Skip to content

[ENG-10464] Critical issues in yarn.lock#11627

Open
antkryt wants to merge 5 commits intoCenterForOpenScience:feature/pbs-26-2from
antkryt:fix/ENG-10464-3
Open

[ENG-10464] Critical issues in yarn.lock#11627
antkryt wants to merge 5 commits intoCenterForOpenScience:feature/pbs-26-2from
antkryt:fix/ENG-10464-3

Conversation

@antkryt
Copy link
Contributor

@antkryt antkryt commented Mar 9, 2026

Ticket

Purpose

delete old and unused packages; remove some old UI

Changes

What was removed:
babel-core, babel-loader, markdown stack (@centerforopenscience/markdown-it-atrules, @centerforopenscience/markdown-it-imsize, @centerforopenscience/markdown-it-toc, @centerforopenscience/markdown-it-video, markdown-it, markdown-it-ins-del, markdown-it-sanitizer and all the transitive packages they brought), other unused packages

All the rest vulnerable packages are pulled in mostly by webpack@3, so to "fix" them it's required to migrate to webpack@5 or remove all (or most of the) web UI from the backend (or just upgrade vulnerable packages to the safe version, let me know if I need to do it for this ticket)

Admin package.json is untouched

Side Effects

QE Notes

CE Notes

Documentation

@antkryt antkryt changed the title remove vulnarable packages and some web ui content [ENG-10464] Critical issues in yarn.lock Mar 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant