chore: upgrade workflows and update dependencies - #214
borisonekenobi wants to merge 27 commits into
Conversation
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [json-schema-to-typescript](https://github.com/bcherny/json-schema-to-typescript) from 13.1.2 to 16.0.0. - [Changelog](https://github.com/bcherny/json-schema-to-typescript/blob/master/CHANGELOG.md) - [Commits](https://github.com/bcherny/json-schema-to-typescript/commits) --- updated-dependencies: - dependency-name: json-schema-to-typescript dependency-version: 16.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@angular-devkit/schematics](https://github.com/angular/angular-cli) from 18.0.7 to 22.2.1. - [Release notes](https://github.com/angular/angular-cli/releases) - [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md) - [Commits](angular/angular-cli@18.0.7...v22.2.1) --- updated-dependencies: - dependency-name: "@angular-devkit/schematics" dependency-version: 22.2.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rimraf](https://github.com/isaacs/rimraf) from 5.0.10 to 6.1.3. - [Changelog](https://github.com/isaacs/rimraf/blob/main/CHANGELOG.md) - [Commits](isaacs/rimraf@v5.0.10...v6.1.3) --- updated-dependencies: - dependency-name: rimraf dependency-version: 6.1.3 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.6 to 5.0.3. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 5.0.3 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.26.0 to 6.29.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v6.26.0...v6.29.0) --- updated-dependencies: - dependency-name: undici dependency-version: 6.29.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.7.3. - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.7.3) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.7.3 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.8. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.2...v3.1.8) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.8 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.24 to 4.13.13. - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.24...v4.13.13) --- updated-dependencies: - dependency-name: hono dependency-version: 4.13.13 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the angular group with 2 updates in the /src directory: [@angular-devkit/architect](https://github.com/angular/angular-cli) and [@angular-devkit/core](https://github.com/angular/angular-cli). Updates `@angular-devkit/architect` from 0.1800.7 to 0.2202.1 - [Release notes](https://github.com/angular/angular-cli/releases) - [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md) - [Commits](https://github.com/angular/angular-cli/commits) Updates `@angular-devkit/core` from 18.0.7 to 22.2.1 - [Release notes](https://github.com/angular/angular-cli/releases) - [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md) - [Commits](angular/angular-cli@18.0.7...v22.2.1) --- updated-dependencies: - dependency-name: "@angular-devkit/architect" dependency-version: 0.2202.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: angular - dependency-name: "@angular-devkit/core" dependency-version: 22.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: angular ... Signed-off-by: dependabot[bot] <support@github.com>
…it/core dependency in package-lock.json
Bumps and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together. Updates `brace-expansion` from 5.0.6 to 5.0.12 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.12) Updates `brace-expansion` from 1.1.15 to 1.1.21 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.12) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 1.1.21 dependency-type: indirect - dependency-name: brace-expansion dependency-version: 5.0.12 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.2 to 6.16.0. - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.15.2...v6.16.0) --- updated-dependencies: - dependency-name: qs dependency-version: 6.16.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Removes [pacote](https://github.com/npm/pacote). It's no longer used after updating ancestor dependency [@angular/cli](https://github.com/angular/angular-cli). These dependencies need to be updated together. Removes `pacote` Updates `@angular/cli` from 22.0.0 to 22.2.1 - [Release notes](https://github.com/angular/angular-cli/releases) - [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md) - [Commits](angular/angular-cli@v22.0.0...v22.2.1) --- updated-dependencies: - dependency-name: "@angular/cli" dependency-version: 22.2.1 dependency-type: indirect - dependency-name: pacote dependency-version: dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.2.2 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v5.2.2...v7.0.2) --- updated-dependencies: - dependency-name: typescript dependency-version: 6.0.3 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 24.13.1 to 26.6.3. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.6.3 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
This reverts commit a698629.
| interval: "weekly" | ||
| day: "sunday" | ||
| time: "09:00" | ||
| timezone: "America/Toronto" |
There was a problem hiding this comment.
Since this project is Europe-based, we should set this to Europe/Berlin
| "module": "commonjs", | ||
| "moduleResolution": "node", | ||
| "module": "node16", | ||
| "moduleResolution": "node16", |
There was a problem hiding this comment.
What is the reason to set this to "node16" specifically?
There was a problem hiding this comment.
Typescript v6 removes node as an available moduleResolution, and the suggested fix by GitHub Copilot was node16, other than that, no opinion on specific module or moduleResolution
| - package-ecosystem: "npm" | ||
| directory: "/src/" | ||
| schedule: | ||
| interval: "weekly" |
There was a problem hiding this comment.
We release this tool in a much larger interval, so I suggest monthly dep updates. Everything shorter than this is highly annoying for maintainers.
|
Thanks for the PR, @borisonekenobi 😊 |
|
Hi @borisonekenobi, thank you so much for this PR and for taking the time to work through the review feedback! 🙏 The code changes are great: the class-based Dependabot is where I have a real stomachache, though. Supply-chain attacks have become a huge problem in the npm ecosystem, and according to GitHub, 66,408 repositories depend on angular-cli-ghpages. Every dependency change I ship ends up in all of those build pipelines, and I take that responsibility seriously. That's why I've deliberately cut down the dependency footprint over time. I even inlined and slimmed down former dependencies so there's less code from third parties in the chain. My approach: outdated dependencies on their own aren't a problem. If there's a security finding, it gets handled right away. Otherwise I update dependencies by hand before each release, alongside Angular/AngularFire, and test everything together. A bot that continuously bumps versions works against that. The devDependencies are also intentionally pinned to the lowest supported Angular version (18), so the build always runs against the minimum the package claims to support (see So would you mind trimming the PR down to the code changes? Concretely:
That leaves the Thanks again, contributions like this are really appreciated! 😊 |
|
Thanks for the detailed feedback. I understand the concern, especially given how many downstream projects use the package and the responsibility that comes with changing its dependency chain. I can trim the PR as requested, but I wanted to point out a few details first. Not all of the dependency updates in this PR are just version bumps. Some of them resolve security vulnerabilities that Dependabot found. The updates reduce the reported vulnerabilities from 83 to 1. (link to resolved vulnerabilities) The remaining vulnerability hasn't been resolved in the upstream packages yet, so there is currently no update that can address it (and, unfortunately, that vulnerability is also what originally prompted me to start this PR). With that in mind, I wanted to suggest a slightly different approach:
If you would still prefer to remove Dependabot completely, that is fine too. I want to flag this before we remove everything, as we may be able to keep the security benefits without continuous dependency updates. Either way, I can make the changes and get the PR into a state you are comfortable merging. |
This pull request introduces several improvements to CI/CD automation, dependency management, and code quality. The main changes include adding Dependabot configuration for automated dependency updates, upgrading GitHub Actions to the latest major versions, updating development dependencies to their latest versions, and making minor code and test improvements for better type safety and maintainability.
CI/CD and Dependency Management Improvements:
.github/dependabot.ymlfile to enable automated dependency updates for both npm and GitHub Actions, scheduled weekly.main.yml,npm-publish.yml) to the latest major versions (actions/checkout@v7,actions/setup-node@v7,actions/upload-artifact@v7,actions/download-artifact@v8). [1] [2] [3] [4] [5]Development Dependency Updates:
src/package.jsonto their latest major versions, including@angular-devkit/*,@types/node,json-schema-to-typescript,rimraf,typescript, andvitest.src/tsconfig.jsonto usemodule: node16andmoduleResolution: node16for better compatibility with newer Node.js and TypeScript versions.Testing and Type Improvements:
gh-pages/lib/gitinengine.gh-pages-integration.spec.tsto use a class-based mock, increasing test clarity and maintainability.engine.spec.tsto check for the correct repository path (borisonekenobi/angular-cli-ghpages).beforeAddhook inPublishOptionsby specifying the correctGhPagesGittype and adding the import insrc/interfaces.ts. [1] [2]src/ng-add.tsfor better type safety when selecting the default project.