Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

V10.4.0 #375

Merged
merged 18 commits into from
Jan 5, 2023
Merged

V10.4.0 #375

merged 18 commits into from
Jan 5, 2023

Conversation

nelsonic
Copy link
Member

@nelsonic nelsonic commented Jan 5, 2023

This PR creates a new [maintenance] release for the package. 📦
To publish a version with the updated jsonwebtoken dependency #374 ⬆️

Changelog:

# Version 10.3.0 - Security Update to `jsonwebtoken` Dependency

Update version of `jsonwebtoken` dependency to latest
to avoid security issues. 
See: https://github.com/dwyl/hapi-auth-jwt2/pull/374 thanks @AntoineAA 
More detail in: https://github.com/dwyl/hapi-auth-jwt2/pull/373 thanks Snyk. 

Sadly the deps badges are no longer working:
Dependencies Status
devDependencies Status

Removing from README.md ✂️

Also:

  • Replaces .travis.yml with .github (GitHub Actions/CI + @dependabot)
  • Update version of prettier + eslint to latest and updates code in index.js from function to => ... 🙄 V10.4.0 #375 (comment)
  • Updates README.md badges from master to main

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

@snyk finds 4 issues with this PR, all jsonwebtoken:
image

Thanks @snyk, suuuuuuuper helpful. Thanks for failing the build that releases the new version of the package to fix the problem you've identified. 🎉

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

Meanwhile what I really want is to know if the CI (GitHub Actions) is passing so I know if Hapi@v21 works ... 🤷‍♂️

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

OK. I'm done with @snyk between them creating a PR as me #373 🤦‍♂️
and now prematurely failing this build that is updating the issue they have identified ... done. 🙅

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

What kind of security system allows a manual override? 🤦‍♂️
https://app.snyk.io/org/nelsonic/pr-checks/2af9b479-c08f-4551-8e13-e0815297bc90
snyk-manual-overrid

This is an acknowledgement that their system is fundamentally broken. 💔

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

"Mark as successful" indeed ...
image

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

Attempted to run npm audit fix ... got:

npm ERR! code ERESOLVE
npm ERR! ERESOLVE could not resolve
npm ERR! 
npm ERR! While resolving: [email protected]
npm ERR! Found: [email protected]
npm ERR! node_modules/eslint
npm ERR!   dev eslint@"^7.0.0-alpha.0" from the root project
npm ERR! 
npm ERR! Could not resolve dependency:
npm ERR! peer eslint@">= 5.0.0" from [email protected]
npm ERR! node_modules/eslint-plugin-prettier
npm ERR!   dev eslint-plugin-prettier@"^3.1.2" from the root project
npm ERR! 
npm ERR! Conflicting peer dependency: [email protected]
npm ERR! node_modules/eslint
npm ERR!   peer eslint@">= 5.0.0" from [email protected]
npm ERR!   node_modules/eslint-plugin-prettier
npm ERR!     dev eslint-plugin-prettier@"^3.1.2" from the root project
npm ERR! 
npm ERR! Fix the upstream dependency conflict, or retry
npm ERR! this command with --force, or --legacy-peer-deps
npm ERR! to accept an incorrect (and potentially broken) dependency resolution.

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

Gonna try and manually update eslint and prettier ... 🧑‍💻⏳ 🙄

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

Somewhat predictably ...

npm run lint

> [email protected] lint
> eslint lib


/Users/n/code/hapi-auth-jwt2/lib/index.js
   20:21  error  Insert `·`                                                                                                                                         prettier/prettier
   46:37  error  Insert `·`                                                                                                                                         prettier/prettier
   56:32  error  Insert `·`                                                                                                                                         prettier/prettier
   64:35  error  Insert `·`                                                                                                                                         prettier/prettier
   73:31  error  Insert `·`                                                                                                                                         prettier/prettier
   85:40  error  Insert `·`                                                                                                                                         prettier/prettier
  184:12  error  Replace `⏎········isValid,⏎········credentials,⏎········response,⏎········errorMessage,` with `·isValid,·credentials,·response,·errorMessage·}·=`  prettier/prettier
  189:7   error  Replace `}·=` with `·`                                                                                                                             prettier/prettier
  324:36  error  Insert `·`                                                                                                                                         prettier/prettier
  340:33  error  Insert `·`                                                                                                                                         prettier/prettier
  371:28  error  Insert `·`                                                                                                                                         prettier/prettier
  402:23  error  Insert `·`                                                                                                                                         prettier/prettier
  410:20  error  Replace `err` with `(err)`                                                                                                                         prettier/prettier
  424:27  error  Insert `·`                                                                                                                                         prettier/prettier

✖ 14 problems (14 errors, 0 warnings)
  14 errors and 0 warnings potentially fixable with the `--fix` option.

This is silly.

20:21  error  Insert `·`    

the line in question is:

register: function(server, options) {

How does this line need a . on it? 🤷‍♂️

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

Through a little investigation, 🔍
it turns out that the latest version of prettier doesn't allow the function keyword. 🤷‍♂️
Everything has to be => (arrow functions) ... 🤦‍♂️

Sooooo glad I don't write JS anymore.
This is suuuuper lame! the function keyword is perfectly fine!
why do the Küel Kids have to ruin perfectly working code?! 🤦‍♂️

@codecov
Copy link

codecov bot commented Jan 5, 2023

Codecov Report

❗ No coverage uploaded for pull request base (main@0cf2b34). Click here to learn what that means.
The diff coverage is n/a.

@@           Coverage Diff            @@
##             main      #375   +/-   ##
========================================
  Coverage        ?   100.00%           
========================================
  Files           ?         2           
  Lines           ?       134           
  Branches        ?         0           
========================================
  Hits            ?       134           
  Misses          ?         0           
  Partials        ?         0           

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

Much better:

image

@nelsonic nelsonic requested a review from SimonLab January 5, 2023 07:41
@nelsonic
Copy link
Member Author

nelsonic commented Jan 5, 2023

@SimonLab please take a look and merge when you're back at your desk. Thanks. 🙏

Copy link
Member

@SimonLab SimonLab left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good thanks 👍

@SimonLab SimonLab merged commit 48e06f1 into main Jan 5, 2023
@SimonLab SimonLab deleted the v10.3.0 branch January 5, 2023 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

2 participants