Skip to content

fix: restore yarn.lock resolutions reverted by #947's merge - #987

Merged
martin-henz merged 1 commit into
masterfrom
fix-947-yarn-lock-regression
Oct 7, 2026
Merged

martin-henz merged 1 commit into
masterfrom
fix-947-yarn-lock-regression

Conversation

@Akshay-2007-1

@Akshay-2007-1 Akshay-2007-1 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

What happened

Per @RichDom2185's review on #947: that PR's merge resolved a yarn.lock conflict by regenerating the whole file via a plain yarn install. That re-resolved every package in the workspace from scratch, not just the ones robot_simulation actually changed. At that moment, many packages' true-latest versions were too recently published to pass .yarnrc.yml's npmMinimalAgeGate (3 days), so yarn silently fell back to older already-aged versions across the board - about 115 unrelated resolutions reverted (e.g. @cspell/* dropped from 10.3.3 back to 10.1.1), reintroducing security advisories that had already been fixed on master.

Fix

  • Restored yarn.lock from the commit immediately before robot_simulation: let a control program be written in Python #947 merged (the last known-good state).
  • Re-applied only the resolutions robot_simulation's own package.json changes actually need: the three/@types/three bump, the real @sourceacademy/py-slang npm dependency (replacing a local portal: path), and @sourceacademy/modules-testplugin.
  • Diffed the result against that pre-robot_simulation: let a control program be written in Python #947 baseline to confirm scope: exactly one resolution changed (@sourceacademy/conductor, moving forward within its existing catalog range, not a revert) - zero others.

Testing

tsc, build, and all 131 robot_simulation tests pass with the restored lockfile.

#947's merge resolved a yarn.lock conflict by regenerating the whole
file via a plain `yarn install`, which re-resolved every package from
scratch - at that moment, many packages' true-latest versions were
too recently published to pass .yarnrc.yml's npmMinimalAgeGate (3
days), so yarn silently fell back to older versions across roughly
115 unrelated packages (e.g. @cspell/* dropped from 10.3.3 back to
10.1.1), reintroducing already-fixed security advisories alongside the
actual robot_simulation changes.

Restores yarn.lock from the commit right before #947 merged, then
re-adds only the handful of entries robot_simulation's own package.json
changes actually need (three/@types/three bump, the real
@sourceacademy/py-slang npm dependency, @sourceacademy/modules-testplugin).
Diffed against the pre-#947 lockfile to confirm: one resolution changed
(@sourceacademy/conductor, forward within its existing catalog range -
not a revert), zero others.

Verified: tsc, build, and all 131 robot_simulation tests still pass.

@martin-henz martin-henz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing this @Akshay-2007-1 and @RichDom2185 for pointing out the issue. Due to the security implications, I'm approving and merging right away.

@martin-henz
martin-henz self-requested a review October 7, 2026 00:12

@martin-henz martin-henz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@martin-henz
martin-henz merged commit 1732247 into master Oct 7, 2026
67 checks passed
@martin-henz
martin-henz deleted the fix-947-yarn-lock-regression branch October 7, 2026 00:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants