yarn 1 prints a url.parse() deprecation warning in the js-deps stage #493

Closed
opened 2026-10-03 05:47:47 +02:00 by clawbot · 2 comments
Collaborator

Found while working on #215.

The Dockerfile's js-deps stage runs yarn install with yarn 1.22.22 on node:24.21.0-alpine, and node prints a deprecation warning during it:

[DEP0169] DeprecationWarning: url.parse() behavior is not standardized and prone to errors that have security implications.

The call is inside yarn 1, which is no longer developed, so the warning will not go away by bumping yarn 1. The build still succeeds.

Definition of done:

  • js-deps installs the pinned packages from a lockfile without the deprecation warning, or this issue records why the warning is accepted.

Model: opus-5-5

Found while working on https://git.eeqj.de/sneak/webhooker/issues/215. The `Dockerfile`'s `js-deps` stage runs `yarn install` with yarn 1.22.22 on `node:24.21.0-alpine`, and node prints a deprecation warning during it: `[DEP0169] DeprecationWarning: url.parse() behavior is not standardized and prone to errors that have security implications.` The call is inside yarn 1, which is no longer developed, so the warning will not go away by bumping yarn 1. The build still succeeds. Definition of done: - `js-deps` installs the pinned packages from a lockfile without the deprecation warning, or this issue records why the warning is accepted. Model: opus-5-5
Author
Collaborator

Plan, after #492 lands (it changes the same Dockerfile stage and package.json):

  • Keep yarn, which the JavaScript styleguide REPO_POLICIES.md links to names, but move to the current release line: pin it in package.json's packageManager field with its hash, enable it through the node image's own corepack in the js-deps stage, and install with yarn install --immutable from a regenerated lockfile. ESLint and prettier stay at the versions now pinned.
  • Done when make lint, make fmt-check and the image build show no deprecation warning from the install, the install stays cached until the manifests change, and nothing is installed on the host.
  • If the current yarn prints the same warning, the PR says so instead and this issue records why the warning is accepted; no other package manager is brought in.

Model: opus-5-5

Plan, after https://git.eeqj.de/sneak/webhooker/pulls/492 lands (it changes the same `Dockerfile` stage and `package.json`): - Keep yarn, which the JavaScript styleguide `REPO_POLICIES.md` links to names, but move to the current release line: pin it in `package.json`'s `packageManager` field with its hash, enable it through the node image's own corepack in the `js-deps` stage, and install with `yarn install --immutable` from a regenerated lockfile. ESLint and prettier stay at the versions now pinned. - Done when `make lint`, `make fmt-check` and the image build show no deprecation warning from the install, the install stays cached until the manifests change, and nothing is installed on the host. - If the current yarn prints the same warning, the PR says so instead and this issue records why the warning is accepted; no other package manager is brought in. Model: opus-5-5
Author
Collaborator

Built in #496.

package.json now pins yarn 4.18.1 by version and hash in its packageManager field. The js-deps stage enables it with the node image's own corepack and installs with yarn install --immutable. yarn.lock was regenerated in yarn 4's format from the old one, so every package keeps its locked version, ESLint and prettier included. A new .yarnrc.yml keeps the install in node_modules/, which is where the lint and Markdown stages run the tools from. The Dockerfile comment above the stage and the README's Linting and Docker sections now describe the new install.

  • The install output has no deprecation warning.
  • A second make lint reuses the cached install.
  • A var in static/js/app.js still turns make lint red.
  • Unformatted Markdown still turns make fmt-check red.

Deviation: .yarnrc.yml is a file the plan did not name. Without it, yarn 4 creates no node_modules/.bin.
Judgement call: yarn 4's telemetry stays at its default. yarn sends nothing on its first run, and every install starts in a fresh layer.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/webhooker/pulls/496. `package.json` now pins yarn 4.18.1 by version and hash in its `packageManager` field. The `js-deps` stage enables it with the node image's own corepack and installs with `yarn install --immutable`. `yarn.lock` was regenerated in yarn 4's format from the old one, so every package keeps its locked version, ESLint and prettier included. A new `.yarnrc.yml` keeps the install in `node_modules/`, which is where the lint and Markdown stages run the tools from. The `Dockerfile` comment above the stage and the README's Linting and Docker sections now describe the new install. - The install output has no deprecation warning. - A second `make lint` reuses the cached install. - A `var` in `static/js/app.js` still turns `make lint` red. - Unformatted Markdown still turns `make fmt-check` red. Deviation: `.yarnrc.yml` is a file the plan did not name. Without it, yarn 4 creates no `node_modules/.bin`. Judgement call: yarn 4's telemetry stays at its default. yarn sends nothing on its first run, and every install starts in a fresh layer. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#493