Skip to content

Conversation

Abdel-Monaam-Aouini
Copy link
Contributor

@Abdel-Monaam-Aouini Abdel-Monaam-Aouini commented Dec 6, 2024

image

@IamLizu
Copy link
Member

IamLizu commented Dec 8, 2024

That's some major change with connect-redis. I guess it is used only in the examples,

@bjohansebas
Copy link
Member

There are already individual PRs that do this, I'm writing this from my phone, so I can't search for them easily.

@wesleytodd
Copy link
Member

I thought we had decided to move these examples out of the main repo?I cant find the issue right now, but I think @UlisesGascon opened it? If so, I dont think we should go about updating them here.

@bjohansebas
Copy link
Member

@wesleytodd this is the issue #5309

@wesleytodd
Copy link
Member

Ah thanks for finding that. Yeah I think we need to re-visit that soon here. Either way, I am not sure doing this large update of versions for the dev deps is a good idea either, it opens the door for a bunch of other problems (mainly that we need to vet them all and dont have time for that) and I would rather see us removing things then spending time updating them when the impact is small or non-existent (like in this case)

@UlisesGascon
Copy link
Member

I thought we had decided to move these examples out of the main repo?I cant find the issue right now, but I think @UlisesGascon opened it? If so, I dont think we should go about updating them here.

I didn't have the time to work on that initiative for a long time, also the approach was more valid before we released express v5. So I am +1 to update them as they are now while thinking as a team if we want to keep alive the other initiative or not for 2025.

@wesleytodd
Copy link
Member

For reference: https://socket.dev/npm/package/connect-redis/alerts/8.0.1

Screenshot 2025-01-08 at 2 41 26 PM

This is funny, @UlisesGascon you are the new maintainer on the dep in question. And the other high issue is safe-buffer which we are working to remove anyway. I think we are good on this.

I guess if others are good with this then I am as well.

@wesleytodd
Copy link
Member

And marked looks good as well AFAICT: https://socket.dev/npm/package/marked

@wesleytodd wesleytodd merged commit 6a40af8 into expressjs:master Jan 8, 2025
21 checks passed
@bjohansebas bjohansebas mentioned this pull request Mar 15, 2025
@UlisesGascon UlisesGascon mentioned this pull request Mar 23, 2025
68 tasks
@wesleytodd wesleytodd mentioned this pull request Mar 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

5 participants