Conversation
Contributor
Author
|
/close iss-925 |
drdavella
requested changes
Aug 8, 2024
Co-authored-by: Dan D'Avella <drdavella@gmail.com>
drdavella
approved these changes
Aug 8, 2024
gilday
approved these changes
Aug 9, 2024
|
|
||
| Users can join the Pixee community [on Slack](https://join.slack.com/t/openpixee/shared_invite/zt-1pnk7jqdd-kfwilrfG7Ov4M8rorfOnUA). This channel can be used to engage with peers who are also interested in Pixee. Feel free to email us at help@pixee.ai with any questions or comments. | ||
|
|
||
| ### Why does pixee sometimes add new dependencies to my project? |
Contributor
There was a problem hiding this comment.
Uppercase Pixee for consistency
|
|
||
| ### Why does pixee sometimes add new dependencies to my project? | ||
|
|
||
| We always prefer to use existing controls built into a language, or a control from a well-known and trusted community dependency. When this is not an option, we add our own open source dependency to the project to ensure maximum readability and maintainability. All dependencies utilize permissive open-source licenses. |
Contributor
There was a problem hiding this comment.
Consider expanding on "when this is not an option". Why is not an option? Maybe "when no such dependency exists that meets that criteria"
|
|
||
| We always prefer to use existing controls built into a language, or a control from a well-known and trusted community dependency. When this is not an option, we add our own open source dependency to the project to ensure maximum readability and maintainability. All dependencies utilize permissive open-source licenses. | ||
|
|
||
| Learn more about the [Java Security Toolkit (io.github.pixee.java-security-toolkit) on Maven Central](https://central.sonatype.com/artifact/io.github.pixee/java-security-toolkit/overview). |
Contributor
There was a problem hiding this comment.
There's another Java toolkit we maintain specifically for xstream.
This was referenced Sep 4, 2026
dunningdan
added a commit
that referenced
this pull request
Sep 7, 2026
#302 cleared 42 of 51 Dependabot alerts by refreshing yarn.lock, but 9 survive because re-resolution provably cannot reach them - their parents either pin an exact version or cap below the patched release: minimatch parent pins 9.0.3 exactly -> 9.0.9 yaml parent pins 2.8.1 exactly -> 2.9.0 serialize-javascript parent caps at ^6.0.0 -> 7.1.1 uuid parent caps at ^8.3.2 -> 11.1.1 qs parent caps at ~6.15.1 -> 6.16.0 yarn resolutions are the only lever here, following the existing `got` entry. This clears 9 of the 11 currently open alerts. qs is the newest of these: GHSA for it was published Sep 2 and GitHub raised alerts #197/#198 three minutes after #302 merged, against the freshly refreshed lockfile. `~6.15.1` excludes 6.16.0, so no future lockFileMaintenance pass would have fixed it either. Remaining open after this: #186/#187 image-size, which has no patched version published upstream. Reached via @docusaurus/mdx-loader at build time only; tracked for risk acceptance rather than code change. Verified on Node 24.20.0: yarn build passes (59 documents) and the dev server serves HTTP 200, which exercises sockjs -> uuid@11, the one bump here that crosses major versions and that a production build would not otherwise cover. Also refreshes the lockFileMaintenance description - it still told the reader to restore a weekly schedule, which is no longer the intent. No behavior change; schedule stays "at any time". Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
/close #work