Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade mocha to 8.x.x release #1

Closed
wants to merge 9 commits into from
Closed

Upgrade mocha to 8.x.x release #1

wants to merge 9 commits into from

Conversation

jayaddison
Copy link

@jayaddison jayaddison commented Apr 23, 2020

This change upgrades the mocha dependency for js-delta-crdts-msgpack-codec to include a security fix (see the release details).

The mocha project will not be backporting this fix to mocha@5.x.x.

This change also commits the NPM package-lock.json, since it is intended to be committed to source repositories. From viewing other projects, practices seem to differ here, so I've reverted this change.

NB: The ^7.1.2 version specification does not pin to 7.1.2 specifically; the caret (^) symbol only matches against the left-most digit when checking for upgrades. I figure it's useful to specify the full three-digit version that was most-recent at the time of writing.

cc @pgte

@jayaddison jayaddison changed the title Upgrade mocha to 6.x.x release Upgrade mocha to 7.x.x release Apr 26, 2020
@jayaddison
Copy link
Author

@pgte Might we be able to merge this upgrade? It's not a hugely exciting update but it does remove a bit of npm audit noise, and reduces the dependency set a little.

@pgte
Copy link
Contributor

pgte commented May 4, 2020

@jayaddison I no longer can maintain these packages. Perhaps @jimpick can or knows who can?

@jayaddison jayaddison changed the title Upgrade mocha to 7.x.x release Upgrade mocha to 8.x.x release Jun 27, 2020
@jayaddison
Copy link
Author

Let me know if there's anything else that could help for merge-readiness here @jimpick; I've updated the pull request to upgrade to mocha 8.x.x since that major version's now available; the largest change per their release notes is that NodeJS 10+ is required.

@jayaddison
Copy link
Author

cc @jimpick - this is a small version bump (and dependency re-arrangement) for js-delta-crdts-msgpack-codec to reduce a bit of NPM audit noise and minimize imported (non-dev)dependencies.

@jayaddison
Copy link
Author

Closing as stale.

@jayaddison jayaddison closed this Dec 10, 2020
@jayaddison jayaddison deleted the upgrade-mocha branch December 10, 2020 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants