Conversation
- @mojaloop/central-services-error-handling 13.2.0 (opt-in ajv/joi parity flag, default off - validation error codes unchanged; mojaloop/project#4479) - node 24.18.0, CI orb and grype/audit-ci config updates - lockfile holds documented in .ncurc.yaml, all reproduced on this suite: event-sdk 14.8.4 (serialize-error ESM), commander 14.0.3 (ESM entry under jest), ml-testing-toolkit-shared-lib 14.3.3 (json-schema-ref-parser 15 ESM) - unit tests 59/59 across 17 suites; coverage gate green; npm audit clean
gibaros
requested review from
bushjames,
elnyry-sam-k,
geka-evk,
kleyow,
oderayi,
shashi165 and
vijayg10
as code owners
August 28, 2026 04:59
ml-repo-maintenance run on this branch: dependency updates, npm overrides for vulnerable transitive packages, CircleCI build orb 2.1.7, audit-ci.jsonc allowlist entries and .grype.yaml ignores for findings with no fix available. The Docker base image is pinned to the Node version this repo declares in .nvmrc. Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
….39.1 The Setup job on PR #146 failed with npm ci ERESOLVE: the previous maintenance commit pinned @babel/core to 7.29.6 while @babel/preset-env moved to ^8.0.5, which requires peer @babel/core@^8.0.0. @hapi/inert is restored to 7.1.2 and central-services-shared moves to 18.39.1 so the Dependencies job (ncu -e 2) passes. Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
The License scan job on PR #146 fails the licence gate with: UNDETERMINED: npm package oer-utils@5.1.2 declares licence "" oer-utils 5.1.2 ships an Apache-2.0 LICENSE file but omits the license field from its package.json; the 1.3.4 copies already resolve as Apache-2.0. Declaring it in the lockfile matches how als-oracle-pathfinder handled the same gate. Verified locally: license-scanner-tool PASS (620 npm components, 0 violations). Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
SonarCloud fails the quality gate on PR #146 with new_security_rating 3, from a single MAJOR issue: the Dockerfile omits --ignore-scripts on npm ci (docker:S6505). Unlike ml-api-adapter, this service has no native dependencies (no node-rdkafka), so nothing needs an explicit npm rebuild afterwards and the existing 'npm prune --production' in the runtime stage is unaffected. Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
The Dependencies job (npx ncu -e 2) fails on anything short of the newest release; 18.39.2 and 18.39.3 were published after this branch moved to 18.39.1. Claude-Session: https://claude.ai/code/session_015JRgXgTq9Zp7RGKM8BCRoe
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What
Dependency maintenance and adoption of
@mojaloop/central-services-error-handling13.2.0 [mojaloop/project#4479]: the ajv/joi parity mapping added in 13.2.0 is opt-in (ERROR_HANDLING_AJV_JOI_PARITY, default off), so this service's validation error codes are unchanged by the upgrade (mojaloop/central-services-error-handling#216).Note: three lockfile holds are documented in
.ncurc.yaml, each reproduced against this suite: event-sdk 14.8.4 (serialize-error ESM), commander 14.0.3 (ESM entry under jest), ml-testing-toolkit-shared-lib 14.3.3 (json-schema-ref-parser 15 is ESM-only).