Skip to content

Security Vulnerabilities with Mocha v9 and dependency on @serverless/test #139

@punit1108

Description

@punit1108
Image Image

Mocha@v9 is getting old. It has got a few ongoing vulnerabilities now.

Tried upgrading to Mocha@v11, but @serverless/test is dependent on Mocha@v9 -

Image

Then, i tried upgrading to Mocha@v10, turns out the it doesn't crash at peerDependencies, but the isolated tests are dependent on the code -

Image

Not that it's a major fix but seems like serverless has made the repository private now and it's no longer available for OSS contributions. Also it was last published 3 years ago, hence i don't think they have any plans to maintain it anymore.

I am opening this issue to discuss how to handle this situation. @mnapoli

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions