[
https://issues.apache.org/jira/browse/ATLAS-5384?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Brijesh Bhalala updated ATLAS-5384:
-----------------------------------
Labels: (was: atlas-react)
> Atlas Classic UI: Upgrade UI dependencies for dashboardv2
> ---------------------------------------------------------
>
> Key: ATLAS-5384
> URL: https://issues.apache.org/jira/browse/ATLAS-5384
> Project: Atlas
> Issue Type: Task
> Components: atlas-core
> Affects Versions: 3.0.0, 2.5.0
> Reporter: Brijesh Bhalala
> Assignee: Brijesh Bhalala
> Priority: Major
> Time Spent: 10m
> Remaining Estimate: 0h
>
> The legacy `dashboardv2` module requires dependency upgrades to address
> outdated sub-packages and close open Dependabot pull requests.
> Because `dashboardv2` is tied to the older npm v6 build environment via
> Maven, attempting to upgrade deeply nested sub-dependencies using manual
> `resolutions` or `overrides` is either unsupported or ineffective.
> Rather than using workarounds to force sub-dependency upgrades, this ticket
> aims to cleanly resolve the outdated dependencies by safely upgrading their
> top-level parent build tools in `package.json`. The changes include:
> 1. **Upgrading core Grunt plugins to pull in secure sub-dependencies:**
> * Upgraded `grunt` to `1.6.3` (Inherently pulls in the modernized version
> of `micromatch` to resolve the `picomatch` alerts).
> * Upgraded `grunt-contrib-connect` to `5.0.1` (Inherently pulls in the
> modernized versions of `serve-static` and `send`).
> * Upgraded `grunt-contrib-cssmin` to `4.0.0` (Inherently resolves the
> nested `clean-css` and `trim-newlines` vulnerabilities while retaining Node
> 12 compatibility).
> 2. **Cleaning up dependencies:**
> * Removed ineffective `overrides`/`resolutions` blocks from `package.json`
> to rely entirely on native, safe npm dependency resolution.
> 3. **Lockfile Generation:**
> * Regenerated a clean `package-lock.json` (`lockfileVersion: 1`) using the
> strictly enforced Node v12.16.0 / npm v6.13.7 environment to ensure the Maven
> build remains stable and developers can continue running `npm install`
> locally without lockfile conflicts.
> This effort cleanly modernizes the build pipeline for `dashboardv2` and will
> consolidate and close the following open Dependabot PRs and audit
> vulnerabilities for the dashboard module:
> * PR #588 (picomatch)
> * PR #579 (picomatch)
> * PR #254 (serve-static)
> * PR #253 (send, serve-static)
> * NPM Audit fixes for `clean-css` and `trim-newlines`.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)