Skip to content

chore(deps-dev): bump prettier-plugin-solidity from 2.3.1 to 2.4.1 - #334

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/prettier-plugin-solidity-2.4.1
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/prettier-plugin-solidity-2.4.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps prettier-plugin-solidity from 2.3.1 to 2.4.1.

Release notes

Sourced from prettier-plugin-solidity's releases.

v2.4.1

What's Changed

Full Changelog: prettier-solidity/prettier-plugin-solidity@v2.4.0...v2.4.1

v2.4.0

What's Changed

Better Tests

Format changes

// Unformatted
contract Foo {
    function bar() public {
// Comments in between the chain
        game.
// CONFIG
// Do not touch
config. // Window
// Resolution 1000
resolveWindow = 1000;
begin
.// Comment 1
functionCall(/* Comment about parameter */ parameter)
.// Comment 2
end;
}
}
// prettier-plugin-solidity 2.4.0
contract Foo {
function bar() public {
// Comments in between the chain
game
// CONFIG
// Do not touch
.config // Window
// Resolution 1000
.resolveWindow = 1000;
    begin // Comment 1
        .functionCall(/* Comment about parameter */ parameter) // Comment 2
        .end;
}

</tr></table>

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [prettier-plugin-solidity](https://github.com/prettier-solidity/prettier-plugin-solidity) from 2.3.1 to 2.4.1.
- [Release notes](https://github.com/prettier-solidity/prettier-plugin-solidity/releases)
- [Commits](prettier-solidity/prettier-plugin-solidity@v2.3.1...v2.4.1)

---
updated-dependencies:
- dependency-name: prettier-plugin-solidity
  dependency-version: 2.4.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ APPROVE — #334

chore(deps-dev): bump prettier-plugin-solidity 2.3.1 → 2.4.1 · head 80ae4fb07116。

纯 devDependency 提升,不跑 Codex PK。这一个我要单独说一句,因为它顺手做了别的事:

  • 它把三个包从 registry.npmmirror.com 换回了 registry.npmjs.org:
    prettier-plugin-solidity · @nomicfoundation/slang(1.3.4→1.3.8)· @bytecodealliance/preview2-shim(0.17.9→0.19.0)。
    方向是对的(镜像源 → 官方源),但这说明 base lockfile 是混源的:我数过,
    base 里还剩 16 条 registry.npmmirror.com vs 659 条 registry.npmjs.org。
    混源 lockfile 的问题不在于哪个源更好,而在于 integrity 的可复算性依赖于「谁在提供这个 tarball」;
    剩下那 16 条值得单独一个 PR 一次性收敛掉,而不是靠 dependabot 碰到哪条换哪条。
  • 新增包条目 0 个,只是版本号+源地址变化;3 条新 resolved 各自都带 integrity。
  • 除 Security Audit/CI Success 外全绿。

共同上下文(这五个 dependabot PR 我一起量的,各自单独判)

① Security Audit 这道闸门是红的,而且合了这个 PR 之后还是红的 —— 原因与本 PR 无关。
我读了失败日志,红的是 npm audit 那一步,high=4 critical=0:

high  @nestjs/core               >=7.6.0-next.1
high  @nestjs/platform-express   *
high  @nestjs/swagger            >=5.0.9
high  multer                     <=2.2.0

这四个在 base lockfile 里都是生产依赖(dev=false:multer 2.2.0、@nestjs/* 12.0.1),
而这五个 PR 一行都没碰它们(我对每个 diff 都 grep 过 multer|@nestjs,命中数全是 0)。
所以「等 CI 全绿再合」在这个仓库现在做不到 —— 这是一笔独立的生产依赖欠账,值得单开一个 PR 收。
同一个 job 里还有第二处失败:Path does not exist: trivy-results.sarif(Trivy 那步没产出文件,上传步骤才报错),
这也是先于本 PR 就有的。

② 这五个 PR 的 lockfile 全部基于同一个 blob 4c6d8bb —— 谁先合,另外四个都得 rebase 重生成 lockfile。
Dependabot 会自己 rebase,但rebase 之后的那份 lockfile 没有人审过:合完第一个之后,
后面每一个都值得再看一眼「解析结果有没有变」,而不是沿用今天的读数。

@clestons clestons left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⏸️ 补一条:本仓在 CC-115 B6 零合并冻结中 —— 上面那条 APPROVE 有效,但现在不要合。

(来自 yetanotheraa-validator-a5 会话:自 2026-09-05 起按 DSR 指令 §3 冻结,解冻条件是 DSR 发布 B6 evidence frozen。原因是论文证据链要钉在一个不动的部署上,合任何东西——包括纯 devDependency——都会让已冻结的证据失效。)

唯一的例外判据是「可外部触发 且 不可逆/涉资金密钥」。我上一条 review 里点名的那 4 条 high advisory 够不上这个例外,对方实测过:单一根因是生产依赖 multer 2.2.0,三个 @nestjs/* 只是经 platform-express 的传递效应;四条 advisory 全是 DoS 或上传限额绕过(不可逆=否、涉资金密钥=否),而且本服务全部 32 条 HTTP 路由里 FileInterceptor/FilesInterceptor/AnyFilesInterceptor/@UploadedFile/multipart 命中数全为 0,multer 从未挂到任何路由上 —— 四条 advisory 都要求攻击者发一个 multer 真正会去解析的 multipart 请求,这个前提在本 build 不成立。

同时订正我上一条 review 里一个会让人白跑一趟的暗示:这笔账 npm audit fix 修不掉。multer@latest = 2.3.0(修复版存在),但 @nestjs/platform-express@latest 已经是 12.0.1 且仍把 multer 钉在 2.2.0。上游没跟进,只能在 package.json 加 overrides 强推 2.3.0,再验 platform-express 在 2.3.0 上没有行为回归 —— 这是一个需要判断的改动,不是 dependabot 能代劳的。

另外一条补充(也来自对方实测):本机默认 registry 是 npmmirror,而它没有实现 audit 接口 —— npm audit 直接返回 [NOT_IMPLEMENTED] /-/npm/v1/security/*。所以任何人在本地跑 npm audit 会看到一个长得像「没问题」的错误输出。这让我上一条里说的「收敛混源 lockfile」从整洁问题升级成了量具问题,建议和 audit 欠账并成同一个 follow-up。

解冻之后再推进合并。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant