Skip to content

refactor: fix vulnerabilities - #37

Merged
LucVidal360 merged 10 commits into
mainfrom
main-34-vulnerabilities
Jul 21, 2026
Merged

LucVidal360 merged 10 commits into
mainfrom
main-34-vulnerabilities

Conversation

@LucVidal360

@LucVidal360 LucVidal360 commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

Context

  • npm complains there are vulnerabilities in our libs
    • this PR aims to fix them.
  • Also, I've observed the tests didn't stop cleanly, hanging for 30 seconds
    • let's fix this too!

Disclaimer

Don't worry, the high number of line changes is mostly about package-lock.json 😉

Changes

  • commits 1 to 7:
    • various lib updates
  • commits 8 and 9:
    • fix the hanging tests
    • it was a pending setTimeout which was not cleared because of a thrown error
  • commit 10: update MongoBulkDataMigration version 1.8.0

`npm update --save lodash`
`npm update --save rimraf`
`npm update --save @eslint/eslintrc @eslint/js \
    @typescript-eslint/eslint-plugin @typescript-eslint/parser eslint \
    eslint-config-prettier eslint-plugin-jest`
@LucVidal360 LucVidal360 self-assigned this Jul 20, 2026
@LucVidal360
LucVidal360 requested a review from pp0rtal as a code owner July 20, 2026 07:55

@orca-security-eu orca-security-eu Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 0   low 0   info 0 View in Orca

`npm update --save mongodb-memory-server`

Note that with this new mongodb version, the `FindOptions` type is not
generic anymore.
`npm update --save  jest ts-jest @types/jest`

There seem to be a bug in jest 30, which prevents asserting
`.rejects.toThrow(new Error("..."))`
It complains that the thrown error is not the same object as the
expected one 🙄
@LucVidal360
LucVidal360 force-pushed the main-34-vulnerabilities branch from ad29580 to 92fcb68 Compare July 20, 2026 08:32
Most dependencies' newer version require at least node 20.
The test
"should directly reject for invalid aggregate pipelines (empty from)"
was successful, but force jest to wait 30 seconds before ending
cleanly.
This came from a `setTimeout` which was not cleaned because of
an unexepected thrown error.

Moving the clearTimeout in a finally fix this issue.

You may ignore whitespaces to review this commit.

Next commit will further refactor the code by moving the check
on `options.dontCount` inside `getTotalEntries`.
This is a minor change (not a patch) because of the new requirement
on node version.
@LucVidal360
LucVidal360 force-pushed the main-34-vulnerabilities branch from 92fcb68 to 2f45b99 Compare July 20, 2026 08:56

@Jordanlelay Jordanlelay left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@LucVidal360 Good work!

@Edwearth Edwearth left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@LucVidal360
LucVidal360 merged commit b8ca161 into main Jul 21, 2026
8 checks passed
@LucVidal360
LucVidal360 deleted the main-34-vulnerabilities branch July 23, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants