Adolfo Ochagavía
04/01/2026, 2:12 PMkotlin-js-store/yarn.lock. I was surprised when, even after updating to the latest version of kotlin, many alerts were still there. Is that expected? Looking at the generated yarn workspace (in build/js), I see that kotlin automatically adds a bunch of dev dependencies for testing, which in turn result in a lockfile with many outdated dependencies. Maybe the warnings should be ignored, because they usually apply to a web server use case, and not to local testing. Still, I wanted to double-check that the warnings are expected and not a product of some misconfiguration on my end (some of the dev dependencies in the lockfile have had CVEs for years).Adolfo Ochagavía
04/01/2026, 2:13 PMEdoardo Luppi
04/01/2026, 2:24 PMEdoardo Luppi
04/01/2026, 2:24 PMAdolfo Ochagavía
04/01/2026, 2:25 PMAdolfo Ochagavía
04/01/2026, 2:25 PMThese are all dev dependencies, used when running JS tests locally. Attacks based on bad handling of untrusted input (DoS, RCE, etc) are not a concern in this use case.
Edoardo Luppi
04/01/2026, 2:28 PMimplementation(devNpm("package-name", "pinned-version"))
See if everything works.Edoardo Luppi
04/01/2026, 2:29 PMEdoardo Luppi
04/01/2026, 2:30 PMAdolfo Ochagavía
04/01/2026, 2:33 PMAdolfo Ochagavía
04/01/2026, 2:35 PMAdolfo Ochagavía
04/01/2026, 2:35 PMAdolfo Ochagavía
04/01/2026, 2:36 PMturansky
04/01/2026, 2:42 PMturansky
04/01/2026, 2:44 PMEdoardo Luppi
04/01/2026, 2:53 PMkotlin.js.yarn=false)
• Run npm audit fix manually inside build/js
• Run kotlinUpgradePackageLock again and see what happens. It should copy the updated lockfile under kotlin-js-store.Edoardo Luppi
04/01/2026, 2:55 PMkotlinAuditFixPackageLock task built-in to KGP, to streamline this process.turansky
04/01/2026, 2:55 PMEdoardo Luppi
04/01/2026, 2:56 PMEdoardo Luppi
04/01/2026, 2:58 PMAdam Semenenko
04/01/2026, 3:16 PMthere is some work going on in the UX side of things for K/JS and K/WasmJust to manage expectations: there's no work yet, but we are very aware of the UX issues. Any feedback, suggestions, use-cases are helpful.
Adam Semenenko
04/01/2026, 3:17 PMEdoardo Luppi
04/01/2026, 5:23 PMAdam Semenenko
04/02/2026, 10:28 AMA way to extend package-related tasks to execute our own npm operationscould you say more about this? What operations do you mean, and what would are they needed for?
Edoardo Luppi
04/02/2026, 10:36 AMnpm audit fix also accepts a --force parameter, which SHOULD NOT be passed by KGP by default.turansky
04/21/2026, 5:31 PMlatest-tools plugin for latest stable versions.