Conversation
Bump the pinned floors in the resolutions block to pull in upstream fixes: - brace-expansion: ^2.1.3 -> ^2.1.4 (now resolves to 2.1.7) - decode-uri-component: ^0.2.2 -> ^0.5.0 The brace-expansion floor mattered independently of the installed version: 2.1.3 satisfied the old pin but is missing an upstream fix that only landed in 2.1.4, so the range permitted a resolve we do not want. Note: decode-uri-component 0.5.0 is ESM-only (export default), while its only consumer, query-string@7, is CommonJS and uses require(). Vite/Rollup resolves that interop at bundle time and the production build was verified to parse normally, but a plain esbuild or bare Node require() of the package yields the namespace object rather than a callable.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The decode-uri-component upgrade introduces an unresolved ESM/CommonJS compatibility risk for query-string.
Review effort: Lite
Findings: 1
What changed in this PR
Raises frontend dependency resolution floors to receive upstream fixes.
Changes:
- Updates
brace-expansionto^2.1.4. - Updates
decode-uri-componentto^0.5.0. - Refreshes the Yarn lockfile.
| File | Summary |
|---|---|
src/gprofiler/frontend/package.json |
Updates dependency resolution floors. |
src/gprofiler/frontend/yarn.lock |
Locks the updated package versions and integrity hashes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "browserslist": "^4.28.7", | ||
| "nanoid": "^3.3.18", | ||
| "decode-uri-component": "^0.2.2", | ||
| "decode-uri-component": "^0.5.0", |
Contributor
There was a problem hiding this comment.
Restored decode-uri-component@^0.2.2 and its lockfile entry to keep the existing query-string@7 consumer CommonJS-compatible. Verified with a runtime parse smoke check and frontend build. Commit: e580a3d.
| "diff": "^5.2.2", | ||
| "yaml": "^2.8.3", | ||
| "brace-expansion": "^2.1.3", | ||
| "brace-expansion": "^2.1.4", |
mlim19
force-pushed
the
update_dependent_components
branch
from
September 28, 2026 23:16
e580a3d to
f047ae2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Bump the pinned floors in the resolutions block to pull in upstream fixes:
The brace-expansion floor mattered independently of the installed version: 2.1.3 satisfied the old pin but is missing an upstream fix that only landed in 2.1.4, so the range permitted a resolve we do not want.
Note: decode-uri-component 0.5.0 is ESM-only (export default), while its only consumer, query-string@7, is CommonJS and uses require(). Vite/Rollup resolves that interop at bundle time and the production build was verified to parse normally, but a plain esbuild or bare Node require() of the package yields the namespace object rather than a callable.
Description
Related Issue
Motivation and Context
How Has This Been Tested?
Screenshots
Checklist: