JingsongLi commented on PR #10312:
URL: https://github.com/apache/paimon/pull/10312#issuecomment-5934740425

   Reviewed the lockfile update and the upstream 7.29.1/7.30.0 fixes, then ran 
`yarn install --frozen-lockfile`, `yarn why undici` and the full `yarn build` 
on Node 23.11.0. Installation/integrity checks and the production documentation 
build passed, including validation of 60 Catalog and 10 Management OpenAPI 
operations. CI is green as well.
   
   For the current Paimon dependency path, Undici is brought in only by 
`@easyops-cn/docusaurus-search-local` → `cheerio`. The search plugin reads 
generated local HTML and calls `cheerio.load`; it does not call Cheerio's 
`fromURL` or Undici's HTTP, WebSocket, retry, cache or decompression APIs. The 
upstream security fixes are valid, but this PR does not demonstrate a reachable 
Paimon issue or change the generated documentation behavior.
   
   Closing this standalone transitive version bump under our current end-to-end 
value criterion. A concrete affected documentation workflow or reachable 
security case would justify revisiting it; this does not imply the upstream 
fixes are unnecessary for applications that use those APIs.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to