-
Notifications
You must be signed in to change notification settings - Fork 100
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependencies for audit #2153
Conversation
Signed-off-by: Peter Haumer <[email protected]>
Codecov ReportBase: 90.71% // Head: 90.71% // No change to project coverage 👍
Additional details and impacted files@@ Coverage Diff @@
## main #2153 +/- ##
=======================================
Coverage 90.71% 90.71%
=======================================
Files 86 86
Lines 8107 8107
Branches 1710 1710
=======================================
Hits 7354 7354
Misses 752 752
Partials 1 1 Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here. ☔ View full report at Codecov. |
Signed-off-by: Peter Haumer <[email protected]>
Kudos, SonarCloud Quality Gate passed!
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for updating (and deduping) dependencies 👍
Left a few comments, will approve after testing the branch locally 🙂
@@ -1,5 +1,5 @@ | |||
{ | |||
"version": "2.6.1-SNAPSHOT", | |||
"version": "2.6.2-SNAPSHOT", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do we want the version to be "2.7.0-SNAPSHOT" to prepare for the next release on the main branch?
I'm also ok with leaving it as is - it really doesn't matter what the version is since our updated deployment workflow will automatically handle bumping the version when we publish 2.7.0.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
My apologies. I picked the wrong branch it seems.
"mocha/**/minimatch": "^3.1.2", | ||
"mocha/**/flat": "^5.0.1", | ||
"**/json5": "^2.2.2" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Curious about these since I think we were trying to remove as many resolutions as possible 🙂
Do we want to hold off on updating Mocha to a newer version because it would introduce major changes that break our tests?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, I was just a bit lazy as I have forgotten how to run the integration tests. :-)
json5 seems to be all over the place and could not find a more scoped solution.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The local integration tests are currently broken until we fix #2103. The Theia integration tests that run on every PR build are using Mocha, so I think we could try updating Mocha and if those tests still pass then it should be good to update 🙂
Regarding json5 being all over the place, I believe it's a fairly new vulnerability so probably not all our dependencies have addressed it yet. I agree keeping the resolution makes sense in that case.
the changes work well for me. |
Proposed changes
Using the zowe-explorer-api brought with it several security audits as it was using older Zowe dependencies. Updating to the latest eliminated most resolutions. The hope is that this could be published as a v2.6.2.
One area I did not want to touch was mocha as I am not familiar with the integration tests anymore, but updating that to a newer version would simply this even further.
Release Notes
Milestone:
Changelog:
Types of changes
What types of changes does your code introduce to Zowe Explorer?
Put an
x
in the boxes that applyChecklist
Put an
x
in the boxes that apply. You can also fill these out after creating the PR. If you're unsure about any of them, don't hesitate to ask. We're here to help! This checklist will be used as reference for both the contributor and the revieweryarn workspace vscode-extension-for-zowe vscode:prepublish
has been executedFurther comments