Skip to content

Raise resolution floors for two frontend transitive dependencies - #141

Open
mlim19 wants to merge 1 commit into
masterfrom
update_dependent_components
Open

mlim19 wants to merge 1 commit into
masterfrom
update_dependent_components

Conversation

@mlim19

@mlim19 mlim19 commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bump the pinned floors in the resolutions block to pull in upstream fixes:

  • brace-expansion: ^2.1.3 -> ^2.1.4 (now resolves to 2.1.7)
  • decode-uri-component: ^0.2.2 -> ^0.5.0

The brace-expansion floor mattered independently of the installed version: 2.1.3 satisfied the old pin but is missing an upstream fix that only landed in 2.1.4, so the range permitted a resolve we do not want.

Note: decode-uri-component 0.5.0 is ESM-only (export default), while its only consumer, query-string@7, is CommonJS and uses require(). Vite/Rollup resolves that interop at bundle time and the production build was verified to parse normally, but a plain esbuild or bare Node require() of the package yields the namespace object rather than a callable.

Description

Related Issue

Motivation and Context

How Has This Been Tested?

Screenshots

Checklist:

  • I have updated the relevant documentation.
  • I have added tests for new logic.

Bump the pinned floors in the resolutions block to pull in upstream fixes:

- brace-expansion: ^2.1.3 -> ^2.1.4 (now resolves to 2.1.7)
- decode-uri-component: ^0.2.2 -> ^0.5.0

The brace-expansion floor mattered independently of the installed version:
2.1.3 satisfied the old pin but is missing an upstream fix that only landed
in 2.1.4, so the range permitted a resolve we do not want.

Note: decode-uri-component 0.5.0 is ESM-only (export default), while its
only consumer, query-string@7, is CommonJS and uses require(). Vite/Rollup
resolves that interop at bundle time and the production build was verified
to parse normally, but a plain esbuild or bare Node require() of the
package yields the namespace object rather than a callable.
@mlim19
mlim19 requested review from dkorlovs and a lite review from Copilot September 28, 2026 17:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The decode-uri-component upgrade introduces an unresolved ESM/CommonJS compatibility risk for query-string.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Raises frontend dependency resolution floors to receive upstream fixes.

Changes:

  • Updates brace-expansion to ^2.1.4.
  • Updates decode-uri-component to ^0.5.0.
  • Refreshes the Yarn lockfile.
File Summary
src/​gprofiler/​frontend/​package.json Updates dependency resolution floors.
src/​gprofiler/​frontend/​yarn.lock Locks the updated package versions and integrity hashes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

"browserslist": "^4.28.7",
"nanoid": "^3.3.18",
"decode-uri-component": "^0.2.2",
"decode-uri-component": "^0.5.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Restored decode-uri-component@^0.2.2 and its lockfile entry to keep the existing query-string@7 consumer CommonJS-compatible. Verified with a runtime parse smoke check and frontend build. Commit: e580a3d.

@mlim19
mlim19 added this pull request to stack #143 September 28, 2026 22:47
Copilot AI review requested due to automatic review settings September 28, 2026 22:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The changes are limited and no blocking issues were identified; only a minor description update was noted.

Review effort: Lite
Findings: 1 Low severity

Open (1)
Resolved since last review (1)

"diff": "^5.2.2",
"yaml": "^2.8.3",
"brace-expansion": "^2.1.3",
"brace-expansion": "^2.1.4",
@mlim19
mlim19 force-pushed the update_dependent_components branch from e580a3d to f047ae2 Compare September 28, 2026 23:16
Copilot AI review requested due to automatic review settings September 28, 2026 23:16

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Resolve the decode-uri-component runtime compatibility issue and add appropriate validation.

Review effort: Lite
Findings: 1 High severity · 1 Low severity

Open (2)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants