Skip to content

Conversation

tempoz
Copy link
Contributor

@tempoz tempoz commented Oct 3, 2025

As Dan correctly points out, this is ACTUALLY the latest LTS version of node.

This lets us upgrade docusaurus, which allows us to stop depending on a vulnerable version of tar-fs:

https://github.com/buildbuddy-io/buildbuddy/security/dependabot/223

@tempoz tempoz requested a review from dan-stowell October 3, 2025 16:43
@dan-stowell
Copy link
Contributor

@sluongng points out we may need to upgrade rules_nodejs as well.

@dan-stowell
Copy link
Contributor

What's the correct order to bump this dependency? Merge the change here, then in the internal repo?

@tempoz
Copy link
Contributor Author

tempoz commented Oct 3, 2025

They need to be done at basically the same time :/

@tempoz
Copy link
Contributor Author

tempoz commented Oct 3, 2025

I have had a goal for a while of having internal use buildbuddy to determine these toolchain versions, but it didn't pan when I first tried. Might be worth looking at again.

@tempoz tempoz force-pushed the upgrade-to-node-22 branch from b7d2f90 to ede55d2 Compare October 3, 2025 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants