Repository navigation
Conversation
|
this parameter "--production" is still used by Node v14 . |
|
Node 14 (and 16) are already end-of-life though. They shouldn't be used any more, as they won't even get patched. IMO you should drop support for them, as in the worst case this enables stakeholders using those outdated versions. Even if Node 14 support has to be kept for some reason there should be a conditional to use the |
If you expect that repo to follow the most basic best current security practices or even SAP security policies, you will face disillusionment :) I've tried to push a bunch of security compliance PRs a year ago, most of them have been merged/taken over. Dunno why such a critical piece in the SAP software supply chain can be left with known critical CVEs such as https://security-tracker.debian.org/tracker/CVE-2024-2961 several months ... or years. |
|
MBT requires support for Node 14, and the Node 14 MBT Docker image is utilized by SAP Piper. Therefore, it cannot be replaced at this time. |
|
So critical components in the SAP software supply chain use unmaintained and cluttered by serious security flaws node.js version? |
|
still there in 2025/2026, I hope this warning could be fixed so we can have a clean console log |
|
@kbarnold, could you please also approve this small one? |
I fully support to merge this soon to avoid more severe problems when this option is removed and no longer available in npm after it's been deprecated for a really long time. And, of course, I'd like to get rid of this annoying warning in the console as well. @kbarnold |
|
This looks good and I will review and approve it, but am currently busy with rebuilding the CI and release setup. |
Description
This PR replaces all occurrences of
--productionin annpmcontext with--omit=dev.Currently you get these warnings when deploying MTA projects with the standard
npmbuilder:"npm warn config production Use
--omit=devinstead"The
omitoption was introduced withnpm8, so it's available in all supported versions.Checklist