Update JavaScript dependencies - #524
Merged
Merged
Conversation
kieran-osgood-shopify
added this pull request to stack #528
September 17, 2026 10:06
kieran-osgood-shopify
force-pushed
the
dependency-sweep/javascript
branch
2 times, most recently
from
October 1, 2026 10:52
acee012 to
479a344
Compare
kieran-osgood-shopify
removed this pull request from stack #528
October 1, 2026 10:53
kieran-osgood-shopify
added this pull request to stack #538
October 1, 2026 10:53
kieran-osgood-shopify
marked this pull request as ready for review
October 1, 2026 12:26
josemiguel-alvarez
approved these changes
Oct 2, 2026
## Summary Bottom layer of the dependency-cleanup stack: JavaScript → Ruby/CocoaPods → Android → React Native/sample → CI. - Update Babel core/preset-env to 7.29.7 and the React Native CLI family to 19.1.2; refresh vulnerable transitive dependencies in the current pnpm lockfile. - Upgrade Turbo to 2.9.18, migrate `pipeline` to `tasks`, and preserve existing environment forwarding with loose mode. - Scope fast-xml-parser 5.7.0 overrides to the Android/iOS CLI consumers. Patch query-string's decoder import so it can use the fixed decode-uri-component 0.5.0 without changing React Navigation's API. - Add seven compatibility tests, including the malformed-URL stack-overflow regression, and run the complete Jest suite in CI. React 19.1.0, React Native 0.80.2, and native dependency versions are unchanged in this layer. ## Security status The resolved graph addresses all 52 npm alerts in the [GitHub alert baseline](https://github.com/Shopify/checkout-sheet-kit-react-native/security/dependabot?q=is%3Aopen+ecosystem%3Anpm). These close only after the fixes reach the default branch and GitHub refreshes its dependency graph. The public npm audit decreases from **71 findings to 2 high findings**, with no critical findings remaining. The remaining Metro → image-size advisories are not dismissed or ignored: - GHSA-w3rx-r6r6-pgpr - GHSA-5p2g-fcmc-qvqq Both currently advertise no patched version. Metro expects the image-size 1.x API, so a 2.x override also needs separate compatibility validation. Ruby alerts are reserved for the next stack layer. ## Supersedes Closes #385 Closes #446 Closes #451 Closes #454 Closes #459 Closes #471 Closes #477 Closes #485 Confirm these bot PRs close after landing; do not treat a closed PR as proof that its security alerts are resolved. ## Validation - 130 tests pass across seven suites. - Frozen-lockfile install, TypeScript/ESLint, license checks, module build, API report, and package snapshot pass. The sample retains its existing inline-style warning. - Release-mode Metro bundles succeed for iOS and Android. The React Native CLI discovers Checkout Kit on both platforms. - No manual device sweep yet; perform it once from the completed stack tip. ## How to test **GIVEN** the sample app is configured for a development storefront with products available for purchase **WHEN** you start Metro, build and launch the sample on iOS and Android, browse Catalog → product details → Cart, visit Settings, then open and dismiss checkout **THEN** builds succeed, images and navigation work, and checkout opens and returns to the sample without new runtime errors; behavior should match the base branch Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6
Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6
Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6
kieran-osgood-shopify
force-pushed
the
dependency-sweep/javascript
branch
from
October 2, 2026 09:30
479a344 to
99c4687
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes are you making?
Bottom layer of the dependency-cleanup stack: JavaScript → Ruby/CocoaPods → Android → React Native/sample → CI.
pipelinetotasks, and preserve existing environment forwarding with loose mode.React 19.1.0, React Native 0.80.2, and native dependency versions are unchanged in this layer.
Security status
The resolved graph addresses all 52 npm alerts in the GitHub alert baseline. These close only after the fixes reach the default branch and GitHub refreshes its dependency graph.
The public npm audit decreases from 71 findings to 2 high findings, with no critical findings remaining. The remaining Metro → image-size advisories are not dismissed or ignored:
Both currently advertise no patched version. Metro expects the image-size 1.x API, so a 2.x override also needs separate compatibility validation. Ruby alerts are reserved for the next stack layer.
Supersedes
Closes #385
Closes #446
Closes #451
Closes #454
Closes #459
Closes #471
Closes #477
Closes #485
Confirm these bot PRs close after landing; do not treat a closed PR as proof that its security alerts are resolved.
PR Checklist
Important
Releasing a new version of the kit?
package.jsonfile.Tip
See the Contributing documentation for instructions on how to publish a new version of the library.