Repository navigation
swap vendored leaflet with npm leaflet #5695
Copy link
Copy link
Closed
GSA/datagov-catalog
#364Labels
O&MOperations and maintenance tasks for the Data.gov platformOperations and maintenance tasks for the Data.gov platformSecurity - complianceRelating to security compliance or documentationRelating to security compliance or documentation
Milestone
Description
Activity
We also added some leaflet image files in GSA/datagov-catalog#174. When we use npm to package leaflet, the images will likely get installed elsewhere and we can remove the ones we added manually.
After leaflet npm'ed, we need to come back and briefly check that the marker image is not broken. it seems to be a known leaflet issue.
this is working now and have another 6 months before we need to address this
- added a parent issue
on May 14, 2026 - addedSecurity - complianceRelating to security compliance or documentationRelating to security compliance or documentationO&MOperations and maintenance tasks for the Data.gov platformOperations and maintenance tasks for the Data.gov platform
on Jun 24, 2026 - removed a parent issue
on Jul 7, 2026 - moved this from O&M Specific Backlog to 📟 Sprint Backlog (Top Priority) in data.gov team board
on Jul 15, 2026 - moved this from 📟 Sprint Backlog (Top Priority) to 🏗 In Progress in data.gov team board
on Jul 28, 2026 - linked a pull request that will close this issue5695 Swap vendored Leaflet for npm package #364
on Jul 29, 2026 - moved this from 👀 Needs Review to ✔ Done in data.gov team board
on Jul 29, 2026
Metadata
Metadata
Assignees
Labels
O&MOperations and maintenance tasks for the Data.gov platformOperations and maintenance tasks for the Data.gov platformSecurity - complianceRelating to security compliance or documentationRelating to security compliance or documentation
Type
Projects
- StatusShow more project fields🗄 Closed
User Story
In order to not be on the hook for security updates and allow auto-updates to occur, datagov wants to swap our vendored leaflet instance with the npm version
Acceptance Criteria
[ACs should be clearly demoable/verifiable whenever possible. Try specifying them using BDD.]
AND we want dependabot to do its job
WHEN the vendored version of leaflet is removed
THEN its derived from npm instead
AND CSP policies are updated so no change in functionality occurs
Background
try to avoid allowing entire package registries in our CSP. we vendored leaflet to avoid having to do that. however, we haven't been notified that we've violated some security policy so maybe using registries is okay?
Security Considerations (required)
[Any security concerns that might be implicated in the change. "None" is OK, just be explicit here!]
Sketch
[Notes or a checklist reflecting our understanding of the selected approach]