Skip to content

Upgrade build toolchain and deploy to Pages on push - #43

Merged
STRML merged 3 commits into
masterfrom
deps-and-pages-deploy
Sep 27, 2026
Merged

STRML merged 3 commits into
masterfrom
deps-and-pages-deploy

Conversation

@STRML

@STRML STRML commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Clears every open Dependabot alert and replaces the hand-merged gh-pages branch with a deploy workflow.

Change Why
Babel 8, webpack 5.111, webpack-dev-server 6, npm lockfile npm audit goes from 91 open alerts to 0
markdown → marked (gfm off) markdown has a ReDoS with no fixed release
raw-loader → ?raw asset/source raw-loader is deprecated in webpack 5
.github/workflows/deploy.yml builds on PRs, deploys master to Pages

gh-pages never got dist/ai.js, so https://strml.net/ai.html is broken today. This fixes it.

Checked by serving the assembled _site locally: both pages render, no console errors, the typed stylesheet keeps its comments and formatting, and work.txt links render as before.

Supersedes the open Dependabot PRs.

Babel 8, webpack 5.111, webpack-cli 7, webpack-dev-server 6. Moves from yarn v1 to npm (package-lock.json). npm audit reports 0 vulnerabilities.

markdown (ReDoS, no fixed release) is replaced by marked with gfm off, so bare URLs stay plain text for replaceURLs. raw-loader is replaced by webpack's asset/source via a ?raw query. Webpack's built-in CSS/HTML handling is turned off, since it minified the stylesheet text the page types out. Dropped unused exports-loader, util, and the Babel proposal plugins now in preset-env.
The workflow builds on each push and PR, runs npm audit, and deploys master to Pages. The old gh-pages branch was merged by hand and never had dist/ai.js, so /ai.html was broken live.

README links the Age of AI edition and documents the deploy.
Swept deploy.yml for every job condition (1 site). A workflow_dispatch on another branch no longer reaches the deploy job.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant