Skip to content

bump Mocha to version 12.0.3 - #295

Open
rafapaezbas wants to merge 1 commit into
expressjs:masterfrom
rafapaezbas:bump-mocha
Open

rafapaezbas wants to merge 1 commit into
expressjs:masterfrom
rafapaezbas:bump-mocha

Conversation

@rafapaezbas

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​mocha@​9.2.2 ⏵ 12.0.397 +110095 +195 -1100

View full report

@krzysdz

krzysdz commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

You can fix the CI on older Node versions by specifying older versions of mocha as appropriate in .github/workflows/ci.yml like this:

- name: Node.js 11.x
node-version: "11"
npm-i: mocha@8.4.0 supertest@6.1.6

I think the versions from expressjs/serve-index#171 should be fine (9.2.2 for Node.js 12-13, 10.8.2 for <20 and 21; 20 and 22+ work with the latest version).

@krzysdz krzysdz added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants