Skip to content

feat!: upgrade selfsigned to v5 to drop node-forge - #89

Merged
chenjiahan merged 1 commit into
rstackjs:mainfrom
Nsttt:fix/selfsigned-v5
Oct 2, 2026
Merged

chenjiahan merged 1 commit into
rstackjs:mainfrom
Nsttt:fix/selfsigned-v5

Conversation

@Nsttt

@Nsttt Nsttt commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

selfsigned@3 depends on node-forge, which is flagged by security vulnerability scanners. selfsigned@5 replaces node-forge with @peculiar/x509 and the native WebCrypto API.

This upgrade unblocks getsentry/sentry#125476, whose vulnerability check fails on the transitive node-forge dependency:

@rsbuild/plugin-basic-ssl@1.2.3
└── selfsigned@3.0.1
    └── node-forge@1.4.0

Changes

selfsigned v5 has two breaking changes that affect this plugin:

  • generate() is now async, so we await it.
  • The days option was removed in favor of notAfterDate. To avoid a breaking change for plugin users, selfsignedOptions.days (default 30) is still accepted and converted to notAfterDate. If notAfterDate is set, days is ignored.

The cached certificate is now reused based on its actual expiry date (read with crypto.X509Certificate) instead of the file's mtime compared against days. This keeps working when users pass notAfterDate, and an unreadable cached file now triggers regeneration.

Test plan

  • pnpm build, pnpm check, tsc --noEmit and pnpm test pass
  • Manually verified that days: 1 produces a cert expiring in 1 day, that a valid cached cert is reused, that an invalid cached file is regenerated, and that notAfterDate is respected

@chenjiahan chenjiahan changed the title fix(deps): upgrade selfsigned to v5 to drop node-forge feat!: upgrade selfsigned to v5 to drop node-forge Oct 2, 2026
@chenjiahan
chenjiahan merged commit 7b27a01 into rstackjs:main Oct 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants