Repository navigation
Declare logger, refresh action pins, drop grunt tooling - #790
Merged
Merged
Conversation
Backlog items 5, 6 and 7. logger (item 5) Jekyll 4.4 requires logger but does not declare it, so it resolved from the standard library and warned on every build. Ruby 3.5 removes it from the default gems, at which point a bundled build without it is expected to fail rather than warn. Declared as `gem "logger", "~> 1.6"`, resolving to 1.7.0; the warning is gone. GitHub Actions pins (item 6) checkout v4 -> v7 (source of the Node 20 annotation) cache v4 -> v6 configure-pages v4 -> v6 deploy-pages v4 -> v5 upload-pages-artifact v3 -> v5 Release notes for the Pages trio show no breaking changes; the majors are Node runtime upgrades and internal dependency bumps. upload-pages-artifact v5 uses upload-artifact v7 internally and deploy-pages v5 is its matching generation, so the three move together. lychee-action and setup-ruby were already current on their floating major tags. grunt tooling (item 7) Delete package.json, Gruntfile.js and .jshintrc, and drop the now-stale Gruntfile.js and package.json entries from the _config.yml exclude list. Nothing referenced them: no workflow, script or page, no package-lock.json and no node_modules. assets/js/scripts.min.js is committed, so no build output is lost. This permanently closes the phantom grunt Dependabot alerts. The pin in 6e817a9 only raised the declared range; with the manifest gone there is nothing left to scan, so the seven grunt-* dependencies still on open-ended ">1.3.0" ranges cannot raise alerts either. Verified: the built site is byte-identical to the previous baseline across all 1242 files, and the logger warning no longer appears. Only the @import Sass deprecation remains, which is deferred by design. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backlog items 5, 6 and 7.
Item 5 — declare
loggerJekyll 4.4 requires
loggerbut does not declare it, so it resolved from thestandard library and warned on every build. Ruby 3.5 removes it from the default
gems, at which point a bundled build without it is expected to fail rather than
warn.
Declared as
gem "logger", "~> 1.6"→ resolves to 1.7.0. Warning is gone.Item 6 — refresh action pins
actions/checkoutactions/cacheactions/configure-pagesactions/deploy-pagesactions/upload-pages-artifactcheckout@v4was the source of the Node 20 deprecation annotation on every run.I checked the release notes before bumping: no breaking changes — the majors are
Node runtime upgrades and internal dependency bumps.
upload-pages-artifactv5uses
upload-artifactv7 internally anddeploy-pagesv5 is its matchinggeneration, so the trio moves together.
lychee-actionandruby/setup-rubywerealready current on their floating major tags.
Item 7 — drop the grunt tooling
Deleted
package.json,Gruntfile.js,.jshintrc, plus the now-staleGruntfile.js/package.jsonentries in the_config.ymlexcludelist.Nothing referenced them — no workflow, script or page, no
package-lock.json, nonode_modules.assets/js/scripts.min.jsis committed, so no build output islost.
This permanently closes the phantom
gruntDependabot alerts. The pin in6e817a9 only raised the declared range; with the manifest gone there is nothing
left to scan, so the seven
grunt-*dependencies still on open-ended">1.3.0"ranges cannot raise alerts either.
Worth noting the theme this tooling belonged to was already gone twice over:
#789 removed
theme: minima, andpackage.jsonhad long claimed to beminimal-mistakes-theme— a third theme the site had not used in years.Verification
loggerwarning no longer appears@importSass deprecation remains, deferred by design (see Clear three of four Sass deprecation categories #789)One thing a PR cannot verify
The deploy workflow only runs on push to
master, so this PR does not exercisethe upgraded Pages actions.
build.ymlcoverscheckout@v7and the Jekyllbuild, but
configure-pages@v6/upload-pages-artifact@v5/deploy-pages@v5run for the first time on merge. They are a coordinated set with no documented
breaking changes, so the risk is low — but worth watching the deploy run, and the
live site, immediately after merging.
🤖 Generated with Claude Code