Skip to content

NXT-20662: Update package dependencies to fix security vulnerabilities - #276

Merged
daniel-stoian-lgp merged 7 commits into
developfrom
feature/NXT-20662
Oct 8, 2026
Merged

daniel-stoian-lgp merged 7 commits into
developfrom
feature/NXT-20662

Conversation

@alexandrumorariu

@alexandrumorariu alexandrumorariu commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Enact-DCO-1.0-Signed-off-by: Alexandru Morariu alexandru.morariu@lgepartner.com

Checklist

  • I have read and understand the contribution guide
  • A CHANGELOG entry is included
  • I have run automated testing and it is passed
  • Documentation was added or is not needed
  • This is an API breaking change

Issue Resolved / Feature Added

Update package dependencies to fix security vulnerabilities

Resolution

Additional Considerations

Updated major versions:
react-live: ^4.1.8 --> ^5.0.0 no breaking changes (https://github.com/FormidableLabs/react-live/releases/tag/react-live%405.0.0)
linkinator: ^6.1.2 --> ^8.1.0 no breaking changes (https://github.com/JustinBeckwith/linkinator/releases?page=1)

  • react, react-dom ^19.2.7 → ^19.3.0 Root and all 3 sample-runners
  • react-live ^4.1.8 → ^5.0.0 All 3 sample-runners
  • @enact/limestone ^1.11.2 → ^1.12.0 sample-runner/limestone
  • highlight.js ^11.11.1 → ^11.12.0 Root (dependencies)
  • @types/react ^19.2.17 → ^19.3.0 Root (devDependencies)
  • @types/react-dom ^19.2.3 → ^19.3.0 Root (devDependencies)
  • eslint ^9.39.4 → ^9.39.5 Root (devDependencies)
  • linkinator ^6.1.2 → ^8.1.0 Root (devDependencies)

Moonstone and Sandstone are unchanged as support for those libraries was interrupted.

I changed the cli version to develop.

Links

NXT-20662

Comments

@dan-ichim-lgp

Copy link
Copy Markdown
Contributor

The title and description say this fixes security vulnerabilities, but no advisory or affected package is named, and Resolution is empty. The diff is a dependency bump plus a CI branch change. Please list the real changes: React and ReactDOM to ^19.3.0, react-live to ^5.0.0 for the agate, core, and limestone runners, linkinator to ^8.1.0, @enact/limestone to ^1.12.0, and the CI clone of enactjs/cli moving from release/7.2.x.develop to develop.

Sandstone stays on react-live ^4.1.8 and moonstone on ~4.1.7. Please say whether that is intentional.

Please also add the Enact-DCO sign-off in Comments.

Comment thread CHANGELOG.md

## [unreleased]

- Updated minor dependencies versions to the latest.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This entry does not match the diff. linkinator moves from 6 to 8 and react-live moves from 4 to 5, and the CI workflow now clones cli develop. Please name those changes here.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

Comment thread package.json
"eslint": "^9.39.5",
"eslint-config-enact": "^5.1.3",
"linkinator": "^6.1.2",
"linkinator": "^8.1.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a two-major jump from ^6.1.2 and it is not mentioned in the description. npm run check-links still calls linkinator ./dist --recurse --verbosity error. Please confirm those flags still work on linkinator 8.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I ran the command on linkinator 8.1.0 here, and npm run check-links (linkinator ./dist --recurse --verbosity error) works the same as on 6.1.2.

@daniel-stoian-lgp
daniel-stoian-lgp merged commit 1e37d2c into develop Oct 8, 2026
4 checks passed
@daniel-stoian-lgp
daniel-stoian-lgp deleted the feature/NXT-20662 branch October 8, 2026 06:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants