Skip to content

fix(deps): pin sass and select2 to restore the release build - #2384

Merged
thostetler merged 1 commit into
adsabs:masterfrom
thostetler:fix/pin-sass-select2-build
Oct 1, 2026
Merged

thostetler merged 1 commit into
adsabs:masterfrom
thostetler:fix/pin-sass-select2-build

Conversation

@thostetler

@thostetler thostetler commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

The release build broke on Node 18/20 with ERR_REQUIRE_ESM from sass's chokidar
dependency, and separately on select2 floating to a version that requires Node
>=24 and drops a file grunt needs.

  • sass pinned to ~1.99.0 (last version with a dual CJS/ESM chokidar); select2
    pinned to ~4.0.13 (last 4.0.x, still ships compat/matcher.js).
  • Added yarn.lock. The repo mandates Yarn 1.x but only tracked
    package-lock.json, so Yarn ignored it and re-resolved every caret range on
    each deploy. That is the root cause of both floats.

sass floated past 1.100.0, which pulls in chokidar ^5 (ESM-only).
grunt's sass task does a CommonJS require() of it, which throws
ERR_REQUIRE_ESM on Node 18 and 20. Pin to ~1.99.0, the newest
version with a dual CJS/ESM chokidar.

select2 floated to 4.1.0, which requires Node >=24 (a hard error
under Yarn 1) and dropped compat/matcher.js, which copy:libs
needs; grunt-contrib-copy silently skips the missing file instead
of failing, so the break only surfaced later as an ENOENT in
generateBundles. Pin to ~4.0.13, the last 4.0.x release.

Both floats were possible because the repo had no yarn.lock, so
Yarn 1 ignored the committed package-lock.json and re-resolved
every caret range on each deploy. Adding yarn.lock here.
@thostetler
thostetler marked this pull request as ready for review October 1, 2026 18:15
Copilot AI balanced review requested due to automatic review settings October 1, 2026 18:15
@thostetler
thostetler merged commit 5d0e206 into adsabs:master Oct 1, 2026
1 check passed
@thostetler
thostetler deleted the fix/pin-sass-select2-build branch October 1, 2026 18:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

馃數 Needs a closer look

The newly locked dependency graph updates many packages beyond the two targeted dependencies and warrants a verified release build.

Review effort: Balanced
Findings: None

What changed in this PR

Pins compatible Sass and Select2 release lines and introduces deterministic Yarn dependency resolution.

Changes:

  • Restricts Sass and Select2 to compatible minor versions.
  • Updates npm resolution metadata.
  • Adds a Yarn 1 lockfile for reproducible deployments.
File Description
package.json Restricts Sass and Select2 versions.
package-lock.json Updates npm鈥檚 resolved dependency graph.
yarn.lock Locks Yarn鈥檚 complete dependency graph.

馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants