Skip to content

Upgrade Docusaurus 2.4.3 → 3.10.2 (clears all website vulnerabilities) - #193

Merged
StefanSteiner merged 1 commit into
upcomingfrom
feat/docusaurus-3
Sep 22, 2026
Merged

StefanSteiner merged 1 commit into
upcomingfrom
feat/docusaurus-3

Conversation

@StefanSteiner

Copy link
Copy Markdown
Collaborator

Summary

Upgrades the docs site from Docusaurus 2.4.3 → 3.10.2. Docusaurus 3's refreshed dependency tree resolves 66 of the 68 Dependabot advisories natively; the remaining two (serialize-javascript, uuid) are pinned via resolutions. yarn audit now reports 0 vulnerabilities.

This supersedes the earlier resolutions workaround — the whole Docusaurus 2 patchwork (including the webpack: 5.94.0 pin, which only existed to dodge 2.4.3's schema-utils v4 build break) is removed.

Changes

  • Deps: @docusaurus/* → ^3.10.2, react/react-dom → ^18.3.1, @mdx-js/react → ^3.1.1, prism-react-renderer → ^2.4.1; swap @tsconfig/docusaurus → @docusaurus/tsconfig; add @types/react ^18; typescript → ~5.6.3.
  • Resolutions: dropped the D2 patchwork; kept only serialize-javascript + uuid pins and an @types/react dedupe (fixes duplicate-React-types tsc errors).
  • prism-react-renderer v2: require('prism-react-renderer').themes.github.
  • MDX v3: converted installation.md Tabs from the mdx-code-block idiom to native JSX (v3 rejects JSX tags spanning fenced blocks). DownloadPicker uses a small documented cast because v3 narrows TabItem.label to string while still rendering ReactNode at runtime (keeps the OS icon labels).
  • Config: migrated onBrokenMarkdownLinks → markdown.hooks.onBrokenMarkdownLinks; added onBrokenAnchors: 'throw' and fixed a pre-existing broken anchor in releases.md (#passingprocesssettings → #process-settings, now caught by D3's anchor checking).
  • ts-node: added a CommonJS override in tsconfig.json so the deploy step's download_links.ts still runs under the new esnext module config.

Test plan

  • yarn install --frozen-lockfile
  • yarn run lint:check (prettier)
  • yarn run typecheck (tsc) — clean
  • yarn build (Docusaurus 3 production build) — success, no warnings
  • yarn ts-node download_links.ts (deploy step) — runs
  • yarn audit — 0 vulnerabilities (was 68)
  • Verified Tabs (installation) and DownloadPicker OS icon labels render in the built HTML
  • CI build job passes
  • Manual browser smoke-test of tabs, download picker, and search (recommended before merge — I could not run a live browser in this environment)

Note

Build + lint + typecheck + rendered-HTML checks all pass, but I could not run a live browser here. A quick manual pass over the deployed preview (tabs, download picker OS detection, Algolia search, dark mode) is worth doing before merge.

Migrates the docs site to Docusaurus 3, which refreshes the transitive
dependency tree and resolves 66 of the 68 Dependabot advisories natively.
The remaining two (serialize-javascript, uuid) are pinned via resolutions.
Net result: `yarn audit` reports 0 vulnerabilities.

Changes:
- Bump @docusaurus/* to ^3.10.2, react/react-dom to ^18, @mdx-js/react to
  ^3, prism-react-renderer to ^2; swap @tsconfig/docusaurus for
  @docusaurus/tsconfig; add @types/react ^18; bump typescript to ~5.6.3.
- Drop the Docusaurus 2 resolutions patchwork (incl. the webpack 5.94.0
  pin, which was only needed to dodge 2.4.3's schema-utils v4 build break);
  keep only serialize-javascript + uuid pins and an @types/react dedupe.
- prism-react-renderer v2 import (themes.github).
- MDX v3: convert installation.md Tabs from the mdx-code-block idiom to
  native JSX; DownloadPicker uses a documented cast since v3 narrows
  TabItem.label to string while still rendering ReactNode.
- Migrate onBrokenMarkdownLinks to markdown.hooks; add onBrokenAnchors:
  'throw' and fix a pre-existing broken anchor in releases.md.
- Add a ts-node CommonJS override so the deploy step's download_links.ts
  still runs under the new esnext module config.

Verified: yarn install --frozen-lockfile, lint:check, typecheck, build,
ts-node download_links.ts, and yarn audit (0 vulnerabilities) all pass;
Tabs and DownloadPicker icons render correctly in the built HTML.
@StefanSteiner
StefanSteiner merged commit ad119c4 into upcoming Sep 22, 2026
5 checks passed
@StefanSteiner
StefanSteiner deleted the feat/docusaurus-3 branch September 22, 2026 03:48
StefanSteiner added a commit that referenced this pull request Sep 22, 2026
…ies (#193) (#194)

Migrates the docs site to Docusaurus 3, which refreshes the transitive
dependency tree and resolves 66 of the 68 Dependabot advisories natively.
The remaining two (serialize-javascript, uuid) are pinned via resolutions.
Net result: `yarn audit` reports 0 vulnerabilities.

Changes:
- Bump @docusaurus/* to ^3.10.2, react/react-dom to ^18, @mdx-js/react to
  ^3, prism-react-renderer to ^2; swap @tsconfig/docusaurus for
  @docusaurus/tsconfig; add @types/react ^18; bump typescript to ~5.6.3.
- Drop the Docusaurus 2 resolutions patchwork (incl. the webpack 5.94.0
  pin, which was only needed to dodge 2.4.3's schema-utils v4 build break);
  keep only serialize-javascript + uuid pins and an @types/react dedupe.
- prism-react-renderer v2 import (themes.github).
- MDX v3: convert installation.md Tabs from the mdx-code-block idiom to
  native JSX; DownloadPicker uses a documented cast since v3 narrows
  TabItem.label to string while still rendering ReactNode.
- Migrate onBrokenMarkdownLinks to markdown.hooks; add onBrokenAnchors:
  'throw' and fix a pre-existing broken anchor in releases.md.
- Add a ts-node CommonJS override so the deploy step's download_links.ts
  still runs under the new esnext module config.

Verified: yarn install --frozen-lockfile, lint:check, typecheck, build,
ts-node download_links.ts, and yarn audit (0 vulnerabilities) all pass;
Tabs and DownloadPicker icons render correctly in the built HTML.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant