[jira] [Created] (YUNIKORN-2496) Fix security issues in website javascript

2024-03-17 Thread Wilfred Spiegelenburg (Jira)
Wilfred Spiegelenburg created YUNIKORN-2496:
---

 Summary: Fix security issues in website javascript
 Key: YUNIKORN-2496
 URL: https://issues.apache.org/jira/browse/YUNIKORN-2496
 Project: Apache YuniKorn
  Issue Type: Task
  Components: website
Reporter: Wilfred Spiegelenburg
Assignee: Wilfred Spiegelenburg


The change to pnmp triggered a large number of security alerts from dependabot.

7 could be fixed directly by the 4 PRs opened by dependabot. 6 need manual 
intervention.

The change also included an upgrade of the Algolia search component to 3.x. 
That change prevent running {{{}pnpm audit{}}}. 
Docusaurus 3.x also contains a large number of backward incompatible changes 
and an upgrade is planned separately. Using the Algolia 3.x dependency already 
pushes some of these changes and should be reverted to Algolia 2.x same as the 
rest of Docusaurus environment.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

-
To unsubscribe, e-mail: dev-unsubscr...@yunikorn.apache.org
For additional commands, e-mail: dev-h...@yunikorn.apache.org



[jira] [Resolved] (YUNIKORN-2481) Convert yunikorn-site build to use pnpm

2024-03-17 Thread Craig Condit (Jira)


 [ 
https://issues.apache.org/jira/browse/YUNIKORN-2481?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Craig Condit resolved YUNIKORN-2481.

Fix Version/s: 1.6.0
   Resolution: Fixed

Merged to master.

> Convert yunikorn-site build to use pnpm
> ---
>
> Key: YUNIKORN-2481
> URL: https://issues.apache.org/jira/browse/YUNIKORN-2481
> Project: Apache YuniKorn
>  Issue Type: Improvement
>  Components: website
>Reporter: Craig Condit
>Assignee: Craig Condit
>Priority: Major
>  Labels: pull-request-available
> Fix For: 1.6.0
>
>
> Our current yunikorn-site build is driven by yarn v1, which is very outdated 
> and slow. We should switch to using pnpm instead.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

-
To unsubscribe, e-mail: dev-unsubscr...@yunikorn.apache.org
For additional commands, e-mail: dev-h...@yunikorn.apache.org