Skip to content

Consolidate Learn dependencies and runtime updates - #3136

Merged
ktsaou merged 2 commits into
masterfrom
deps/consolidated-october-2026
Oct 9, 2026
Merged

ktsaou merged 2 commits into
masterfrom
deps/consolidated-october-2026

Conversation

@ktsaou

@ktsaou ktsaou commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Learn's dependency updates were spread across overlapping PRs, so the declared packages, copied browser bundles and runtime pins could be reviewed or merged at different versions. This combines all supported updates into one tested change and includes newly available compatible updates.

What changes in production

  • Keep Yarn Classic 1.22.22 as the root lock authority, freshly resolving compatible dependencies. Align Node 22.23.3 and bundled npm 10.9.9 across Netlify, generated settings and containers. npm 12 is a separate toolchain-major opportunity, not required by this update.
  • Upgrade Swagger UI and its complete, checksum-verified 21-file distribution to 5.33.1, including licenses. The deployed API viewer and declared packages now agree.
  • Refresh supported security/build leaves, including js-yaml, Joi, SVGO, brace-expansion, Express/body-parser/qs, PostCSS, Undici, Nanoid, Terser and current Babel/SWC. Docusaurus/Faster 3.10.2, React 19.3, Tailwind 4.3.3 and Rspack 1.7.12 stay on their compatible current parents.
  • Update Mermaid to 12.1.0 and pin Nedi's integrity-checked Markdown-it 15.0.2/Mermaid 12.1.0/Viz 3.31.0 assets. A small wrapper keys the original Docusaurus renderer by theme to preserve correct first-load light/dark diagrams. Obsolete Mermaid overrides are removed. Mermaid requires ES2024-capable browsers, including Safari 17.4 or newer.
  • Import Website's shared IndexNow Blob SDK 11.1.4 contract unchanged and correct the previously stale 11.0.1 test expectation. The six owner files and manifest match Website exactly; no live submission is performed.
  • Import the canonical static-site gate with entities 8.1.0/source-map-js 1.2.2. The SEO owner is published at 6b6761c1; gate code, ruleset 10, baselines and consumer identity checks are unchanged.
  • Refresh seven Python lock leaves with verified hashes and update pinned setup-node/upload-artifact/download-artifact actions within their existing majors and Node 24 runtime.

Development tooling also moves to dotenv 18.0.7, Vitest/coverage 5.0.3 and Pixelmatch 8.0.0. The existing dotenv config API is retained; explicit clearMocks: false preserves the prior test lifecycle. Pixelmatch changes its color-distance algorithm, but the existing visual thresholds and nine-page same-build calibration remain unchanged and pass. No documentation content, redirect/indexability policy, sidebar experiment or DCstat producer migration is included.

Validation and limits

  • Complete test:run: 494 Vitest tests pass with one existing skip, plus 99 Node checks. Isolated link tests, updated ingest dependency-policy tests and Swagger/vendor identity checks pass.
  • Two complete publication builds pass every gate, including the 2,032-page C8 check, and contain 4,259 byte-identical files.
  • Desktop/mobile browser checks pass for Mermaid first load and reload in both themes, the 72-operation API viewer, and Nedi's three asset APIs. The unchanged nine-page same-build calibration passes.
  • The Python hash lock installs and passes compatibility checks under Python 3.13.15. Six existing full-ingest tests still fail on source inventory/path assumptions; all six reproduce with master's original Python lock. Their expectations were not weakened.
  • The native final audit reports 62 advisory/path rows across seven package names and nine GHSAs, not 62 distinct vulnerabilities. Remaining braces, KaTeX, selector-parser, serialize-javascript, sprintf-js, tinypool and uuid findings are explicit upstream/no-published-fix holds. Unsupported parent overrides were not forced. The current absence of a cache advisory does not certify its max-stale behavior fixed.
  • The canonical SEO owner passes unchanged default validation in 89.1 seconds. Final qualification includes independent review of this exact Learn head.

Consolidation and delivery

Supersedes #3073, #3080, #3081, #3082, #3093, #3121, #3128, #3129, #3130, #3131, #3132, #3133 and #3135. Old history and branches remain available; final supported versions are resolved together under Yarn.

Ordinary upstream review is required. Deliver the corresponding Website IndexNow owner before this exact consumer. The separate sidebar experiment #3127 and producer migration #3126 stay outside this change. SEO SOW-0038 and Learn's dependency documentation retain measured qualification and follow-up holds.


Summary by cubic

Consolidates Learn's dependency updates into one tested change so declared packages, copied browser bundles, and runtime pins merge at matching versions. Replaces 13 overlapping PRs.

Aligns Node 22.23.3/npm 10.9.9 across Netlify, containers, and workflows, and refreshes security/build dependencies including js-yaml, Joi, SVGO, Mermaid 12.1.0, and Nedi's Markdown-it 15.0.2/Viz 3.31.0 assets. Upgrades Swagger UI to 5.33.1 with its checksum-verified distribution, imports the Website IndexNow Blob SDK 11.1.4 contract and the canonical site-build-gate (entities 8.1.0, source-map-js 1.2.2), and moves dev tooling to dotenv 18.0.7, Vitest 5.0.3, and Pixelmatch 8.0.0 with Playwright 1.64.0.

Behavior changes to check

  • Mermaid now requires ES2024-capable browsers, including Safari 17.4 or newer.
  • A theme-keyed Mermaid wrapper, covered by four new tests, preserves correct first-load light/dark diagrams and regenerates on theme change.
  • Pixelmatch's color-distance algorithm changed; existing visual thresholds were recalibrated and pass.
  • clearMocks: false preserves the previous test lifecycle under the Vitest v5 default change.
  • Six existing full-ingest tests still fail on source inventory/path assumptions; all six reproduce with master's original Python lock.
  • The SOW-0017 remediation JSON is now explicitly marked as historical acceptance evidence; current vendor identity is owned by the site-build-gate and IndexNow manifests.

Written for commit e00761c. Summary will update on new commits.

View guided diff Turn on auto-fix

Summary by CodeRabbit

  • Improvements

    • Mermaid diagrams now refresh to match the active color theme when it changes.
    • Updated the embedded API documentation viewer and diagram-rendering components.
  • Documentation

    • Updated local setup guidance and clarified browser compatibility for Mermaid diagrams.
    • Updated documented build environment versions.
  • Maintenance

    • Updated build tooling and supporting packages.

Review follow-up

  • Explicitly mark the original SOW-0017 remediation JSON as historical acceptance evidence. Its original commits remain intact; current manifests own current vendor byte identity.
  • Four direct tests protect the Mermaid adapter's initial light/dark rendering, theme-change regeneration, unchanged-theme identity and diagram-text forwarding. The actual adapter has 100% coverage under the unchanged thresholds. A private mutation removing its theme key fails the regeneration test; the complete suite passes 494 Vitest tests, one existing skip and 99 Node checks. Independent review passes the three-file follow-up.
  • Nedi's full Mermaid asset grows from 3,572,661 to 5,493,176 decoded bytes. Locally measured gzip at level 9 grows from 976,006 to 1,565,532 bytes (589,526 additional bytes); this is compression qualification, not a production network trace. The full global library remains to preserve the available diagram API. Mermaid Tiny omits mindmap/architecture, KaTeX, lazy loading and ELK. A feature-preserving asynchronous loader would be separate performance work; this change does not silently narrow supported answers.

The follow-up changes documentation and tests only. Production wrapper, runtime configuration, locks and compiled site behavior remain unchanged from the qualified candidate.

@netlify

netlify Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for netdata-docusaurus ready!

Name Link
🔨 Latest commit e00761c
🔍 Latest deploy log https://app.netlify.com/projects/netdata-docusaurus/deploys/6ac9312191ff9600088912f9
😎 Deploy Preview https://deploy-preview-3136--netdata-docusaurus.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 12 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b94b2577-45c1-49b6-ad56-4edca600e2ed

📥 Commits

Reviewing files that changed from the base of the PR and between 709e71d and e00761c.


📒 Files selected for processing (3)
  • config/seo-remediation-contract.json
  • src/__mocks__/theme-original/Mermaid.js
  • src/theme/Mermaid/index.test.js


No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 6a15208c-522e-4d9d-ba1a-fe5a6a7336de

📥 Commits

Reviewing files that changed from the base of the PR and between 3e846ee and 709e71d.


⛔ Files ignored due to path filters (7)
  • scripts/dep-impact/package-lock.json is excluded by !**/package-lock.json
  • scripts/link-integrity/package-lock.json is excluded by !**/package-lock.json
  • scripts/site-build-gate/package-lock.json is excluded by !**/package-lock.json
  • static/swagger-ui-es-bundle-core.js.map is excluded by !**/*.map
  • static/swagger-ui.css.map is excluded by !**/*.map
  • static/swagger-ui.js.map is excluded by !**/*.map
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock

📒 Files selected for processing (34)
  • .devcontainer/devcontainer.json
  • .github/workflows/dependency-impact.yml
  • .github/workflows/generated-output-boundary.yml
  • .github/workflows/rendered-link-integrity.yml
  • .learn_environment/ingest-requirements.txt
  • FIRST-TOUCH-ATTRIBUTION.md
  • README.md
  • ingest/test_dependency_policy.py
  • netlify.toml
  • package.json
  • plugins/netlify-plugin-indexnow/README.md
  • plugins/netlify-plugin-indexnow/package.json
  • plugins/netlify-plugin-indexnow/vendor-checksums.json
  • scripts/dep-impact/package.json
  • scripts/site-build-gate/manifest.json
  • scripts/verify-indexnow-vendor.js
  • src/components/Nedi/assets.js
  • src/seo/deploymentIntegrations.test.js
  • src/theme/Mermaid/index.js
  • static.toml
  • static/swagger-ui-bundle.js
  • static/swagger-ui-bundle.js.LICENSE.txt
  • static/swagger-ui-es-bundle-core.js
  • static/swagger-ui-es-bundle.js
  • static/swagger-ui-es-bundle.js.LICENSE.txt
  • static/swagger-ui-standalone-preset.js
  • static/swagger-ui-standalone-preset.js.LICENSE.txt
  • static/swagger-ui-vendor.json
  • static/swagger-ui.css
  • static/swagger-ui.js
  • tests/dependency_authority.test.js
  • tests/site_build_gate.test.js
  • tests/swagger_ui_vendor.test.js
  • vitest.config.js

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



📝 Walkthrough

Walkthrough

The pull request updates Node.js, npm, CI actions, and JavaScript and Python dependencies. It also updates Mermaid rendering behavior, vendor metadata, compatibility guidance, and related tests.

Changes

Runtime and CI

Layer / File(s) Summary
Node.js and npm version alignment
.devcontainer/devcontainer.json, FIRST-TOUCH-ATTRIBUTION.md, README.md, netlify.toml, static.toml, src/seo/deploymentIntegrations.test.js
Development and deployment configuration and setup guidance use Node.js 22.23.3 and npm 10.9.9. Related integration test expectations are updated.
CI action pin updates
.github/workflows/dependency-impact.yml, .github/workflows/generated-output-boundary.yml, .github/workflows/rendered-link-integrity.yml, ingest/test_dependency_policy.py
Workflows update pinned setup-node, upload-artifact, and download-artifact versions. The dependency policy test expects setup-node v7.1.0.

JavaScript Dependencies and Rendering

Layer / File(s) Summary
Mermaid renderer and compatibility
package.json, src/components/Nedi/assets.js, src/theme/Mermaid/index.js, README.md
Mermaid and related Nedi assets use updated versions and integrity hashes. The Mermaid wrapper keys the rendered component by color mode. README adds renderer and browser compatibility guidance.
Dependency and vendor metadata updates
package.json, vitest.config.js, scripts/dep-impact/package.json, plugins/netlify-plugin-indexnow/*, scripts/site-build-gate/manifest.json, scripts/verify-indexnow-vendor.js, static/swagger-ui-*, static/swagger-ui-vendor.json, tests/dependency_authority.test.js, tests/site_build_gate.test.js, tests/swagger_ui_vendor.test.js, src/seo/deploymentIntegrations.test.js, README.md
JavaScript dependency versions and resolutions change, including Vitest, Playwright, Pixelmatch, IndexNow, and Swagger UI. Vendor metadata, license notices, test expectations, and tooling guidance are updated. Vitest sets clearMocks: false.

Python Ingest Requirements

Layer / File(s) Summary
Python requirements lock and regeneration
.learn_environment/ingest-requirements.txt, README.md
The hashed lock updates package versions, hashes, platform markers, and provenance comments. It adds conditional dependencies and documents --upgrade for lock regeneration.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other


Merge Risk

Merge Risk: ⚪ Minimal · up to 709e7

No concrete defect remains identified in this change. Complete the planned Website IndexNow rollout before publishing the consumer.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 709e7

The inspected changes preserve existing loading controls, input forwarding and embed configuration. No introduced security weakness was established. Risk remains low rather than minimal because the upgraded rendering libraries and external embed behavior were not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Nedi dependencies execute within the Learn browser document. Route-scoped loading limits initiation, not script authority or lifetime: the existing embed instance persists across navigation. The inspected PR does not expand this local exposure, but remote backend authority cannot be bounded from these sources.

Trust Boundaries and Controls

  • observed — Version-pinned CDN scripts retain integrity and anonymous crossorigin attributes in both server declarations and dynamic injection. First-party Nedi scripts remain intentionally unpinned, a pre-existing trust arrangement rather than a control removed by this PR. Integrity authenticates selected bytes, not their rendering or sanitization behavior.

Resilience and Maintainability Implications

  • observed — The existing Nedi lifecycle clears readiness timers and navigation callbacks, removes a container when construction fails, and preserves an already usable embed during retry. These local recovery controls are unchanged; removing script elements does not undo previously executed external script effects.



Pre-merge checks | Passed 4 | Failed 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 9 files. (19 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly summarizes the pull request's main scope: consolidating Learn dependency updates and runtime version updates across the project.

Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 9 files. (19 skipped: 19 unsupported.)



✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 41 files

Confidence score: 4/5

  • src/components/Nedi/assets.js loads Mermaid’s ~5.5 MB UMD bundle, which can add noticeable download and parse time for Ask Nedi users. Consider using a smaller build or loading the bundle only when needed.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="src/components/Nedi/assets.js">

<violation number="1" location="src/components/Nedi/assets.js:20">
P3: Ask Nedi now loads mermaid 12's main UMD bundle, which includes the Elk layout engine by default and is ~5.5 MB minified (unpkg shows `mermaid.min.js` at 5.49 MB in mermaid@12.1.0). Mermaid's own docs state that in v12 ELK is "bundled with `mermaid` and used by default", and the no-Elk build is the separate `@mermaid-js/tiny` package. Check with the Nedi embed owner whether the Elk layouts are actually needed for diagram answers; if not, pin `@mermaid-js/tiny` (or the site's existing mermaid 12 ESM bundle) instead of shipping a 5.5 MB script with a new SRI hash on this route.</violation>
</file>
Architecture diagram
sequenceDiagram
    participant Dev as Developer
    participant CI as GitHub Actions
    participant Build as Netlify Build
    participant Site as Docusaurus Site
    participant Mermaid as Mermaid Renderer
    participant Swagger as Swagger UI
    participant Nedi as Nedi Chatbot
    participant CDN as CDN (jsdelivr)
    participant IndexNow as IndexNow Plugin
    participant Gate as Site Build Gate

    Note over Dev,CI: Consolidated dependency management
    Dev->>Dev: Yarn Classic 1.22.22 resolves dependencies
    Dev->>Dev: Node 22.23.3 + npm 10.9.9 pinned

    CI->>CI: setup-node v7.1.0 with Node 22.23.3
    CI->>CI: upload/download-artifact v7.0.2/v8.0.2

    Build->>Build: Node 22.23.3 + npm 10.9.9 environment
    Build->>Site: Build Docusaurus site
    Site->>Mermaid: Render diagrams (v12.1.0)
    Site->>Swagger: Serve API viewer (v5.33.1)
    Site->>Nedi: Load chatbot assets

    Note over Site,Mermaid: NEW: Theme-keyed wrapper
    Site->>Mermaid: Pass colorMode as key
    Mermaid->>Mermaid: Fresh render per theme
    alt Theme change (light/dark)
        Site->>Mermaid: Remount with new key
        Mermaid-->>Site: Clean SVG render
    end

    Note over Nedi,CDN: Integrity-checked assets
    Nedi->>CDN: Load markdown-it@15.0.2
    Nedi->>CDN: Load mermaid@12.1.0
    Nedi->>CDN: Load viz@3.31.0
    CDN-->>Nedi: Verify integrity hashes
    Note over Nedi: Requires ES2024 browsers (Safari 17.4+)

    Note over Build,IndexNow: IndexNow contract
    Build->>IndexNow: Execute deployment plugin
    IndexNow->>IndexNow: Use @netlify/blobs@11.1.4
    IndexNow->>IndexNow: Verify vendor checksums match Website

    Note over Build,Gate: Static build validation
    Build->>Gate: Run site build gate
    Gate->>Gate: Verify entities@8.1.0, source-map-js@1.2.2
    Gate->>Gate: Check package-lock.json hash

    Note over CI: Test execution
    CI->>CI: Vitest v5 with clearMocks: false
    CI->>CI: Run 490 tests + 99 Node checks
    CI->>CI: Pixelmatch 8 visual calibration
    
    opt Test failure
        CI->>CI: Report dependency impact
        CI->>CI: Upload artifact for review
    end

    Note over Build,Site: Production deploy
    Build-->>Site: Deploy to Netlify
    Site-->>Dev: Accessible at production URL
Loading

Reply with feedback, questions, or to request a fix.

View guided diff | Turn on auto-fix | Re-trigger cubic

Comment thread plugins/netlify-plugin-indexnow/README.md
Comment thread src/theme/Mermaid/index.js
Comment thread src/components/Nedi/assets.js
@ktsaou
ktsaou marked this pull request as ready for review October 9, 2026 18:12
@ktsaou
ktsaou requested a review from a team as a code owner October 9, 2026 18:12
@ktsaou
ktsaou requested review from mtblz and witalisoft October 9, 2026 18:12
@ktsaou
ktsaou merged commit a0ab7b0 into master Oct 9, 2026
15 checks passed
@ktsaou
ktsaou deleted the deps/consolidated-october-2026 branch October 9, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants