Core: Fix Node 24 deprecation warning #32382
Merged
+78
−54
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #32376
What I did
Checklist for Contributors
Testing
The changes in this PR are covered in the following automated tests:
Manual testing
This section is mandatory for all contributions. If you believe no manual test is necessary, please state so explicitly. Thanks!
Documentation
MIGRATION.MD
Checklist for Maintainers
When this PR is ready for testing, make sure to add
ci:normal
,ci:merged
orci:daily
GH label to it to run a specific set of sandboxes. The particular set of sandboxes can be found incode/lib/cli-storybook/src/sandbox-templates.ts
Make sure this PR contains one of the labels below:
Available labels
bug
: Internal changes that fixes incorrect behavior.maintenance
: User-facing maintenance tasks.dependencies
: Upgrading (sometimes downgrading) dependencies.build
: Internal-facing build tooling & test updates. Will not show up in release changelog.cleanup
: Minor cleanup style change. Will not show up in release changelog.documentation
: Documentation only changes. Will not show up in release changelog.feature request
: Introducing a new feature.BREAKING CHANGE
: Changes that break compatibility in some way with current major version.other
: Changes that don't fit in the above categories.🦋 Canary release
This PR does not have a canary release associated. You can request a canary release of this pull request by mentioning the
@storybookjs/core
team here.core team members can create a canary release here or locally with
gh workflow run --repo storybookjs/storybook canary-release-pr.yml --field pr=<PR_NUMBER>
Greptile Summary
Updated On: 2025-09-11 11:45:39 UTC
This PR addresses Node 24 deprecation warnings (DEP0190) that occur when using
spawnSync
andspawn
withshell: true
and separate command arguments. The warning flags this pattern as a security vulnerability since arguments are not properly escaped when concatenated.The fix applies two different approaches across the codebase:
Single command string approach: In
upgrade.ts
andpostinstall.ts
, commands like['npm', 'ls']
are consolidated into single strings like'npm ls'
when usingshell: true
.Array arguments without shell approach: In
JsPackageManagerFactory.ts
, the code switches from using shell commands as strings to using command arrays without theshell: true
option.The changes primarily affect package manager detection and command execution across Storybook's build and setup processes. These are internal operations that run during Storybook initialization, CLI commands, and addon installation. The corresponding test files are updated to match the new command patterns, ensuring mock expectations align with the actual implementation.
Additionally, a
--trace-deprecation
flag is added to the storybook:ui npm script to help developers identify similar issues during development.Confidence score: 4/5
JsPackageManagerFactory.ts
to ensure package manager detection still works reliably across different environments