Skip to content

Conversation

@avivkeller
Copy link
Member

From what I can tell, we do not need this as a dependency.

https://github.com/nodejs/nodejs.org/blob/main/.husky/pre-commit downloads the latest version via pnpm dlx, and ignores the locally installed version, so why do we even have a locally installed version?

Copilot AI review requested due to automatic review settings May 9, 2025 22:57
@avivkeller avivkeller requested review from a team as code owners May 9, 2025 22:57
@vercel
Copy link

vercel bot commented May 9, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Updated (UTC)
nodejs-org ✅ Ready (Inspect) Visit Preview May 9, 2025 10:57pm

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR removes the locally installed lint-staged dependency as it is no longer required, given that the latest version is automatically downloaded via pnpm dlx.

  • Removed the lint-staged dependency from package.json.
  • Updated the dependabot configuration by eliminating lint-staged from its tracked dependencies.

Reviewed Changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.

File Description
package.json Removed the lint-staged dependency from the dependencies list.
.github/dependabot.yml Removed lint-staged from the list of dependencies monitored by dependabot.
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported
Comments suppressed due to low confidence (2)

package.json:35

  • Removing the lint-staged dependency is appropriate given that it's no longer required; ensure that any related scripts or configuration are updated accordingly.
"lint-staged": "15.5.1",

.github/dependabot.yml:29

  • The removal of lint-staged from dependabot's configuration aligns with the dependency removal; confirm that dependabot is not expected to monitor this package elsewhere.
- lint-staged

@codecov-commenter
Copy link

codecov-commenter commented May 9, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 74.84%. Comparing base (10a07a1) to head (4670699).
Report is 1 commits behind head on main.

✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #7738   +/-   ##
=======================================
  Coverage   74.84%   74.84%           
=======================================
  Files          98       98           
  Lines        7888     7888           
  Branches      200      200           
=======================================
  Hits         5904     5904           
  Misses       1983     1983           
  Partials        1        1           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link
Member

@MattIPv4 MattIPv4 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am -1 on removing this, we should update the husky command to use the locally installed version. Pulling down the latest on every commit feels very dangerous

@AugustinMauroy
Copy link
Member

I agree with Matt

@ovflowd
Copy link
Member

ovflowd commented May 12, 2025

I am -1 on removing this, we should update the husky command to use the locally installed version. Pulling down the latest on every commit feels very dangerous

Agreed. Husky should run local version, we should reduce attack vectors.

@avivkeller
Copy link
Member Author

Got it. I'll replace this PR with one that replaces dlx with exec.

@avivkeller avivkeller closed this May 12, 2025
@avivkeller avivkeller deleted the chore/remove-lint-staged branch May 12, 2025 22:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants