Skip to content

chore(deps): bump browserslist, qs, joi, js-yaml in example lockfile - #155

Merged
ethanpschoen merged 2 commits into
mainfrom
ethan/chore/example-dep-bumps
Sep 25, 2026
Merged

ethanpschoen merged 2 commits into
mainfrom
ethan/chore/example-dep-bumps

Conversation

@ethanpschoen

@ethanpschoen ethanpschoen commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Description of this change

Bumps example/yarn.lock in place, the same way #144 did. I used yarn up -R with yarn 4.2.2 (the example's packageManager). No new resolutions; example/package.json is unchanged.

Package From To
browserslist 4.28.1 4.29.1
qs 6.15.2 6.16.0
baseline-browser-mapping 2.9.7 2.11.26
joi 17.13.4 17.13.8
js-yaml 4.3.1 4.3.2

Knock-on changes:

  • browserslist's data packages also moved: caniuse-lite, electron-to-chromium, node-releases, update-browserslist-db.
  • side-channel 1.1.1 and side-channel-list 1.0.1 are added for qs.
  • The @ketch-com/ketch-react-native@file:../package entry is left exactly as on main. yarn hashes that entry from the packed package/, which includes the gitignored lib/ build output. That makes its checksum machine-dependent: two runs in the same checkout produced different values. As a result, yarn install --immutable in example/ fails on main and on this branch alike, and only that one entry differs.

No entry changes major.

Not included: image-size (#476). The only fix is 2.x, and metro pins 1.x.

This is separate from #154 (the package/ lockfiles). #154 was already approved, so this change goes in its own PR rather than being added to that one.

Why is this change being made?

  • Chore (non-functional changes)
  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

How was this tested? How can the reviewer verify your testing?

CI doesn't build example/, so these checks were run locally in example/ (Node 23.11.0, yarn 4.2.2), on main and on this branch:

Check main this branch
yarn install (non-immutable) diff — only the file:../package checksum changes; every dependency entry is consistent
tsc --noEmit 0 errors 0 errors
eslint 0 errors, 1 warning 0 errors, 1 warning
Android production metro bundle 1,070,059 B 1,070,059 B (same SHA-256)
iOS production metro bundle 1,064,837 B 1,064,837 B (same SHA-256)

The eslint warning is the existing no-path-concat in metro.config.js. The bundles are identical because every bumped package is build tooling.

Not run:

  • The example's only jest suite. It's an Appium e2e test that fails to load webdriverio on main and on this branch alike, and it needs a device.
  • Native builds.
  • The metro dev server. The existing resolutions entry "qs": "^6.14.1" now puts body-parser on qs 6.16.0, and that isn't exercised under the dev server.

Related issues

Closes Dependabot alerts #432, #433, #442, #449, #450, #469, #470 and #472. Vanta: KD-18416, KD-18415.

Checklist

  • I have added tests to cover my changes.
  • All new and existing tests passed.
  • I have evaluated the security impact of this change, and OWASP Secure Coding Practices have been observed.
  • I have informed stakeholders of my changes.

Note

Low Risk
Lockfile-only transitive upgrades to dev/build dependencies; no application source changes and local checks reported identical Metro bundles.

Overview
Updates example/yarn.lock only (no package.json changes) by refreshing resolved versions for build-tooling and security-related transitive deps, mainly via yarn up -R.

Direct bumps: browserslist 4.28.1 → 4.29.1 (with caniuse-lite, electron-to-chromium, node-releases, update-browserslist-db, and baseline-browser-mapping, including CLI path dist/cli.js → dist/cli.cjs), qs 6.15.2 → 6.16.0 (adds side-channel@^1.1.1 / side-channel-list@^1.0.1), joi 17.13.4 → 17.13.8, and js-yaml 4.3.1 → 4.3.2.

Aligns with the example app’s existing resolutions for qs and js-yaml; intended to clear Dependabot alerts without changing app/runtime bundle output.

Reviewed by Cursor Bugbot for commit 678a5d4. Configure here.

yarn up -R with yarn 4.2.2; all entries stay within their major.
image-size stays on 1.x (metro pins it; fix is 2.x only).
@ethanpschoen
ethanpschoen marked this pull request as ready for review September 25, 2026 18:34
@ethanpschoen
ethanpschoen requested review from a team as code owners September 25, 2026 18:34
@ethanpschoen
ethanpschoen merged commit 33eb277 into main Sep 25, 2026
12 checks passed
@ethanpschoen
ethanpschoen deleted the ethan/chore/example-dep-bumps branch September 25, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants