[NoQA] [Snyk] Security upgrade reassure from 1.0.0-rc.4 to 1.0.0#84893
[NoQA] [Snyk] Security upgrade reassure from 1.0.0-rc.4 to 1.0.0#84893mjasikowski merged 3 commits intomainfrom
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-SIMPLEGIT-15457646
|
@mjasikowski Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
The Snyk PR updated reassure in package.json from ^1.0.0-rc.4 to ^1.0.0 but did not regenerate package-lock.json, causing npm ci to fail in all CI checks due to the lock file being out of sync.
|
Fixed the failing checks: The Snyk PR updated |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1d6bd8d3d2
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| "react-refresh": "^0.14.2", | ||
| "react-test-renderer": "19.1.0", | ||
| "reassure": "^1.0.0-rc.4", | ||
| "reassure": "^1.0.0", |
There was a problem hiding this comment.
Regenerate lockfile for reassure upgrade
This change updates package.json to reassure@^1.0.0 but leaves package-lock.json pinned to ^1.0.0-rc.4/1.0.0-rc.4 (see package-lock.json:276 and package-lock.json:35200-35208), so the upgrade is not actually reflected in reproducible installs. In this repo, setupNode runs npm ci (.github/actions/composite/setupNode/action.yml:56), and npm ci requires the lockfile to be in sync (it errors with: npm ci can only install packages when your package.json and package-lock.json ... are in sync), which can break CI jobs whenever dependency install is needed.
Useful? React with 👍 / 👎.
…b0cfaf03044f0a4501bb
|
Fixed the failing checks: The branch was behind |
|
🚧 @mjasikowski has triggered a test Expensify/App build. You can view the workflow run here. |
|
🧪🧪 Use the links below to test this adhoc build on Android, iOS, and Web. Happy testing! 🧪🧪
|
|
✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release. |
|
🚀 Deployed to staging by https://github.com/mjasikowski in version: 9.3.40-0 🚀
|
|
🚀 Deployed to staging by https://github.com/mjasikowski in version: 9.3.40-0 🚀
|
|
🚀 Deployed to production by https://github.com/cristipaval in version: 9.3.41-4 🚀
|
Explanation of Change
Fixed Issues
$
PROPOSAL:
Tests
Offline tests
QA Steps
// TODO: These must be filled out, or the issue title must include "[No QA]."
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectiontoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari