-
Notifications
You must be signed in to change notification settings - Fork 146
fix(deps): update dependency bcryptjs to v3 - - package.json #920
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Dependency ReviewThe following issues were found:
License Issuespackage.json
Allowed Licenses: MIT, MIT-0, Apache-2.0, BSD-3-Clause, BSD-3-Clause-Clear, ISC, BSD-2-Clause, Unlicense, CC0-1.0, 0BSD, X11, MPL-2.0, MPL-1.0, MPL-1.1, MPL-2.0, Zlib Excluded from license check: pkg:npm/caniuse-lite OpenSSF Scorecard
Scanned Files
|
✅ Deploy Preview for endearing-brigadeiros-63f9d0 canceled.
|
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #920 +/- ##
=======================================
Coverage 63.20% 63.20%
=======================================
Files 47 47
Lines 1685 1685
=======================================
Hits 1065 1065
Misses 620 620 ☔ View full report in Codecov by Sentry. |
245ccd5 to
45cbde1
Compare
45cbde1 to
3e15f09
Compare
|
@06kellyjac - can we get a review on this? Any adjustments to API that are potentially problematic with existing usage in the library? |
|
The breaking changes were:
renovate bot says it's pretty new so we could also just hold off a few days to see if anything else explodes upstream. |
This PR contains the following updates:
^2.4.3->^3.0.2Release Notes
dcodeIO/bcrypt.js (bcryptjs)
v3.0.2Compare Source
Bug fixes
28e5103)v3.0.1Compare Source
Bug fixes
e7055ca)v3.0.0Compare Source
Breaking changes
2f45985)The project now exports an ECMAScript module by default, albeit with an UMD fallback, ships with types, the dist/ directory no longer exists in version control, and Closure Compiler externs have been removed.
d36bfb4)This library was not affected by the bug that led to incrementing the bcrypt version from 2a to 2b, but nowadays most implementations use 2b, including the native bcrypt binding, so this change aligns with them. Existing hashes will continue to work, but test logic that generates hashes and compares them literally might need to be updated to account for the new default.
Features
d5656b3)Other
2a9bea9)e09eb9a)58333a1)2e3b176)ec02e8a)9db275f)ac70ac5)574d690)e746547)548559d)4977df0)a84d4e4)c8c9c01)1b54cc4)Backlog from v2
7e2e93a)The npm package does not need externs as it is needed only for closure compiler. Added it in .npmignore since bcryptjs overrides global module and process in WebStorm IDE.
684fac6)b09f7f2)648482a)49a1d1a)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.