npm pin pass: GHSA-73rr-hh4g-fpgx diff 7.0.0 -> 8.0.3 GHSA-8fgc-7cc6-rx7x webpack 5.101.3 -> 5.104.1 GHSA-38r7-794h-5758 webpack 5.101.3 -> 5.104.1 Both are overrides Yarn warns about and applies. webpack overrides KGP's own exact pin, so the bundler now runs ahead of the version the Kotlin toolchain was tested against; the catalog entry says to re-check on every Kotlin upgrade and drop the pin once KGP passes 5.104.1. diff 7 -> 8 is a semver-major override of a mocha-only dependency. Pinning webpack unscoped grew kotlin-js-store/wasm/yarn.lock by 520 lines -- webpack's whole tree landing in a lockfile that bundles nothing with webpack. Yarn writes an entry for every resolutions key whether or not the graph requests the package, and npmPins applied every pin to both Yarn roots. So pin() now takes an optional NpmPinTarget: pin("ws", libs.versions.npm.ws) // both pin("webpack", libs.versions.npm.webpack, NpmPinTarget.JS) // JS only No target still means both, so existing declarations keep their meaning. The extension exposes jsPins/wasmPins instead of one flat map, the plugin feeds each Yarn root only its own pins, and verifyNpmPins checks each lockfile against its own pin map so a scoped pin is never reported missing from a lockfile it was never meant to reach. kotlin-js-store/wasm/yarn.lock is now byte-identical to develop again, which also retires the phantom entries the previous pass added to it. Verified with kotlinUpgradeYarnLock, kotlinWasmUpgradeYarnLock, verifyNpmPins, jsTest, wasmJsTest and wasmWasiTest.
|
📖 Documentation Preview The documentation has been built successfully for this PR. Generated Files:
Artifacts:
This comment will be updated automatically when the PR is updated. |
aharakal
approved these changes
Aug 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the three Scorecard
Vulnerabilitieswarnings left open by #913:diffwebpackwebpackFollows #913, which is now merged — this branch is a single commit on top of it.
The two pins
diffwebpackBoth are overrides that Yarn warns about and applies:
webpackoverrides KGP's own exact pin. The Kotlin Gradle plugin pinswebpack@5.101.3for Kotlin 2.4.10, so this deliberately runs the bundler ahead of the version the Kotlin toolchain was tested against. The catalog entry carries a note to re-check the pin on every Kotlin upgrade and drop it once KGP's own webpack passes 5.104.1, rather than silently holding the bundler back.diff7 → 8 is a semver-major override of whatmocha@11.7.5requests.diffis a mocha-only dependency used for assertion output.jsTest,wasmJsTestandwasmWasiTestall pass on both, which is what makes these safe rather than merely plausible.Why this also changes the npm-pins plugin
Pinning
webpackunscoped grewkotlin-js-store/wasm/yarn.lockby 520 lines / 76 packages — webpack's entire tree (@webassemblyjs/*,acorn,ajv,terser,browserslist, …) landing in a lockfile that bundles nothing with webpack. Yarn writes an entry for everyresolutionskey whether or not that graph requests the package, andnpmPinsapplied every pin to both Yarn roots.That was tolerable at #913's scale (~10 phantom packages); at 76 it means the wasm CI job downloads and installs a bundler it never runs, and Dependabot starts reporting those packages against a lockfile that never uses them.
So
pin()now takes an optional target:NpmPinTargetenum (JS,WASM); no target means both, so every existing call keeps its meaning.NpmPinsExtensionnow exposesjsPins/wasmPinsinstead of one flatpinsmap.NpmPinsPluginfeeds each Yarn root only the pins scoped to it.VerifyNpmPinsTaskchecks each lockfile against its own pin map, so a scoped pin is never reported as missing from a lockfile it was never meant to reach.Net effect on the wasm lockfile:
kotlin-js-store/wasm/yarn.lockgoes back to its singlewsentry — identical to what it held before #913. That PR added 59 phantom lines to it as a documented, accepted tradeoff; this one removes them, so the tradeoff no longer has to be accepted.wsis the only pinned package present in both graphs and stays unscoped; the other seven are JS-only.Docs
docs/modules/ROOT/pages/contributing/build-from-source.adocgains a "Scoping a pin to one lockfile" subsection under the existing Pinning npm Packages section, including thegrep -c '^webpack@' …check for deciding whether a pin needs a scope.Verification