Skip to content

Conversation

@yanxue-22
Copy link
Contributor

TICKET: DX-1557

@yanxue-22 yanxue-22 force-pushed the BG-1557-Nanoid-Predictable-Generation-Vulnerability branch from 0be12d5 to 76a6f16 Compare September 11, 2025 21:36
@yanxue-22
Copy link
Contributor Author

Bumping mocha to 10.6.0 gets rid of Nanoid dependency completely, along with the vulnerability.

Breaking changes from bumping mocha can be found here: https://github.com/mochajs/mocha/blob/main/CHANGELOG.md#1000--2022-05-01

The only relevant breaking change is the Node.js v12 drop, but since the package.json requires Node.js >=20 already, its not a problem.

@yanxue-22 yanxue-22 marked this pull request as ready for review September 11, 2025 21:47
@yanxue-22 yanxue-22 requested review from a team as code owners September 11, 2025 21:47
@yanxue-22 yanxue-22 merged commit cb1d499 into master Sep 12, 2025
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants