Skip to content

fix(node): clear all n8n community-node review findings (scanner + codex) - #33

Merged
nicolasiscoding merged 2 commits into
mainfrom
fix/n8n-scanner-violations
Aug 20, 2026
Merged

nicolasiscoding merged 2 commits into
mainfrom
fix/n8n-scanner-violations

Conversation

@nicolasiscoding

Copy link
Copy Markdown
Member

Makes the package pass the n8n community-node review clean. Fixes every finding the reviewers flagged — the @n8n/scan-community-package scanner findings and the codex nodeVersion lint finding.

Scanner findings (@n8n/scan-community-package)

  • require-node-api-error (TurboDocx.node.ts): re-threw a caught error variable. Now re-raised as a fresh NodeOperationError, message + description preserved verbatim. execute.unknownOperation.test.ts pins that behavior (still passes).
  • no-hardcoded-secrets (hmac.contract.test.ts): hardcoded whsec_test_…. Now generated per-run with crypto.randomBytes — any value works, the test only exercises the HMAC round-trip.
  • test files shipped in dist/ (which also tripped the secret rule on the dist side): exclude __tests__/*.test.ts from the build (tsconfig exclude; tsconfig.test.json re-includes for jest). dist/ now ships only real node/credential code.
  • icon-prefer-themed-variants (node, trigger, both credentials): single-file icons → { light, dark } with a distinct turbodocx.dark.svg. (The scanner errors if light and dark point at the same file, so a distinct file is required; the brand mark is theme-independent, so the dark file mirrors the light one.)

Codex finding

  • [LOW] Codex nodeVersion should be "1.0": both *.node.json tracked the release version (1.4.0). Pinned to "1.0" (fixed schema value). AGENTS.md updated to drop nodeVersion from the release bump list + rewrite the rationale so it doesn't recur.

Verification

  • node scripts/scan-community-package.mjs: ✅ source + dist legs pass, 0 errors / 0 warnings
  • npx @n8n/node-cli@latest lint: exit 0 (v0.44.4)
  • npm run lint: clean · npx jest: 25 suites / 129 tests pass

Relationship to #32

#32 wires this scanner into CI + a pre-commit hook (currently a failing gate). This PR makes the node pass that gate. Merge this with or before #32 so main never carries a red gate.

🤖 Generated with Claude Code

Nicolas Fry and others added 2 commits August 20, 2026 14:54
Makes the package pass `@n8n/scan-community-package` cleanly (0 errors, 0
warnings). Addresses every finding the n8n reviewers flagged:

- require-node-api-error: TurboDocx.node.ts re-threw a caught error variable.
  Re-raise it as a fresh NodeOperationError, preserving message + description
  verbatim (execute.unknownOperation.test.ts pins that behavior).
- no-hardcoded-secrets: the HMAC contract test hardcoded `whsec_test_...`.
  Generate the secret per-run with crypto.randomBytes — any value works, the
  test only exercises the HMAC round-trip.
- test files were compiled into dist/ and shipped in the tarball (which also
  tripped the secret rule on the dist side). Exclude __tests__/*.test.ts from
  the build (tsconfig exclude; tsconfig.test.json re-includes for jest).
- icon-prefer-themed-variants: node, trigger and both credentials used a
  single-file icon. Provide { light, dark } with a distinct turbodocx.dark.svg
  (the brand mark is theme-independent, so the dark file mirrors the light one).

Verified: scanner passes (source + dist legs), `npm run lint` clean, and all
25 suites / 129 jest tests pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The n8n community-node review flagged `[LOW] Codex nodeVersion should be "1.0"`
— it's a fixed schema value (mirrors the node's internal `version`, like every
node in n8n-nodes-base), not the package release. Both codex files tracked the
release version (1.4.0); pin them to "1.0".

Also update AGENTS.md: drop `nodeVersion` from the release version-bump list and
its sanity check, and rewrite the rationale so the next release doesn't
reintroduce the finding. Caught by `npx @n8n/node-cli@latest lint` (exit 0).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@nicolasiscoding

Copy link
Copy Markdown
Member Author

CR: TurboDocx/workflow-templates#8 (private)

@nicolasiscoding
nicolasiscoding marked this pull request as ready for review August 20, 2026 19:07
@nicolasiscoding

Copy link
Copy Markdown
Member Author

approved

@nicolasiscoding
nicolasiscoding merged commit 52a5670 into main Aug 20, 2026
1 check passed
nicolasiscoding added a commit that referenced this pull request Aug 20, 2026
Patch release carrying the n8n community-node review fixes (#33) on top of the
1.4.0 feature set (partner prefs, optional quote decline reason, TurboSign
conditional fields). Bumps package.json, package-lock.json (both root fields),
and clientContext NODE_PACKAGE_VERSION; codex nodeVersion stays "1.0".

Pre-release checks pass: npm ci, lint, build, jest (129 tests), and the
@n8n/scan-community-package scanner (source + dist, 0 findings).

Co-authored-by: Nicolas Fry <nicolas@turbodocx.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant