dengliming opened a new issue, #654:
URL: https://github.com/apache/shenyu-dashboard/issues/654

   ## Description
   The declared and tested Node.js versions of the dashboard are far behind 
what the toolchain and the Node.js release schedule support:
   
   - `package.json` declares `"engines": { "node": ">=8.0.0" }` and the README 
lists "node v8.0+" as the prerequisite.
   - `build.yml` runs the matrix `[12.x, 14.x, 16.x, 18.x, 20.x]` with 
`actions/checkout@v2` / `actions/setup-node@v1`; `deploy.yml` builds on Node 20 
with `actions/[email protected]`; `sync-to-main.yml` uses Node 16.
   - Several locked dependencies already require newer runtimes: 
`[email protected]` (#583) declares `node >=20.18.1`, 
`whatwg-encoding`/`whatwg-mimetype` declare `node >=18`, and #589 had to switch 
`deploy.yml` to `npm ci` because a fresh resolve pulled `commander@15` (`node 
>=22.12.0`). Node 12/14/16 in the matrix therefore only pass because `npm 
install` merely warns on unmet `engines`.
   - Per the Node.js release schedule (as of 2026-09-24): Node 18 reached 
end-of-life on 2025-04-30 and Node 20 on 2026-04-30. Node 22 is in Maintenance 
LTS until 2027-04-30, Node 24 is the Active LTS (maintenance until 2028-04-30), 
and Node 26 becomes LTS on 2026-10-28.
   
   So the project currently builds and deploys on an EOL runtime and advertises 
support for versions that its own dependencies no longer support.
   
   ## Location
   (Refers to `master @ 83969a5`.)
   - `package.json:100-102` (`engines`)
   - `README.md:11` (prerequisite)
   - `.github/workflows/build.yml:16-22` (matrix and outdated actions)
   - `.github/workflows/deploy.yml:21-23`
   - `.github/workflows/sync-to-main.yml:21-23`
   
   ## Impact
   - Security fixes in Node.js no longer reach the CI/deploy environment (Node 
20 is EOL).
   - Contributors on Node 8-16 get a misleading "supported" signal and then hit 
dependency engine errors or `npm ci` lockfile mismatches.
   - `actions/checkout@v2` and `actions/setup-node@v1`/`v2.4.0` run on the 
deprecated Node 16 Actions runtime and will be blocked by GitHub.
   
   ## Suggested fix
   1. Set the minimum supported version to the oldest non-EOL LTS: `"engines": 
{ "node": ">=22.12.0" }` (22.12 is the floor required by `commander@15`), and 
add an `.nvmrc` / `.node-version` with `22`.
   2. Update the README prerequisite to "Node.js 22 LTS or newer (24 
recommended)".
   3. Change the `build.yml` matrix to `[22.x, 24.x]` and bump 
`actions/checkout@v4` and `actions/setup-node@v4` (with `cache: npm`); switch 
it to `npm ci` for reproducible installs.
   4. Build and deploy on Node 24 in `deploy.yml` and `sync-to-main.yml` with 
`actions/setup-node@v4`.
   5. Verify that the `roadhog` (webpack) build works on Node 22/24 without 
`--openssl-legacy-provider`; if not, add the flag via `NODE_OPTIONS` in the 
scripts or, preferably, plan the migration off `roadhog`, which is unmaintained.
   
   ## Related existing
   - #583 (undici bump introduced the `node >=20.18.1` requirement)
   - #589 (deploy workflow switched to `npm ci` because of `commander@15` 
requiring Node >=22.12)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to