Skip to content

Code Review - #10

Open
Tripl321 wants to merge 22 commits into
Technigo:mainfrom
Tripl321:main
Open

Code Review#10
Tripl321 wants to merge 22 commits into
Technigo:mainfrom
Tripl321:main

Conversation

@Tripl321

Copy link
Copy Markdown

No description provided.

Tripl321 and others added 14 commits May 25, 2026 14:16
Removed emoji placeholders from the document.
Updated the security requirements table by removing redundant column title and improving clarity.
…omponents/SingleMessage.jsx för att uppfylla krav K1, K4 och K6. Se kommentarerna i koden för detaljer om varje ändring.
Added a security policy document outlining supported versions and vulnerability reporting.
Bumps [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) from 8.5.1 to 9.0.0.
- [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](auth0/node-jsonwebtoken@v8.5.1...v9.0.0)

---
updated-dependencies:
- dependency-name: jsonwebtoken
  dependency-version: 9.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Removes [esbuild](https://github.com/evanw/esbuild). It's no longer used after updating ancestor dependency [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). These dependencies need to be updated together.


Removes `esbuild`

Updates `vite` from 4.5.14 to 8.0.16
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version:
  dependency-type: indirect
- dependency-name: vite
  dependency-version: 8.0.16
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.1 to 6.15.2.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.1...v6.15.2)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.15.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@netlify

netlify Bot commented Jun 10, 2026

Copy link
Copy Markdown

Deploy Preview for yh-message-app-fullstack ready!

Name Link
🔨 Latest commit 3895833
🔍 Latest deploy log https://app.netlify.com/projects/yh-message-app-fullstack/deploys/6a291ab4f9546d000894c0c4
😎 Deploy Preview https://deploy-preview-10--yh-message-app-fullstack.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@netlify

netlify Bot commented Jun 10, 2026

Copy link
Copy Markdown

Deploy Preview for yh-message-app-fullstack failed. Why did it fail? →

Name Link
🔨 Latest commit 692f857
🔍 Latest deploy log https://app.netlify.com/projects/yh-message-app-fullstack/deploys/6a3266b80b07f90008c3b6ec

@karinisaksson karinisaksson left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Snyggt jobbat! Bara en grej jag tänkte på. Gällande K3: granskningslogg så fattar jag det som att loggarna inte sparas permanent om man kör console.log. Om loggarna ska sparas över tid och granskas i efterhand bör man skriva loggarna till fil eller databas. Men för detta projekt kanske console.log räcker.

Tripl321 added 5 commits June 12, 2026 09:43
…s-6.15.2

Bump qs from 6.15.1 to 6.15.2 in /backend
…multi-f57e1e291f

Bump esbuild and vite in /frontend
…sonwebtoken-9.0.0

Bump jsonwebtoken from 8.5.1 to 9.0.0 in /backend
Updated tar module version to a more secure version.
@HIPPIEKICK

Copy link
Copy Markdown
Contributor

Ser ut som att ni missat att lägga upp något för granskningsfasen? Pinga mej när ni gjort det är ni snälla! 😊

Added detailed analysis of security alerts from Dependabot, focusing on jsonwebtoken vulnerabilities and proposed solutions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants