Skip to content

chore: update zod to 3.22.4#563

Merged
dguyen merged 4 commits intodocumenso:feat/refreshfrom
adithyaakrishna:chore/update-zod
Oct 19, 2023
Merged

chore: update zod to 3.22.4#563
dguyen merged 4 commits intodocumenso:feat/refreshfrom
adithyaakrishna:chore/update-zod

Conversation

@adithyaakrishna
Copy link
Copy Markdown
Contributor

Description:

  • This PR updates zod to 3.22.4 as the previous versions had ReDoS vulnerability

More Info: colinhacks/zod#2824 and colinhacks/zod#2609

@vercel
Copy link
Copy Markdown

vercel bot commented Oct 14, 2023

@adithyaakrishna is attempting to deploy a commit to the Documenso Team Team on Vercel.

A member of the Team first needs to authorize it.

Copy link
Copy Markdown
Member

@catalinpit catalinpit left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

Copy link
Copy Markdown
Collaborator

@dguyen dguyen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you also upgrade them across the other packages? I think since a recent commit there were a few other packages that have zod now.

@adithyaakrishna
Copy link
Copy Markdown
Contributor Author

@dguyen Yes sure, will send a commit for that too :)

@adithyaakrishna
Copy link
Copy Markdown
Contributor Author

@dguyen Done, I updated next-auth as well, also, I was wondering if I could just update all the packages instead of only Zod?

@dguyen
Copy link
Copy Markdown
Collaborator

dguyen commented Oct 19, 2023

What was the reason for upgrading next-auth? We prefer to try stay away from unnecessary updates since they generally break things and requires testing.

In this case I think upgrading Zod only is fine since there's a vulnerability.

@adithyaakrishna
Copy link
Copy Markdown
Contributor Author

@dguyen Makes sense, I have reverted the change to next-auth with the above commit :)

Signed-off-by: Adithya Krishna <aadithya794@gmail.com>
Signed-off-by: Adithya Krishna <aadithya794@gmail.com>
Signed-off-by: Adithya Krishna <aadithya794@gmail.com>
@dguyen
Copy link
Copy Markdown
Collaborator

dguyen commented Oct 19, 2023

Something in the package lock file is breaking the build.

When I delete it and re-run everything it works.

Could you undo everything, and do the Zod upgrade incrementally so the package lock file is correctly updated?

Signed-off-by: Adithya Krishna <aadithya794@gmail.com>
@adithyaakrishna
Copy link
Copy Markdown
Contributor Author

@dguyen Fixed it :)

@dguyen dguyen merged commit 616cf1c into documenso:feat/refresh Oct 19, 2023
@dguyen
Copy link
Copy Markdown
Collaborator

dguyen commented Oct 19, 2023

Cheers 👍

/tip 25

@algora-pbc
Copy link
Copy Markdown

algora-pbc bot commented Oct 19, 2023

🎉🎈 @adithyaakrishna has been awarded $25! 🎈🎊

@algora-pbc algora-pbc bot added the 💰 Rewarded Set by Algora after bounty is rewarded to user label Oct 19, 2023
Mythie pushed a commit that referenced this pull request Nov 6, 2023
* chore: updated zod 

Signed-off-by: Adithya Krishna <aadithya794@gmail.com>

---------

Signed-off-by: Adithya Krishna <aadithya794@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

💰 Rewarded Set by Algora after bounty is rewarded to user

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants