MagicMirror Forum
    • Recent
    • Tags
    • Unsolved
    • Solved
    • MagicMirror² Repository
    • Documentation
    • 3rd-Party-Modules
    • Donate
    • Discord
    • Register
    • Login
    A New Chapter for MagicMirror: The Community Takes the Lead
    Read the statement by Michael Teeuw here.

    Maintaining modules - security updates

    Scheduled Pinned Locked Moved Development
    5 Posts 3 Posters 723 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Q Offline
      qistoph
      last edited by

      Hi everyone,

      As a developer/maintainer of a couple of MM modules I’m really wondering how everyone is keeping their modules’ dependencies up to date.

      An easy thing to do would be to run npm audit fix on my repos and/or merge all PRs from dependabot, but I’m too worried about breaking changes in dependencies. I wouldn’t know how to find the time to extensively test and fix all functionality in the modules. Especially if it would break functionality that someone else is using, that I’m not myself.

      How do other developer handle this?

      Chris

      S BKeyportB 2 Replies Last reply Reply Quote 0
      • S Offline
        sdetweil @qistoph
        last edited by

        @qistoph sadly there is no magic. all of them lead to testing

        audit fix causes more problems than it resolves. cause of unseen breaking changes.

        one of my (not published) modules gets it’s data from a mongob db somewhere remote. the server version changed, and dropped support for my (admittedly old) client version. one function I used was an external add on, now part of the product… BUT done differently… so you get to rewrite sometimes… it’s crushing…

        from a security standpoint, we are not a general purpose web site w lots of different users trying to use it at the same time

        Sam

        How to add modules

        learning how to use browser developers window for css changes

        1 Reply Last reply Reply Quote 0
        • BKeyportB Online
          BKeyport Module Developer @qistoph
          last edited by

          @qistoph I’m moving the stuff I do to no dependencies. :)

          The "E" in "Javascript" stands for "Easy"

          1 Reply Last reply Reply Quote 0
          • Q Offline
            qistoph
            last edited by

            Would’ve been nice if there were (at least a couple) basic libs with long time support. Security fixes, maybe some added functionality now and then, but no breaking changes…

            The actual risk of almost all vulnerabilities is quite low indeed because of the way our systems are setup. It’s just the earie feeling of seeing all these critical issues while installing my modules that doesn’t feel right.

            S 1 Reply Last reply Reply Quote 0
            • S Offline
              sdetweil @qistoph
              last edited by

              @qistoph we don’t have any binaries, all our code is in JavaScript. we are exposed to the general internet trends, speed of delivery over stability

              breaking changes are everywhere.

              I will say that a couple volunteers have been are working hard on processes for mm to detect those breaking changes by implementing a test system . but nothing is perfect

              Sam

              How to add modules

              learning how to use browser developers window for css changes

              1 Reply Last reply Reply Quote 0
              • 1 / 1
              • First post
                Last post
              Enjoying MagicMirror? Please consider a donation!
              MagicMirror created by Michael Teeuw.
              Forum managed by Sam, technical setup by Karsten.
              This forum is using NodeBB as its core | Contributors
              Contact | Privacy Policy