Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2.1.5: bump @xmldom/xmldom to 0.7.9 #263

Merged
merged 1 commit into from
Nov 17, 2022
Merged

Conversation

szphie
Copy link

@szphie szphie commented Oct 24, 2022

Hey - I'm not sure how you'd want to handle this, but the vuln fix that caused the @xmldom/xmldom breaking change was backported into 0.7.6 - https://github.com/xmldom/xmldom/releases/tag/0.7.6

Would you mind cutting a 2.x release for those of us not in a position to handle breaking changes?

@cjbarth
Copy link
Contributor

cjbarth commented Oct 24, 2022

I'm not inclined to cut release, but if you get a PR ready to go, I'll see if I can find some time to do it. This PR has merge conflicts and does not have any update to the change log. Please make those adjustments.

@szphie
Copy link
Author

szphie commented Oct 24, 2022

conflicts resolved but the PR should target a 2.x branch if you'd be so kind as to create one

where's the changelog?

@BadgerOps
Copy link

Howdy, I'm interested in this as well - looks like the changelog in releases is built off the PR title at this point - happy to help contribute to a changelog if we can get a 2.x branch from @cjbarth or another maintainer. We're unfortunately not in a position to deal with a breaking change in this package either.

@cjbarth
Copy link
Contributor

cjbarth commented Nov 13, 2022

Here is a 2.x branch: https://github.com/yaronn/xml-crypto/tree/2.x

@szphie szphie changed the base branch from master to 2.x November 14, 2022 08:03
@szphie
Copy link
Author

szphie commented Nov 14, 2022

Base changed

@cjbarth
Copy link
Contributor

cjbarth commented Nov 14, 2022

I don't think ci.yaml is in scope for this PR.

@szphie szphie changed the title 2.1.5: bump @xmldom/xmldom to 0.7.6 2.1.5: bump @xmldom/xmldom to 0.7.9 Nov 14, 2022
@LoneRifle
Copy link
Collaborator

@cjbarth any objections moving 2.x to 9307bb0? It's the last commit before the xmldom 0.8.x upgrade

@cjbarth
Copy link
Contributor

cjbarth commented Nov 15, 2022

It looks to me that the commit you suggest is after all the changes that resulted in the need for a semver-major bump, so it doesn't seem right to move the 2.x branch there.

@LoneRifle
Copy link
Collaborator

Most of those changes are safe; the only one that needed the semver major was the xmldom upgrade itself. On hindsight, I should have made one final 2.x release before upgrading xmldom, which I'll take as a learning point.

Either way, let's leave 2.x where you left it, we can always pick up all the missed dep upgrades later.

Copy link
Collaborator

@LoneRifle LoneRifle left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm. Will merge and publish when I have the means to do so

@LoneRifle LoneRifle merged commit ada8f2d into node-saml:2.x Nov 17, 2022
@cjbarth cjbarth added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants