JingsongLi commented on PR #10312: URL: https://github.com/apache/paimon/pull/10312#issuecomment-5934740425
Reviewed the lockfile update and the upstream 7.29.1/7.30.0 fixes, then ran `yarn install --frozen-lockfile`, `yarn why undici` and the full `yarn build` on Node 23.11.0. Installation/integrity checks and the production documentation build passed, including validation of 60 Catalog and 10 Management OpenAPI operations. CI is green as well. For the current Paimon dependency path, Undici is brought in only by `@easyops-cn/docusaurus-search-local` → `cheerio`. The search plugin reads generated local HTML and calls `cheerio.load`; it does not call Cheerio's `fromURL` or Undici's HTTP, WebSocket, retry, cache or decompression APIs. The upstream security fixes are valid, but this PR does not demonstrate a reachable Paimon issue or change the generated documentation behavior. Closing this standalone transitive version bump under our current end-to-end value criterion. A concrete affected documentation workflow or reachable security case would justify revisiting it; this does not imply the upstream fixes are unnecessary for applications that use those APIs. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
