Skip to content

chore: Bump mocha to 12.0.2 - #414

Merged
Steve-Mcl merged 2 commits into
mainfrom
chore/bump-mocha-12
Oct 1, 2026
Merged

Steve-Mcl merged 2 commits into
mainfrom
chore/bump-mocha-12

Conversation

@Steve-Mcl

Copy link
Copy Markdown
Contributor

Description

Fixes CVE-2026-24001 (Trivy code scanning alert #2). mocha 11 pins diff to ^7.0.0 and no 7.x release has the fix. mocha 12 depends on diff 9.

Related Issue(s)

Checklist

  • I have read the contribution guidelines
  • Suitable unit/system level tests have been added and they pass
  • Documentation has been updated
    • Upgrade instructions
    • Configuration details
    • Concepts
  • Changes flowforge.yml?
    • Issue/PR raised on FlowFuse/helm to update ConfigMap Template
    • Issue/PR raised on FlowFuse/CloudProject to update values for Staging/Production
  • Link to Changelog Entry PR, or note why one is not needed.

Labels

  • Includes a DB migration? -> add the area:migration label

Fixes CVE-2026-24001 (Trivy code scanning alert #2). mocha 11 pins diff to ^7.0.0 and no 7.x release has the fix. mocha 12 depends on diff 9.
@Steve-Mcl
Steve-Mcl requested a review from hardillb September 30, 2026 16:20
@hardillb

Copy link
Copy Markdown
Contributor

@Steve-Mcl Mocha v12 needs at least NodeJS 20 (we dropped testing on 16 & 18 in the other repos

@Steve-Mcl

Steve-Mcl commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

@hardillb dropped 16 and 18 from matrix, added 22 - break eggs make omelettes right?

You ok with that?

@Steve-Mcl
Steve-Mcl merged commit 4ed8aa0 into main Oct 1, 2026
8 checks passed
@Steve-Mcl
Steve-Mcl deleted the chore/bump-mocha-12 branch October 1, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants