Remove unused gulp-sourcemaps dependency - #14729
Conversation
There was a problem hiding this comment.
🟢 Approval recommended
The dependency and all usages are removed consistently without affecting metadata generation.
Pull request overview
Removes unused source-map initialization from localization pipelines and eliminates its vulnerable dependency chain.
Changes:
- Removes
gulp-sourcemapsusage and dependency. - Prunes related transitive packages from the lockfile.
- Preserves existing localization pipeline behavior.
File summaries
| File | Description |
|---|---|
Extension/gulpfile.js |
Removes source-map initialization from localization tasks. |
Extension/package.json |
Removes the unused development dependency. |
Extension/yarn.lock |
Prunes gulp-sourcemaps and orphaned transitive dependencies. |
Review details
- Files reviewed: 2/3 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Sean McManus (sean-mcmanus)
left a comment
There was a problem hiding this comment.
✨Copilot (agent165): Reviewed at a7bd689 against base 2f25880, with local verification.
The core change is correct. [email protected]'s createMetaDataFiles() calls processFile(file.contents.toString('utf8')) with no source-map argument, so the maps were never consumed — only rewriteLocalizeCalls() reads file.sourceMap, and this gulpfile does not use it. The transpiled JS is also filtered out of both pipelines before gulp.dest, so it never reaches disk.
Empirical A/B: with node_modules installed from the base lockfile and only gulpfile.js swapped, gulp translations-generate and gulp translations-export produce byte-identical output (180 files under dist/, and the 312,756-byte vscode-cpptools.xlf). Re-running both at this head after yarn install --frozen-lockfile reproduces the same outputs. yarn test-yarn-lock and yarn verify-yarn-lock pass, and gulp-sourcemaps, source-map-resolve, and decode-uri-component are gone from node_modules.
No debugging regression: gulp-typescript already forces inlineSourceMap: false / sourceMap: true at project creation and then sets sourceMap from whether inputs carry a map, so this only stops an unused map from being generated. Shipped source maps still come from tsc --build (inlineSourceMap) and webpack (devtool: 'source-map').
Security rationale checks out: [email protected] is still covered by GHSA-vcc3-ghjq-m6fr (<= 0.4.2, patched in 0.5.0), so calling it vulnerable is accurate even though it postdates the older GHSA-w573-4hg7-7wgq fix.
One [Minor] follow-through comment on the leftover resolutions entries. Build-time-only change with no product-code impact; low release risk.
* Use npm ci in issue workflows (#14702) * Pin the Yarn bootstrap and add SHA-512 lock checksums (#14703) * Add SHA-512 checksums to yarn.lock * Pin the Yarn bootstrap install * Register LLVM component for LLDB-MI (#14704) * Add xobjgen to gitignore (for Linux/Mac). (#14707) * Retry transient Yarn install failures (#14708) * Ensure the language client is always ready before using it (#14617) * Update 1.34.0 changelog (#14710) * Update changelog and version for 1.34.1 (#14714) * Update clang-tidy checks to 23.1.0 (#14713) * Use native file type mappings for TypeScript-side classification (#14711) * Add 1.34.2 changelog (#14722) * Add 1.34.2 changelog * Remove ignored network isolation policy (#14728) * Bump fast-uri from 3.1.5 to 3.1.6 in /ExtensionPack (#14731) Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.6. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.5...v3.1.6) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump @xmldom/xmldom from 0.8.13 to 0.8.15 in /Extension (#14733) Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.13 to 0.8.15. - [Release notes](https://github.com/xmldom/xmldom/releases) - [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md) - [Commits](xmldom/xmldom@0.8.13...0.8.15) --- updated-dependencies: - dependency-name: "@xmldom/xmldom" dependency-version: 0.8.15 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump browserslist from 4.28.1 to 4.28.8 in /Extension (#14732) Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.1 to 4.28.8. - [Release notes](https://github.com/browserslist/browserslist/releases) - [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md) - [Commits](browserslist/browserslist@4.28.1...4.28.8) --- updated-dependencies: - dependency-name: browserslist dependency-version: 4.28.8 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Remove unused gulp-sourcemaps dependency (#14729) * Remove unused gulp-sourcemaps dependency * Remove orphaned dependency resolutions * Fix custom configuration provider regression (#14725) * Restore custom configuration provider checks * Ignore empty crash report files (#14730) * Ignore empty crash report files * Preserve pending crash reads across clients * Keep crash writing state for pending reports * Fix fast-uri dependency. (#14735) * Fix fast-uri dependency. * Also for Themes. * Implement session state tracking for "Run and Debug" button when Inte… (#14719) * Implement session state tracking for "Run and Debug" button when IntelliSense is disabled and add corresponding tests * Enhance session state tracking for build and debug by updating folder open status and adding tests * Fix build and debug folder session state tracking * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <[email protected]> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <[email protected]> --------- Co-authored-by: Copilot Autofix powered by AI <[email protected]> Co-authored-by: Sean McManus <[email protected]> * Fix #11263: Make Edit Configurations UI fully theme-aware in custom themes (#14692) * Fix #11263: use theme-aware colors in Edit Configurations UI * Enhance dropdown styling with theme-aware colors in settings UI --------- Co-authored-by: Sean McManus <[email protected]> * Add processFilter for remote attach process selection (#14684) * Add processFilter for remote attach process selection When attaching to a process on a remote target, the process always has to be selected by hand, even though the launch configuration already knows which executable it belongs to. A generated configuration cannot hard-code processId either, because the pid changes on every boot and on every restart of the service, so the picker is the only option. Add an optional processFilter regular expression to the cppdbg attach configuration. When set, it is matched against the label, description and detail of the remote process list: exactly one match attach to that process directly more than one show the picker with only the matching entries no match show the full picker, as before All three fields are considered because the item format depends on the transport: useExtendedRemote reports the user and the full command line in the label, while pipeTransport reports the process name in the label and the command line in the detail. An invalid regular expression is reported instead of being silently ignored. This affects remote attach only (pipeTransport and useExtendedRemote); local attach continues to use program-based matching. Closes #14682 * Extract remote process filtering into a helper Move the matching logic out of RemoteAttachPicker into a standalone function so that it can be unit tested without a VS Code quick pick or a live connection to a remote target. No functional change. * Add unit tests for processFilter matching Cover empty and non-string filter values, matching against label, description and detail, multiple matches, an invalid regular expression, and a regression case ensuring missing fields are not treated as empty strings. --------- Co-authored-by: Adrian Freihofer <[email protected]> Co-authored-by: Sean McManus <[email protected]> * Bump the github-actions group with 2 updates (#14738) Bumps the github-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.37.7 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ff2f1c6...cdf488f) Updates `github/codeql-action/analyze` from 4.37.7 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ff2f1c6...cdf488f) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Fix localization translation errors (#14737) * Localization - Translated Strings * Fix localization translation errors * Address localization review feedback * Fix localization review feedback --------- Co-authored-by: csigs <[email protected]> * Update changelog for 1.34.3 (#14740) * Update changelog and version for 1.34.4. (#14748) * Enable PR CI for release and insiders (#14751) * Fix localization string import (#14743) * Fix localization string import * Correct conversion cycle translations * Add Run and Debug session state tests (#14736) --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: Bob Brown <[email protected]> Co-authored-by: Colen Garoutte-Carson <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Prashant Kumar Rai <[email protected]> Co-authored-by: Copilot Autofix powered by AI <[email protected]> Co-authored-by: afreof <[email protected]> Co-authored-by: Adrian Freihofer <[email protected]> Co-authored-by: csigs <[email protected]>
Summary
Remove the unused
gulp-sourcemapsinitialization from the localization pipelines and drop the dependency. This removes the vulnerable transitive[email protected]package while preserving localization behavior because the metadata generator does not consume source maps.Validation
yarn install --frozen-lockfile --ignore-scriptsyarn compileyarn translations-generateyarn gulp translations-export