Skip to content

chore: update dependencies and adopt central-services-error-handling 13.2.0 - #146

Open
gibaros wants to merge 6 commits into
mainfrom
chore/deps-security-20260827
Open

gibaros wants to merge 6 commits into
mainfrom
chore/deps-security-20260827

Conversation

@gibaros

@gibaros gibaros commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What

Dependency maintenance and adoption of @mojaloop/central-services-error-handling 13.2.0 [mojaloop/project#4479]: the ajv/joi parity mapping added in 13.2.0 is opt-in (ERROR_HANDLING_AJV_JOI_PARITY, default off), so this service's validation error codes are unchanged by the upgrade (mojaloop/central-services-error-handling#216).

Note: three lockfile holds are documented in .ncurc.yaml, each reproduced against this suite: event-sdk 14.8.4 (serialize-error ESM), commander 14.0.3 (ESM entry under jest), ml-testing-toolkit-shared-lib 14.3.3 (json-schema-ref-parser 15 is ESM-only).

- @mojaloop/central-services-error-handling 13.2.0 (opt-in ajv/joi parity flag,
  default off - validation error codes unchanged; mojaloop/project#4479)
- node 24.18.0, CI orb and grype/audit-ci config updates
- lockfile holds documented in .ncurc.yaml, all reproduced on this suite:
  event-sdk 14.8.4 (serialize-error ESM), commander 14.0.3 (ESM entry under jest),
  ml-testing-toolkit-shared-lib 14.3.3 (json-schema-ref-parser 15 ESM)
- unit tests 59/59 across 17 suites; coverage gate green; npm audit clean
ml-repo-maintenance run on this branch: dependency updates, npm overrides for
vulnerable transitive packages, CircleCI build orb 2.1.7, audit-ci.jsonc
allowlist entries and .grype.yaml ignores for findings with no fix available.
The Docker base image is pinned to the Node version this repo declares in
.nvmrc.

Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
….39.1

The Setup job on PR #146 failed with npm ci ERESOLVE: the previous maintenance
commit pinned @babel/core to 7.29.6 while @babel/preset-env moved to ^8.0.5,
which requires peer @babel/core@^8.0.0. @hapi/inert is restored to 7.1.2 and
central-services-shared moves to 18.39.1 so the Dependencies job (ncu -e 2)
passes.

Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
The License scan job on PR #146 fails the licence gate with:
  UNDETERMINED: npm package oer-utils@5.1.2 declares licence ""

oer-utils 5.1.2 ships an Apache-2.0 LICENSE file but omits the license field from
its package.json; the 1.3.4 copies already resolve as Apache-2.0. Declaring it in
the lockfile matches how als-oracle-pathfinder handled the same gate.

Verified locally: license-scanner-tool PASS (620 npm components, 0 violations).

Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
SonarCloud fails the quality gate on PR #146 with new_security_rating 3, from a
single MAJOR issue: the Dockerfile omits --ignore-scripts on npm ci (docker:S6505).

Unlike ml-api-adapter, this service has no native dependencies (no node-rdkafka),
so nothing needs an explicit npm rebuild afterwards and the existing
'npm prune --production' in the runtime stage is unaffected.

Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
Comment thread Dockerfile Fixed
The Dependencies job (npx ncu -e 2) fails on anything short of the newest release;
18.39.2 and 18.39.3 were published after this branch moved to 18.39.1.

Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants