Skip to content

ISS-924 Add Dependency FAQ - #186

Merged
dhafley merged 2 commits into
mainfrom
iss-924
Aug 9, 2024
Merged

ISS-924 Add Dependency FAQ#186
dhafley merged 2 commits into
mainfrom
iss-924

Conversation

@dhafley

@dhafley dhafley commented Aug 8, 2024

Copy link
Copy Markdown
Contributor

/close #work

@dhafley

dhafley commented Aug 8, 2024

Copy link
Copy Markdown
Contributor Author

/close iss-925

Comment thread docs/faqs.md Outdated
Co-authored-by: Dan D'Avella <drdavella@gmail.com>
Comment thread docs/faqs.md

Users can join the Pixee community [on Slack](https://join.slack.com/t/openpixee/shared_invite/zt-1pnk7jqdd-kfwilrfG7Ov4M8rorfOnUA). This channel can be used to engage with peers who are also interested in Pixee. Feel free to email us at help@pixee.ai with any questions or comments.

### Why does pixee sometimes add new dependencies to my project?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Uppercase Pixee for consistency

Comment thread docs/faqs.md

### Why does pixee sometimes add new dependencies to my project?

We always prefer to use existing controls built into a language, or a control from a well-known and trusted community dependency. When this is not an option, we add our own open source dependency to the project to ensure maximum readability and maintainability. All dependencies utilize permissive open-source licenses.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider expanding on "when this is not an option". Why is not an option? Maybe "when no such dependency exists that meets that criteria"

Comment thread docs/faqs.md

We always prefer to use existing controls built into a language, or a control from a well-known and trusted community dependency. When this is not an option, we add our own open source dependency to the project to ensure maximum readability and maintainability. All dependencies utilize permissive open-source licenses.

Learn more about the [Java Security Toolkit (io.github.pixee.java-security-toolkit) on Maven Central](https://central.sonatype.com/artifact/io.github.pixee/java-security-toolkit/overview).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's another Java toolkit we maintain specifically for xstream.

@dhafley
dhafley merged commit 2591790 into main Aug 9, 2024
@dhafley
dhafley deleted the iss-924 branch August 9, 2024 12:17
dunningdan added a commit that referenced this pull request Sep 7, 2026
#302 cleared 42 of 51 Dependabot alerts by refreshing yarn.lock, but 9
survive because re-resolution provably cannot reach them - their parents
either pin an exact version or cap below the patched release:

  minimatch             parent pins 9.0.3 exactly      -> 9.0.9
  yaml                  parent pins 2.8.1 exactly      -> 2.9.0
  serialize-javascript  parent caps at ^6.0.0          -> 7.1.1
  uuid                  parent caps at ^8.3.2          -> 11.1.1
  qs                    parent caps at ~6.15.1         -> 6.16.0

yarn resolutions are the only lever here, following the existing `got`
entry. This clears 9 of the 11 currently open alerts.

qs is the newest of these: GHSA for it was published Sep 2 and GitHub
raised alerts #197/#198 three minutes after #302 merged, against the
freshly refreshed lockfile. `~6.15.1` excludes 6.16.0, so no future
lockFileMaintenance pass would have fixed it either.

Remaining open after this: #186/#187 image-size, which has no patched
version published upstream. Reached via @docusaurus/mdx-loader at build
time only; tracked for risk acceptance rather than code change.

Verified on Node 24.20.0: yarn build passes (59 documents) and the dev
server serves HTTP 200, which exercises sockjs -> uuid@11, the one bump
here that crosses major versions and that a production build would not
otherwise cover.

Also refreshes the lockFileMaintenance description - it still told the
reader to restore a weekly schedule, which is no longer the intent. No
behavior change; schedule stays "at any time".

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants