Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

npmignore: Don't include the source of tests #5799

Merged
merged 1 commit into from Oct 8, 2021
Merged

Conversation

glasser
Copy link
Member

@glasser glasser commented Oct 8, 2021

We know of no reason that including the source of tests in built npm
packages would be helpful, and we've heard reports that including the
RSA private key fixture as we do in apollo-server-core can trigger
security scans.

Change how we drop tests from "dist" to drop the whole test directory in
case some other files sneak in there.

Fixes #5781.

@glasser glasser added the 2021-10 label Oct 8, 2021
@glasser glasser force-pushed the glasser/no-bundle-tests branch 2 times, most recently from 71ce883 to 669c710 Compare October 8, 2021 23:41
We know of no reason that including the source of tests in built npm
packages would be helpful, and we've heard reports that including the
RSA private key fixture as we do in apollo-server-core can trigger
security scans.

Change how we drop tests from "dist" to drop the whole test directory in
case some other files sneak in there.

Add a comment to the one npmignore file that differs from the others.

Fixes #5781.
@glasser glasser enabled auto-merge (squash) October 8, 2021 23:42
@glasser glasser merged commit 61695f1 into main Oct 8, 2021
@glasser glasser deleted the glasser/no-bundle-tests branch October 8, 2021 23:46
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Apr 20, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

fixture.key file causing Aquasec scan failures
1 participant