Update Docusaurus and the documentation dependencies - #91
Merged
Merged
Conversation
- Move the Docusaurus packages to 3.10.2. - Raise the Node version to 22, which 3.10 requires. - Move onBrokenMarkdownLinks under the markdown hooks. - Override serialize-javascript and uuid to patched releases.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
Every open npm alert sits in
docs/package-lock.json. None reaches the service. They are the Docusaurus build for the documentation site.@docusaurus/*from 3.7.0 to 3.10.2.node-versionto 22 indocs-pr.ymlanddocs-deploy.yml, andengines.nodeto>=20.0. Docusaurus 3.10 declaresnode >=20, and both workflows pinned 18.onBrokenMarkdownLinksundermarkdown.hooks. The old position is deprecated and is removed in Docusaurus 4.serialize-javascriptanduuid. Docusaurus 3.10.2 still resolves 6.0.2 and 8.3.2 through its webpack tooling, and neither closes on the version bump alone.npm auditgoes from 31 findings, 1 low and 15 moderate and 15 high, to 17, all high and all one root cause.What this closes
@babel/corehttp-proxy-middlewarejoiminimatchpath-to-regexppicomatchwebpack-dev-serverserialize-javascriptuuidimage-sizeimage-sizestays open because no patched release exists. Its advisory names<= 2.0.2with no fixed version, and 2.0.2 is the newest release. Docusaurus calls it at build time to size local images, so the input is the repository's own files.Verify
npm ciandnpm run buildboth succeed on Node 22, which is what the workflows now use. The deprecation warning is gone after the config move.The rendered site is compared against a Docusaurus 3.7.0 build from
mainon Node 18. Both produce the same 30 pages. The visible text is identical on 29 of them. The one difference is the home page title, which 3.10 no longer doubles:The two overrides were checked separately for behavior change. Building with and without them gives a byte-identical file set and 30 byte-identical HTML pages.