Repository navigation
fix(node): clear all n8n community-node review findings (scanner + codex) - #33
Merged
Merged
Conversation
Makes the package pass `@n8n/scan-community-package` cleanly (0 errors, 0
warnings). Addresses every finding the n8n reviewers flagged:
- require-node-api-error: TurboDocx.node.ts re-threw a caught error variable.
Re-raise it as a fresh NodeOperationError, preserving message + description
verbatim (execute.unknownOperation.test.ts pins that behavior).
- no-hardcoded-secrets: the HMAC contract test hardcoded `whsec_test_...`.
Generate the secret per-run with crypto.randomBytes — any value works, the
test only exercises the HMAC round-trip.
- test files were compiled into dist/ and shipped in the tarball (which also
tripped the secret rule on the dist side). Exclude __tests__/*.test.ts from
the build (tsconfig exclude; tsconfig.test.json re-includes for jest).
- icon-prefer-themed-variants: node, trigger and both credentials used a
single-file icon. Provide { light, dark } with a distinct turbodocx.dark.svg
(the brand mark is theme-independent, so the dark file mirrors the light one).
Verified: scanner passes (source + dist legs), `npm run lint` clean, and all
25 suites / 129 jest tests pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The n8n community-node review flagged `[LOW] Codex nodeVersion should be "1.0"` — it's a fixed schema value (mirrors the node's internal `version`, like every node in n8n-nodes-base), not the package release. Both codex files tracked the release version (1.4.0); pin them to "1.0". Also update AGENTS.md: drop `nodeVersion` from the release version-bump list and its sanity check, and rewrite the rationale so the next release doesn't reintroduce the finding. Caught by `npx @n8n/node-cli@latest lint` (exit 0). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Member
Author
|
CR: TurboDocx/workflow-templates#8 (private) |
nicolasiscoding
marked this pull request as ready for review
August 20, 2026 19:07
Member
Author
|
approved |
Merged
nicolasiscoding
added a commit
that referenced
this pull request
Aug 20, 2026
Patch release carrying the n8n community-node review fixes (#33) on top of the 1.4.0 feature set (partner prefs, optional quote decline reason, TurboSign conditional fields). Bumps package.json, package-lock.json (both root fields), and clientContext NODE_PACKAGE_VERSION; codex nodeVersion stays "1.0". Pre-release checks pass: npm ci, lint, build, jest (129 tests), and the @n8n/scan-community-package scanner (source + dist, 0 findings). Co-authored-by: Nicolas Fry <nicolas@turbodocx.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Makes the package pass the n8n community-node review clean. Fixes every finding the reviewers flagged — the
@n8n/scan-community-packagescanner findings and the codexnodeVersionlint finding.Scanner findings (
@n8n/scan-community-package)require-node-api-error(TurboDocx.node.ts): re-threw a caught error variable. Now re-raised as a freshNodeOperationError, message + description preserved verbatim.execute.unknownOperation.test.tspins that behavior (still passes).no-hardcoded-secrets(hmac.contract.test.ts): hardcodedwhsec_test_…. Now generated per-run withcrypto.randomBytes— any value works, the test only exercises the HMAC round-trip.dist/(which also tripped the secret rule on the dist side): exclude__tests__/*.test.tsfrom the build (tsconfigexclude;tsconfig.test.jsonre-includes for jest).dist/now ships only real node/credential code.icon-prefer-themed-variants(node, trigger, both credentials): single-file icons →{ light, dark }with a distinctturbodocx.dark.svg. (The scanner errors if light and dark point at the same file, so a distinct file is required; the brand mark is theme-independent, so the dark file mirrors the light one.)Codex finding
[LOW] Codex nodeVersion should be "1.0": both*.node.jsontracked the release version (1.4.0). Pinned to"1.0"(fixed schema value). AGENTS.md updated to dropnodeVersionfrom the release bump list + rewrite the rationale so it doesn't recur.Verification
node scripts/scan-community-package.mjs: ✅ source + dist legs pass, 0 errors / 0 warningsnpx @n8n/node-cli@latest lint: exit 0 (v0.44.4)npm run lint: clean ·npx jest: 25 suites / 129 tests passRelationship to #32
#32 wires this scanner into CI + a pre-commit hook (currently a failing gate). This PR makes the node pass that gate. Merge this with or before #32 so
mainnever carries a red gate.🤖 Generated with Claude Code