Uh oh!
There was an error while loading. Please reload this page.
chore(ci): Move monorepo to nx - #19325
Conversation
Uh oh!
There was an error while loading. Please reload this page.
Codecov Results 📊Generated by Codecov Action |
node-overhead report 🧳Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
|
# Conflicts: # lerna.json # package.json # yarn.lock
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Remove lerna and replace its two uses with lighter alternatives: - **`lerna version`** → `scripts/bump-version.js` — a ~80-line Node script that updates all workspace `package.json` versions and `@sentry-internal/*` cross-references to the exact new version. Modeled after [sentry-javascript#19325](getsentry/sentry-javascript#19325). - **`lerna run build:tarball`** → `turbo run build:tarball` — Turborepo is already used for all other cross-package tasks. Lerna was pulling in a large transitive dependency tree including packages with known vulnerabilities. This removes ~2,300 lines from `yarn.lock`. ### Dependabot alerts resolved **Fully resolved** (vulnerable package completely removed from lockfile): | Alert | Severity | Package | Summary | |-------|----------|---------|---------| | #217 | HIGH | `tar` | Symlink Path Traversal via Drive-Relative Linkpath | | #216 | HIGH | `tar` | Hardlink Path Traversal via Drive-Relative Linkpath | | #185 | HIGH | `tar` | Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain | | #176 | HIGH | `tar` | Arbitrary File Creation/Overwrite via Hardlink Path Traversal | | #174 | HIGH | `tar` | Race Condition via Unicode Ligature Collisions on macOS APFS | | #172 | HIGH | `tar` | Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization | | #137 | HIGH | `axios` | SSRF and Credential Leakage via Absolute URL | **Partially resolved** (some vulnerable entries removed, but the package still exists via other dependency chains): | Alert | Severity | Package | Remaining source | |-------|----------|---------|-----------------| | #213, #208, #207, #205 | HIGH | `minimatch` | `markdownlint-cli`, `vite-plugin-dts` still pull in vulnerable versions | | #161 | HIGH | `glob` | `markdownlint-cli`, `web-ext-run` still pull in vulnerable versions | | #136, #135 | CRITICAL | `form-data` | `jest` (via jsdom) still pulls in `form-data@3.0.2` | | #158, #157 | MEDIUM | `js-yaml` | `@changesets/cli`, `jest` still pull in `js-yaml@3.14.1` | The partially resolved alerts will be addressed in later phases (Phase 6: mop up remaining — bumping `markdownlint-cli`, `@changesets/cli`, `jest`/rrvideo, etc.). Part of the ongoing effort to resolve all Dependabot alerts on this repo. Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
lerna run→nx run-many). Lerna was already using Nx under the hood, so this removes the wrapper layer and uses Nx directly.lerna versionwith a customscripts/bump-version.jsfor release version bumping. The script replicateslerna version --force-publish --exact --no-git-tag-version --no-push– bumps all workspace package versions and updates internal dependency references to exact versions. Also added some unit tests.lerna.json,lernadevDependency) and addnxas a direct devDependency (22.5.0).job_check_lockfile) that runs in parallel with the build.yarn builddoesn't hang waiting for ESC..version.jsonas a single source of truth for the current version (this works well with triggering gitflow)CLAUDE.md,CONTRIBUTING.md,.cursor/rules) to reflect the migration.Closes#19340 (added automatically)