Skip to content

Update Docusaurus and the documentation dependencies - #91

Merged
beetlebugorg merged 1 commit into
mainfrom
deps/docusaurus
Aug 28, 2026
Merged

beetlebugorg merged 1 commit into
mainfrom
deps/docusaurus

Conversation

@beetlebugorg

Copy link
Copy Markdown
Owner

What changes

Every open npm alert sits in docs/package-lock.json. None reaches the service. They are the Docusaurus build for the documentation site.

  • Move @docusaurus/* from 3.7.0 to 3.10.2.
  • Raise node-version to 22 in docs-pr.yml and docs-deploy.yml, and engines.node to >=20.0. Docusaurus 3.10 declares node >=20, and both workflows pinned 18.
  • Move onBrokenMarkdownLinks under markdown.hooks. The old position is deprecated and is removed in Docusaurus 4.
  • Override serialize-javascript and uuid. Docusaurus 3.10.2 still resolves 6.0.2 and 8.3.2 through its webpack tooling, and neither closes on the version bump alone.

npm audit goes from 31 findings, 1 low and 15 moderate and 15 high, to 17, all high and all one root cause.

What this closes

package needed before after
@babel/core 7.29.6 7.27.1 7.29.7 closed
http-proxy-middleware 2.0.10 2.0.9 2.0.10 closed
joi 17.13.4 17.13.3 17.13.6 closed
minimatch 3.1.4 3.1.2 3.1.5 closed
path-to-regexp 0.1.13 0.1.12 0.1.13 closed
picomatch 2.3.2 2.3.1 2.3.2 closed
webpack-dev-server 5.2.6 4.15.2 5.2.6 closed
serialize-javascript 7.0.5 6.0.2 7.1.0 closed by override
uuid 11.1.1 8.3.2 11.1.1 closed by override
image-size 1.2.1 2.0.2 stays open

image-size stays open because no patched release exists. Its advisory names <= 2.0.2 with no fixed version, and 2.0.2 is the newest release. Docusaurus calls it at build time to size local images, so the input is the repository's own files.

Verify

npm ci and npm run build both succeed on Node 22, which is what the workflows now use. The deprecation warning is gone after the config move.

The rendered site is compared against a Docusaurus 3.7.0 build from main on Node 18. Both produce the same 30 pages. The visible text is identical on 29 of them. The one difference is the home page title, which 3.10 no longer doubles:

- go-dims | go-dims
+ go-dims

The two overrides were checked separately for behavior change. Building with and without them gives a byte-identical file set and 30 byte-identical HTML pages.

- Move the Docusaurus packages to 3.10.2.
- Raise the Node version to 22, which 3.10 requires.
- Move onBrokenMarkdownLinks under the markdown hooks.
- Override serialize-javascript and uuid to patched releases.
@beetlebugorg
beetlebugorg merged commit 96eed64 into main Aug 28, 2026
1 check passed
@beetlebugorg
beetlebugorg deleted the deps/docusaurus branch August 28, 2026 00:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant