Skip to content

feat(preview): support loading the Preview library from npm - #4695

Open
jackiejou wants to merge 4 commits into
box:masterfrom
jackiejou:npm-content-preview
Open

feat(preview): support loading the Preview library from npm#4695
jackiejou wants to merge 4 commits into
box:masterfrom
jackiejou:npm-content-preview

Conversation

@jackiejou

@jackiejou jackiejou commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds an opt-in path that loads Box Content Preview from the box-content-preview npm package, gated on features.useNpmBoxContentPreview. Hosts that want the npm path pass a loader:

import { loadBoxContentPreview } from 'box-ui-elements/es/elements/content-preview/loadBoxContentPreview';

<ContentPreview
    features={{ useNpmBoxContentPreview: true }}
    loadPreviewModule={loadBoxContentPreview}
    pdfjsWorkerSrc={new URL('box-content-preview/pdf.worker.min.mjs', import.meta.url).toString()}
/>
  • Flag off (default): CDN preview.js / preview.css and global.Box.Preview, same as today.
  • Flag on: the host-supplied loadPreviewModule loads the npm Preview export and its CSS. ContentPreview does not import box-content-preview itself, so CDN-only apps keep a build that does not resolve that package.
  • loadPreviewModule is required when the flag is on. A missing loader, a failed import, or a module without Preview ends loading, renders the error state, and calls onError.
  • npm show() options include location (staticBaseURI, version, locale) from the existing static/language props, and optional pdfjs.workerSrc from pdfjsWorkerSrc.
  • A function token is forwarded as annotatorToken so box-annotations keeps the write resolver. A string token is omitted so annotations use the resolved read token.
  • DEFAULT_PREVIEW_VERSION is 3.79.0.

box-content-preview is an optional peer (^3.79.0) and a devDependency (3.79.0). CDN-only consumers do not install it. npm consumers install a matching peer and bundle a pdfjs worker for that version.

Why

Hosts can load Preview from their own bundle. The loader stays outside ContentPreview so the optional peer is not pulled into every es/ consumer (including Content Explorer via PreviewDialog).

Test plan

  • Flag off: CDN script and stylesheet still inject; global.Box.Preview is used.
  • Flag on with loadPreviewModule: no CDN tags; npm Preview is used; location and pdfjs.workerSrc match the props (including staticHost with a trailing slash).
  • Flag on without loadPreviewModule, or a loader that rejects / has no Preview export: error state and onError.
  • String token: annotatorToken is omitted. Function token: the same function is forwarded.
  • CDN-only app without box-content-preview installed still builds.
  • Unit tests in ContentPreview.test.js for the npm and CDN paths.

@jackiejou
jackiejou requested review from a team as code owners July 14, 2026 18:07
@coderabbitai

coderabbitai Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 98d8ae5f-33d8-4024-95cd-837a2740c6ed

📥 Commits

Reviewing files that changed from the base of the PR and between 7ae9297 and 4aa4b2a.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • .storybook/main.ts
  • package.json
  • scripts/webpack.config.js
  • src/elements/content-preview/ContentPreview.js
  • src/elements/content-preview/__tests__/ContentPreview.test.js
🚧 Files skipped from review as they are similar to previous changes (4)
  • .storybook/main.ts
  • package.json
  • scripts/webpack.config.js
  • src/elements/content-preview/tests/ContentPreview.test.js

Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review.


Walkthrough

ContentPreview can load box-content-preview through npm under a feature flag, pass location and PDF.js worker options, handle loading failures, and retain CDN loading otherwise. Package metadata, build aliases, mocks, and tests support the new path.

Changes

NPM preview integration

Layer / File(s) Summary
Optional package and build resolution
package.json, .storybook/main.ts, scripts/webpack.config.js
box-content-preview is declared as an optional peer and development dependency. Storybook and Webpack aliases resolve local source paths, and the package is excluded from one Babel transform branch.
Feature-flagged preview loading
src/elements/content-preview/ContentPreview.js, src/elements/content-preview/__tests__/ContentPreview.test.js
ContentPreview selects npm or CDN assets, caches the imported module, detects readiness, and reports npm loading failures through the existing error path. Tests cover both loading paths and failure handling.
Viewer options and validation
src/elements/content-preview/ContentPreview.js, src/elements/content-preview/__tests__/ContentPreview.test.js
The npm preview receives location data and an optional PDF.js worker source. Tests cover URL normalization, option forwarding, and omission of unset PDF.js options.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to 4aa4b

The change adds an opt-in npm loading path while preserving the default CDN behavior, with reported unit, Flow, lint, webpack, and Storybook checks passing; no actionable merge-blocking risk remains beyond normal review.

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant ContentPreview
  participant box_content_preview
  participant Preview
  User->>ContentPreview: Request content preview
  ContentPreview->>box_content_preview: Dynamically import package and styles
  box_content_preview-->>ContentPreview: Return Preview export
  ContentPreview->>Preview: Call show with location and pdfjs options
  Preview-->>User: Display preview
Loading

Suggested reviewers: reneshen0328

Poem

A rabbit hops through npm’s bright door,
Preview loads where CDN was before.
Worker paths curl, locations align,
Errors are caught in a tidy line.
“Hop, hop!” tests cheer in moonlight divine.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the primary change: loading the Preview library from npm.
Description check ✅ Passed The description explains the change, behavior, rationale, dependencies, error handling, and test plan in a relevant structure.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

ahorowitz123
ahorowitz123 previously approved these changes Jul 14, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
src/elements/content-preview/ContentPreview.js (1)

510-538: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

loadNpmPreview() isn't reentrant-safe, and there's no visible unmount guard.

The guard if (this.npmPreviewModule) return; only checks the final cached result, not whether a load is already in flight. If this method is ever invoked a second time before the first Promise.all resolves (e.g. a future retry path, or as seen in the test at ContentPreview.test.js lines 2555-2565 where componentDidMount's fire-and-forget call races an explicit await instance.loadNpmPreview()), both calls will independently import the module, assign npmPreviewModule, and call this.loadPreview() — duplicating new Preview()/.show() invocations. Separately, nothing here appears to check whether the component is still mounted before the post-await setState/loadPreview()/error-path calls.

♻️ Proposed fix: memoize the in-flight promise
-    loadNpmPreview = async (): Promise<void> => {
-        if (this.npmPreviewModule) {
-            return;
-        }
-
-        let previewModule;
-        try {
-            [previewModule] = await Promise.all([
-                import(/* webpackChunkName: "box-content-preview" */ 'box-content-preview'),
-                import(/* webpackChunkName: "box-content-preview" */ 'box-content-preview/styles.css'),
-            ]);
-        } catch {
-            this.onNpmPreviewLoadError('Failed to load the box-content-preview module');
-            return;
-        }
-
-        if (!previewModule.Preview) {
-            this.onNpmPreviewLoadError('box-content-preview module has no Preview export');
-            return;
-        }
-
-        this.npmPreviewModule = previewModule;
-        this.loadPreview();
-    };
+    loadNpmPreview = (): Promise<void> => {
+        if (this.npmPreviewModule) {
+            return Promise.resolve();
+        }
+        if (this.npmPreviewLoadPromise) {
+            return this.npmPreviewLoadPromise;
+        }
+
+        this.npmPreviewLoadPromise = (async () => {
+            let previewModule;
+            try {
+                [previewModule] = await Promise.all([
+                    import(/* webpackChunkName: "box-content-preview" */ 'box-content-preview'),
+                    import(/* webpackChunkName: "box-content-preview" */ 'box-content-preview/styles.css'),
+                ]);
+            } catch {
+                this.onNpmPreviewLoadError('Failed to load the box-content-preview module');
+                return;
+            }
+
+            if (!previewModule.Preview) {
+                this.onNpmPreviewLoadError('box-content-preview module has no Preview export');
+                return;
+            }
+
+            this.npmPreviewModule = previewModule;
+            this.loadPreview();
+        })();
+
+        return this.npmPreviewLoadPromise;
+    };

Please also confirm whether setState/loadPreview() calls after the await are already guarded against post-unmount execution elsewhere in this class (e.g. in componentWillUnmount); if not, this same pattern would benefit from a mount-check.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/elements/content-preview/ContentPreview.js` around lines 510 - 538,
Update loadNpmPreview to memoize and reuse an in-flight loading promise, so
concurrent callers perform only one import and one subsequent loadPreview
invocation. Ensure the promise reference is cleared appropriately after
completion, preserve existing module and error handling, and verify the class’s
componentWillUnmount or equivalent lifecycle state prevents post-await error
handling or loadPreview execution after unmount; add the necessary mounted guard
if none exists.
src/elements/content-preview/__tests__/ContentPreview.test.js (1)

2620-2623: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

jest.dontMock may not safely restore the original virtual mock for later tests.

jest.dontMock('box-content-preview') tells Jest to resolve the real module on next require(), which is a different operation from re-registering the original hoisted jest.mock(...) factory. Since box-content-preview isn't installed in CI, if any test added after this block ever re-imports box-content-preview relying on the top-of-file virtual mock, it could fail to resolve. It works today only because this appears to be the last describe block in the file.

♻️ More robust cleanup: re-register the healthy mock instead of `dontMock`
             afterEach(() => {
-                jest.dontMock('box-content-preview');
                 jest.resetModules();
+                jest.doMock(
+                    'box-content-preview',
+                    () => ({
+                        Preview: function Preview() {
+                            this.addListener = jest.fn();
+                            this.destroy = jest.fn();
+                            this.removeAllListeners = jest.fn();
+                            this.show = jest.fn();
+                            this.updateFileCache = jest.fn();
+                        },
+                    }),
+                    { virtual: true },
+                );
             });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/elements/content-preview/__tests__/ContentPreview.test.js` around lines
2620 - 2623, Update the afterEach cleanup in the ContentPreview test block to
re-register the original virtual mock for box-content-preview instead of calling
jest.dontMock. Preserve jest.resetModules so later tests resolve the same
hoisted mock factory safely.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@src/elements/content-preview/__tests__/ContentPreview.test.js`:
- Around line 2620-2623: Update the afterEach cleanup in the ContentPreview test
block to re-register the original virtual mock for box-content-preview instead
of calling jest.dontMock. Preserve jest.resetModules so later tests resolve the
same hoisted mock factory safely.

In `@src/elements/content-preview/ContentPreview.js`:
- Around line 510-538: Update loadNpmPreview to memoize and reuse an in-flight
loading promise, so concurrent callers perform only one import and one
subsequent loadPreview invocation. Ensure the promise reference is cleared
appropriately after completion, preserve existing module and error handling, and
verify the class’s componentWillUnmount or equivalent lifecycle state prevents
post-await error handling or loadPreview execution after unmount; add the
necessary mounted guard if none exists.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 054ec505-e485-4dfd-b492-8d516308a5cf

📥 Commits

Reviewing files that changed from the base of the PR and between c5e0f55 and 0c91689.

📒 Files selected for processing (5)
  • .flowconfig
  • flow/BoxContentPreviewStub.js.flow
  • package.json
  • src/elements/content-preview/ContentPreview.js
  • src/elements/content-preview/__tests__/ContentPreview.test.js

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/elements/content-preview/ContentPreview.js`:
- Around line 515-538: Update the catch block in loadNpmPreview to capture the
thrown import error and pass its details to onNpmPreviewLoadError instead of
discarding it. Preserve the existing early return and distinguish
module-versus-stylesheet failures when possible so downstream onError/logging
reflects the original cause.
- Around line 544-552: Normalize staticPath at the URL join points in
getNpmPreviewLocation() and getBasePath(), removing leading and trailing slashes
before concatenation so preview asset URLs contain exactly one separator. Apply
the same behavior consistently in both methods without changing the surrounding
host, locale, or version handling.
- Around line 1092-1102: Guard the npm preview rendering flow so
componentDidUpdate/loadPreview cannot instantiate a Preview before
loadNpmPreview has completed. In the Preview selection and construction path,
require a loaded npm preview module when npmPreviewModule is enabled; otherwise
defer or return until it is available, while preserving the existing
global.Box.Preview fallback for non-npm previews.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: c5018b90-385b-4ff3-9f4e-95525969d71d

📥 Commits

Reviewing files that changed from the base of the PR and between 0c91689 and 4c3af68.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • .storybook/main.ts
  • package.json
  • scripts/webpack.config.js
  • src/elements/content-preview/ContentPreview.js
  • src/elements/content-preview/__tests__/ContentPreview.test.js
🚧 Files skipped from review as they are similar to previous changes (2)
  • package.json
  • src/elements/content-preview/tests/ContentPreview.test.js

Comment thread src/elements/content-preview/ContentPreview.js
Comment thread src/elements/content-preview/ContentPreview.js Outdated
Comment thread src/elements/content-preview/ContentPreview.js Outdated
@jackiejou
jackiejou force-pushed the npm-content-preview branch from 4c3af68 to dfed52c Compare July 14, 2026 22:59

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
src/elements/content-preview/ContentPreview.js (1)

546-554: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

staticPath still isn't normalized before concatenation.

trailingSlash only guards the join between staticHost and staticPath; it doesn't strip a leading/trailing slash already present on staticPath itself. A caller-supplied staticPath of /foo/ or foo/ produces a double slash in staticBaseURI, which can break asset resolution in the npm-loaded viewer. This was flagged previously and remains unresolved (no "Addressed" marker, unlike the two other prior findings on this file).

🩹 Proposed fix to normalize staticPath
     getNpmPreviewLocation(): { locale: string, staticBaseURI: string, version: string } {
         const { language, previewLibraryVersion, staticHost, staticPath } = this.props;
-        const trailingSlash = staticHost.endsWith('/') ? '' : '/';
+        const normalizedHost = staticHost.replace(/\/+$/, '');
+        const normalizedPath = staticPath.replace(/^\/+|\/+$/g, '');
         return {
             locale: language,
-            staticBaseURI: `${staticHost}${trailingSlash}${staticPath}/`,
+            staticBaseURI: `${normalizedHost}/${normalizedPath}/`,
             version: previewLibraryVersion,
         };
     }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/elements/content-preview/ContentPreview.js` around lines 546 - 554,
Update getNpmPreviewLocation to normalize staticPath before constructing
staticBaseURI: remove leading and trailing slashes, then concatenate the
normalized value with staticHost and the existing separator so inputs such as
“/foo/” and “foo/” produce a single-slash path.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Duplicate comments:
In `@src/elements/content-preview/ContentPreview.js`:
- Around line 546-554: Update getNpmPreviewLocation to normalize staticPath
before constructing staticBaseURI: remove leading and trailing slashes, then
concatenate the normalized value with staticHost and the existing separator so
inputs such as “/foo/” and “foo/” produce a single-slash path.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: af909572-a4c9-45e8-aff2-274d95205386

📥 Commits

Reviewing files that changed from the base of the PR and between 4c3af68 and dfed52c.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • .storybook/main.ts
  • package.json
  • scripts/webpack.config.js
  • src/elements/content-preview/ContentPreview.js
  • src/elements/content-preview/__tests__/ContentPreview.test.js
🚧 Files skipped from review as they are similar to previous changes (3)
  • package.json
  • scripts/webpack.config.js
  • src/elements/content-preview/tests/ContentPreview.test.js

@jackiejou
jackiejou force-pushed the npm-content-preview branch from dfed52c to c5a2831 Compare July 15, 2026 00:11
@socket-security

socket-security Bot commented Jul 15, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​box-content-preview@​3.79.0811001009680

View full report

@socket-security

socket-security Bot commented Jul 15, 2026

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/elements/content-preview/ContentPreview.js`:
- Around line 515-531: Guard the asynchronous loadNpmPreview flow with the
component’s mounted/destroyed state after the dynamic imports resolve or reject,
before invoking onNpmPreviewLoadError, loadPreview, or any setState-triggering
logic. Update componentWillUnmount to mark the instance destroyed, and ensure
both success and failure paths return without acting once unmounted.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 1e2de9b7-718c-4542-8c78-fcc3610e1122

📥 Commits

Reviewing files that changed from the base of the PR and between dfed52c and c5a2831.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (5)
  • .storybook/main.ts
  • package.json
  • scripts/webpack.config.js
  • src/elements/content-preview/ContentPreview.js
  • src/elements/content-preview/__tests__/ContentPreview.test.js
🚧 Files skipped from review as they are similar to previous changes (4)
  • package.json
  • scripts/webpack.config.js
  • .storybook/main.ts
  • src/elements/content-preview/tests/ContentPreview.test.js

Comment thread src/elements/content-preview/ContentPreview.js
ahorowitz123
ahorowitz123 previously approved these changes Jul 15, 2026
Comment thread package.json Outdated
Comment on lines +479 to +483
if (this.shouldUseNpmPreview()) {
this.loadNpmPreview();
} else {
this.loadStylesheet();
this.loadScript();

@reneshen0328 reneshen0328 Jul 15, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[question] Eventually shouldUseNpmPreview feature related code will be cleaned up I assume? In that case, will other consumer that has been leveraging the CDN script also be forced to switch to using npm installed version only?

Comment thread src/elements/content-preview/ContentPreview.js
Comment thread .storybook/main.ts
Comment thread scripts/webpack.config.js
Comment thread yarn.lock
reneshen0328
reneshen0328 previously approved these changes Jul 15, 2026

@reneshen0328 reneshen0328 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left some questions but nothing is blocking this PR

Comment thread yarn.lock
Comment thread yarn.lock Outdated
Comment thread yarn.lock
Comment thread yarn.lock
@reneshen0328
reneshen0328 self-requested a review July 15, 2026 22:03
@reneshen0328
reneshen0328 dismissed their stale review July 15, 2026 23:05

Dismiss until box-content-preview fixes all critical and high security vuln

@jackiejou
jackiejou force-pushed the npm-content-preview branch from c5a2831 to 4aa4b2a Compare August 20, 2026 18:46
@coderabbitai

coderabbitai Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

Hosts opt in with useNpmBoxContentPreview and pass loadPreviewModule
imported from loadBoxContentPreview.js. The optional peer stays out of
the ContentPreview module graph. Preview assets default to 3.79.0.
@jackiejou
jackiejou force-pushed the npm-content-preview branch from c45e6b6 to 041e395 Compare August 21, 2026 00:08
Visual stories load preview.js from the default library version.
The extra delay lets the CDN script and pdf.js worker finish before capture.
A function token stays the write resolver for box-annotations.
A string token is omitted so annotations receive the resolved read token.
Preview visual stories use the global 500ms capture delay.

@reneshen0328 reneshen0328 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Love it, thanks for addressing all the dependencies vuln. We've discussed this already, but I just want to emphasize this once more so we keep an eye out on these dependencies: npmlog / gauge / are-we-there-yet are all deprecated by npm which could potentially be a maintanance issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants