Repository navigation
fix(cli-command): bump snyk-nodejs-lockfile-parser to 2.10.4 to drop broken @yarnpkg/core #2442
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -2,7 +2,7 @@ import { createRequire } from 'module'; | |||||
| import logger from '@percy/logger'; | ||||||
|
|
||||||
| // snyk-nodejs-lockfile-parser is a CommonJS optionalDependency. It requires | ||||||
| // Node >=18 while the CLI supports Node >=14, so we defer the require to call | ||||||
| // Node >=20.19 while the CLI supports Node >=14, so we defer the require to call | ||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: git diff --stat a05b0ac1efc0d136fa15c2330b55e1e207c6e797 2660c593ad56447ebf3dafca60079f1c7fcc8f38
git diff a05b0ac1efc0d136fa15c2330b55e1e207c6e797 2660c593ad56447ebf3dafca60079f1c7fcc8f38 -- packages/cli-command/package.json packages/cli-command/src/lockfileDiff.js yarn.lock
rg -n 'snyk-nodejs-lockfile-parser|20\.19|22\.13|SNYK_LOCKFILE_PARSER_UNAVAILABLE' packages/cli-command yarn.lockRepository: percy/cli Length of output: 41153 🏁 Script executed: set -e
printf '%s\n' '--- lockfile paths ---'
git ls-tree -r --name-only 2660c593ad56447ebf3dafca60079f1c7fcc8f38 | grep -E '(^|/)(yarn|package-lock|npm-shrinkwrap).*' || true
printf '%s\n' '--- package scripts and package metadata ---'
cat -n packages/cli-command/package.json | sed -n '1,90p'
printf '%s\n' '--- lockfile parser entry ---'
git show 2660c593ad56447ebf3dafca60079f1c7fcc8f38:yarn.lock 2>/dev/null | sed -n '/^snyk-nodejs-lockfile-parser@2\.10\.4:/,/^$/p' || true
printf '%s\n' '--- exact parser registry metadata ---'
python3 - <<'PY'
import json, urllib.request
url = 'https://registry.npmjs.org/snyk-nodejs-lockfile-parser/2.10.4'
with urllib.request.urlopen(url, timeout=20) as r:
data = json.load(r)
print(json.dumps({
'version': data.get('version'),
'engines': data.get('engines'),
'dependencies': data.get('dependencies'),
'optionalDependencies': data.get('optionalDependencies'),
'dist': data.get('dist'),
}, indent=2, sort_keys=True))
PYRepository: percy/cli Length of output: 4871 🌐 Web query:
💡 Result: 🏁 Script executed: set -e
printf '%s\n' '--- parser package metadata ---'
curl -ksSf https://registry.npmjs.org/snyk-nodejs-lockfile-parser/2.10.4 |
python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps({k:d.get(k) for k in ("name","version","engines","dependencies","optionalDependencies","dist")}, indent=2, sort_keys=True))'
printf '%s\n' '--- parser tarball package.json ---'
curl -ksSfL https://registry.npmjs.org/snyk-nodejs-lockfile-parser/-/snyk-nodejs-lockfile-parser-2.10.4.tgz |
tar -xzO package/package.json | python3 -m json.tool | sed -n '1,100p'
printf '%s\n' '--- changed source and related test ---'
cat -n packages/cli-command/src/lockfileDiff.js | sed -n '1,45p'
cat -n packages/cli-command/test/intelliStory.test.js | sed -n '960,1015p'
printf '%s\n' '--- Node references in CI and project metadata ---'
rg -n -i --glob '!yarn.lock' 'node-version|node versions|Node (>=|18|20|22|23|24)|setup-node|engines' .github package.json packages scripts 2>/dev/null | head -n 240
printf '%s\n' '--- concise full diff summary and changed hunks ---'
git diff --stat a05b0ac1efc0d136fa15c2330b55e1e207c6e797 2660c593ad56447ebf3dafca60079f1c7fcc8f38
git diff --unified=3 a05b0ac1efc0d136fa15c2330b55e1e207c6e797 2660c593ad56447ebf3dafca60079f1c7fcc8f38 -- packages/cli-command/src/lockfileDiff.js packages/cli-command/package.jsonRepository: percy/cli Length of output: 16919 🏁 Script executed: set -e
printf '%s\n' '--- test runtime binding and affected test ---'
rg -n -C 4 'NODE_MAJOR|bails on Node|getAffectedPackages\(\) lockfile diff' packages/cli-command/test/intelliStory.test.js
printf '%s\n' '--- workflow test matrix and related comments ---'
cat -n .github/workflows/test.yml | sed -n '145,205p'
printf '%s\n' '--- all Node matrix entries in test workflow ---'
rg -n -C 3 'matrix:|node:' .github/workflows/test.ymlRepository: percy/cli Length of output: 5679 State the parser’s full Node.js support range.
Suggested fix-// Node >=20.19 while the CLI supports Node >=14, so we defer the require to call
+// Node ^20.19.0 || ^22.13.0 || >=24.0.0 while the CLI supports Node >=14, so we defer the require to call
...
-/* istanbul ignore next: snyk-backed path — the parser requires Node >=20.19 while
+/* istanbul ignore next: snyk-backed path — the parser requires Node ^20.19.0 || ^22.13.0 || >=24.0.0 while
CI runs the suite on Node 14, so these lines can't execute there; they're
- exercised by the describeSnyk tests on Node >=18 */
+ exercised by the describeSnyk tests on Node ^20.19.0 || ^22.13.0 || >=24.0.0 */
...
- const err = new Error(`snyk-nodejs-lockfile-parser is not available (requires Node >=20.19, or the optional install was skipped): ${e.message}`);
+ const err = new Error(`snyk-nodejs-lockfile-parser is not available (requires Node ^20.19.0 || ^22.13.0 || >=24.0.0, or the optional install was skipped): ${e.message}`);📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||
| // time — that way importing this module never throws on older Node versions | ||||||
| // (or when the optional install was skipped for any other reason). Cached on | ||||||
| // first successful load so the require only resolves once per process. | ||||||
|
|
@@ -14,7 +14,7 @@ import logger from '@percy/logger'; | |||||
| // initializer (TypeError: _require is not a function). See PER intelliStory binary. | ||||||
| const cjsRequire = createRequire(import.meta.url); | ||||||
| let _snykModule; | ||||||
| /* istanbul ignore next: snyk-backed path — the parser requires Node >=18 while | ||||||
| /* istanbul ignore next: snyk-backed path — the parser requires Node >=20.19 while | ||||||
| CI runs the suite on Node 14, so these lines can't execute there; they're | ||||||
| exercised by the describeSnyk tests on Node >=18 */ | ||||||
| function loadSnyk() { | ||||||
|
|
@@ -23,7 +23,7 @@ function loadSnyk() { | |||||
| _snykModule = cjsRequire('snyk-nodejs-lockfile-parser'); | ||||||
| return _snykModule; | ||||||
| } catch (e) { | ||||||
| const err = new Error(`snyk-nodejs-lockfile-parser is not available (requires Node >=18, or the optional install was skipped): ${e.message}`); | ||||||
| const err = new Error(`snyk-nodejs-lockfile-parser is not available (requires Node >=20.19, or the optional install was skipped): ${e.message}`); | ||||||
| err.code = 'SNYK_LOCKFILE_PARSER_UNAVAILABLE'; | ||||||
| throw err; | ||||||
| } | ||||||
|
|
||||||
Uh oh!
There was an error while loading. Please reload this page.