Skip to content

Conversation

@xeho91
Copy link

@xeho91 xeho91 commented Jul 29, 2025

Description

  • Removed node-fetch and @types/node-fetch dependencies
  • Those dependencies were used only for the types, AFAIK.
    I'm unsure what the minimum Node.js version supported for this package is. I noticed in the package root >=18.
    It could create a debate whether this update is a breaking change (requires major upgrade) or not.
    I personally don't think so, given that I solved only the typing issue.

Related issue(s)

Package @types/node-fetch has a critical vurnerable dependency form-data: GHSA-fjxv-7rqg-78g4

@changeset-bot
Copy link

changeset-bot bot commented Jul 29, 2025

🦋 Changeset detected

Latest commit: 7578dc3

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@asyncapi/parser Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Welcome to AsyncAPI. Thanks a lot for creating your first pull request. Please check out our contributors guide useful for opening a pull request.
Keep in mind there are also other channels you can use to interact with AsyncAPI community. For more details check out this issue.

@xeho91 xeho91 changed the title refactor: Remove node-fetch dependency refactor: remove node-fetch dependency Jul 29, 2025
@xeho91
Copy link
Author

xeho91 commented Jul 30, 2025

Note

There's a chance that browserify-shims dev dependency is no longer needed

@sonarqubecloud
Copy link

@github-actions
Copy link

This pull request has been automatically marked as stale because it has not had recent activity 😴

It will be closed in 120 days if no further activity occurs. To unstale this pull request, add a comment with detailed explanation.

There can be many reasons why some specific pull request has no activity. The most probable cause is lack of time, not lack of interest. AsyncAPI Initiative is a Linux Foundation project not owned by a single for-profit company. It is a community-driven initiative ruled under open governance model.

Let us figure out together how to push this pull request forward. Connect with us through one of many communication channels we established here.

Thank you for your patience ❤️

@github-actions github-actions bot added the stale label Nov 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant