Skip to content

Upgrade dependencies and fix vulnerabilities - #16

Merged
KennethWussmann merged 3 commits into
mainfrom
task/upgrade-deps-20260913-230144
Sep 13, 2026
Merged

KennethWussmann merged 3 commits into
mainfrom
task/upgrade-deps-20260913-230144

Conversation

@KennethWussmann

Copy link
Copy Markdown
Owner

WHY

Routine dependency maintenance. Everything is on latest, the two toml advisories are gone, and the repo actually lints again.

The lint script was broken on main with 211 errors, so there was no green baseline to upgrade against. First commit fixes that, the other two are the actual maintenance.

WHAT

Upgrades

Package From To
@oclif/core 4.8.0 5.0.0
@oclif/plugin-help 6.2.37 7.0.0
@oclif/test 4.1.16 5.0.0
oclif 4.22.68 6.0.0
eslint 9.39.2 10.10.0
eslint-config-oclif 6.0.133 7.1.7
mocha 11.7.5 12.0.1
typescript 5.9.3 6.0.3
@types/chai 4.3.20 5.2.3
@types/node 25.0.10 26.5.1
simplelogin-client 0.5.1 0.6.0
Minor and patch bumps
Package From To
@inquirer/prompts 8.1.0 8.7.2
yaml 2.8.2 2.9.1
@eslint/compat 1.4.1 2.1.1
chai 4.5.0 6.2.2
eslint-config-prettier 10.x 10.1.8
shx 0.3.4 0.4.0
ts-node 10.x 10.9.2

@eslint/compat, chai and shx were already behind their declared ranges in the lockfile, the install picked them up on the way.

Code changes required by the upgrades

  • tsconfig.json: added "types": ["node"]. TypeScript 7 (and 6 in the same layout) no longer pulls in every @types package automatically, so node:fs and friends stopped resolving. Verified with a scratch project that it's not a pnpm symlink thing.
  • src/commands/alias/delete.ts: dropped node:readline/promises for confirm from @inquirer/prompts. The new n/no-unsupported-features/node-builtins rule flags it against engines.node >=18, and we already use inquirer in sl login anyways.
  • src/commands/alias/alias-list-base.ts: the --all pagination loop became recursion because of no-await-in-loop, a dead getFormat() that always returned plain is gone, and the require('yaml') inside the yaml branch is a real import now. That require would have thrown in ESM, so sl alias list --format yaml --all was broken before.
  • src/utils/simplelogin-client.ts: null returns became undefined, the type said one thing and the code did the other after the autofix.
  • src/commands/login.ts, src/utils/config.ts and the rest: mostly ?? over ||, ??=, error cause, import sorting. Bulk of it is eslint --fix.
  • README.md is regenerated by prepack, the v0.2.0 source links in it were stale since the last two releases.

Security

Advisory Package Severity Resolution
GHSA-82x6-q7mm-w9cf toml high override toml@<4.2.0 to >=4.2.0
GHSA-v5mp-jgw5-2x6j toml high same override

toml comes in via markdown-toc > gray-matter, both of which are direct-upgrade dead ends, hence the override. pnpm audit --fix wanted two overlapping entries, I kept the one that subsumes the other. pnpm audit is clean now and prepack still produces the same TOC.

Still open

Item Current Wanted Blocker
typescript 6.0.3 7.0.2 typescript-eslint 8.70 refuses to load on TS 7 and tracks support for TS >=7.1 in typescript-eslint#10940. Build itself is fine on 7.
markdown-toc 1.2.0 - Latest is from 2022 and drags in coffee-script, gulp-header and lodash.template, all deprecated. Only used in prepack, so I'd say we replace it somewhen rather than in this PR.
eslint-plugin-import 2.32.0 - Peer range stops at eslint 9, install warns. Pulled in transitively by eslint-import-resolver-typescript, lint works.
unrs-resolver build script - - pnpm 10 blocks its postinstall. Left unapproved, the prebuilt binaries are enough and lint passes.

Verification

There are no test files in the repo and pnpm test is commented out in CI, so this is build plus lint plus the release pipeline.

  • pnpm install --frozen-lockfile - pass
  • pnpm run build - pass
  • pnpm run lint - pass (was 211 errors on main)
  • pnpm run prepack / postpack - pass
  • pnpm run pack:tarballs - pass, 6 targets built with oclif 6
  • pnpm audit - clean
  • ./bin/run.js --version, help, alias list --help, config, whoami - pass

Written by Claude Opus 5 via Pi

KennethWussmann and others added 3 commits September 13, 2026 23:01
Co-authored-by: Claude Opus 5 via [Pi](https://pi.dev/) <noreply@pi.dev>
Co-authored-by: Claude Opus 5 via [Pi](https://pi.dev/) <noreply@pi.dev>
Co-authored-by: Claude Opus 5 via [Pi](https://pi.dev/) <noreply@pi.dev>
@KennethWussmann
KennethWussmann marked this pull request as ready for review September 13, 2026 21:10
@KennethWussmann
KennethWussmann merged commit f4fefcb into main Sep 13, 2026
1 check passed
@KennethWussmann
KennethWussmann deleted the task/upgrade-deps-20260913-230144 branch September 13, 2026 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant