chore: declare package as private with license and engines#644
chore: declare package as private with license and engines#644mesutoezdil wants to merge 6 commits into
Conversation
Refreshed against latest master to cover advisories published through Jul 21. Resolves 20 of 47 npm audit findings including both critical ones. Remaining findings need breaking upgrades in the Docusaurus toolchain. Signed-off-by: mesutoezdil <[email protected]>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: mesutoezdil The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
✅ Deploy Preview for project-hami ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Warning Review limit reached
Next review available in: 59 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR updates the repository’s npm metadata to better reflect that this is a Docusaurus website (not a publishable package), align licensing metadata with the repo, and document/enforce the required Node.js runtime version.
Changes:
- Mark the package as non-publishable (
private: true) and declare the required Node runtime viaengines.node. - Declare the project license in npm metadata (
CC-BY-4.0). - (From stacked changes visible in this diff) remove unused dependencies and add
overridespins for select transitive dependencies.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| package.json | Declares private, license, and engines, and (in stacked changes) removes unused deps and adds overrides. |
| package-lock.json | Updates root package metadata (e.g., license, engines) and reflects the resolved dependency tree. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
1c41be5 to
6cf5b8c
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.
Comments suppressed due to low confidence (1)
package.json:80
package.jsonends with an extra whitespace-only line (line 80). This will typically causeprettier --check .to fail because Prettier removes trailing whitespace/extra blank lines at EOF.
}
Add npm overrides scoped to the parents that need them, pinned to exact versions: js-yaml, markdown-it and run-con under markdownlint-cli, serialize-javascript under copy-webpack-plugin and css-minimizer-webpack-plugin, and uuid under sockjs. Scoping keeps unrelated subtrees on their own versions. markdownlint-cli stays at 0.48.0 and run-con at 1.3.2 because their newer releases pull deps requiring Node 22 while CI runs Node 20. npm audit now reports 0 vulnerabilities. Signed-off-by: mesutoezdil <[email protected]>
asciinema-player and react-github-btn are not imported anywhere in the site code. gh-pages is unused since deployment moved to Netlify. Fewer dependencies means a smaller vulnerability surface. Signed-off-by: mesutoezdil <[email protected]>
502 entries pointed at registry.npmmirror.com, a third party mirror, so every install fetched tarballs from it. Rewritten to registry.npmjs.org and verified with a clean npm ci, which checks every integrity hash against the official tarballs. Signed-off-by: mesutoezdil <[email protected]>
private: true prevents an accidental npm publish of the site source. The license field matches the repo LICENSE (CC-BY-4.0) and engines declares Node >=20.18.1, the minimum required by transitive deps such as undici and cheerio, which CI and Netlify already satisfy. Signed-off-by: mesutoezdil <[email protected]>
6cf5b8c to
42330be
Compare
Note
Stacked on #556 -> #630 -> #641 -> #643; until those merge their changes appear in this diff too. The change specific to this PR is in
package.jsonplus the matching lockfile root entry (last commit).What
Three metadata fixes in
package.json:"private": true: this is a website, not a publishable npm package; the previous"private": falsewith an org-scoped name meant an accidentalnpm publishwould upload the whole site source to the public registry"license": "CC-BY-4.0": matches the repoLICENSEfile; the missing field is also why regenerated lockfiles keep churning on the root license entry (seen in Add Events page from Google Calendar #632)"engines": { "node": ">=20.18.1" }: the minimum Node required by transitive deps in the lockfile (undici, cheerio); CI and Netlify already run recent Node 20, this makes npm warn contributors on older Node instead of failing mysteriouslyTesting
npm installsyncs the lockfile root entry cleanly, prettier passes,npm auditstill 0Part of #628