Refresh dependencies and align TypeScript tooling - #12
Merged
Merged
Conversation
Contributor
Deploying site with
|
| Latest commit: |
eb660cb
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://305d9d52.site-7lj.pages.dev |
| Branch Preview URL: | https://chore-refresh-dependencies.site-7lj.pages.dev |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
TypeScript remains on 6.0.3 because Astro’s checker requires its JavaScript API. Native type-aware linting runs through oxlint-tsgolint.
Why
Resolve the Astro security alerts and refresh the full dependency graph. Patched overrides for fflate and sharp address vulnerable versions pinned upstream. Add enforceable repository guidance and checks to catch unsafe casts, mutable inputs, and generated-code residue.
Verification
Frozen dependency installation, repository hooks, formatting, linting, Astro type checks, all 12 tests, and the production build pass. The dependency audit reports no vulnerabilities. Linting, type checks, tests, and builds also pass with native Node absent from PATH. Browser-based résumé generation produced valid PDFs, and negative lint probes confirmed rule enforcement.
GitHub CI and CodeQL passed. Cloudflare Pages successfully deployed commit e997f72 through its Git integration: deployment preview.
Known local issue:
wrangler pages devstarts under Bun 1.4.0 but HTTP requests time out. The same test under Node 24.20.0 returns HTTP 200. This did not prevent the Cloudflare Git-integration deployment. The separatebun run deployCLI command was not exercised.Context