Skip to content

fix(compute): update nodemailer and remove decommissioned smtp-transport dependency#4386

Draft
angelcaamal wants to merge 2 commits into
mainfrom
fix/update-nodemailer-vulnerabilities
Draft

fix(compute): update nodemailer and remove decommissioned smtp-transport dependency#4386
angelcaamal wants to merge 2 commits into
mainfrom
fix/update-nodemailer-vulnerabilities

Conversation

@angelcaamal

@angelcaamal angelcaamal commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Description

Fixes security vulnerabilities reported in dependencies by updating nodemailer to a secure version and removing the decommissioned nodemailer-smtp-transport package.

Changes Made:

  • Updated nodemailer to the latest secure version to address security advisories.
  • Removed the decommissioned nodemailer-smtp-transport dependency (npm audit fix).
  • Refactored mailjet.js to use nodemailer's native SMTP transport configuration directly.
  • Refactored unit tests in test/mailjet.test.js to align with the new native transport setup.
image

Fixes Internal: b/537368484

Note: Before submitting a pull request, please open an issue for discussion if you are not associated with Google.

Checklist

  • I have followed guidelines from CONTRIBUTING.MD and Samples Style Guide
  • Tests pass: npm test (see Testing)
  • Lint pass: npm run lint (see Style)
  • Required CI tests pass (see CI testing)
  • These samples need a new API enabled in testing projects to pass (let us know which ones)
  • These samples need a new/updated env vars in testing projects set to pass (let us know which ones)
  • This pull request is from a branch created directly off of GoogleCloudPlatform/nodejs-docs-samples. Not a fork.
  • This sample adds a new sample directory, and I updated the CODEOWNERS file with the codeowners for this sample
  • This sample adds a new sample directory, and I created GitHub Actions workflow for this sample
  • This sample adds a new Product API, and I updated the Blunderbuss issue/PR auto-assigner with the codeowners for this sample
  • Please merge this PR for me once it is approved

Note: Any check with (dev), (experimental), or (legacy) can be ignored and should not block your PR from merging (see CI testing).

@angelcaamal angelcaamal added api: compute Issues related to the Compute Engine API. samples Issues that are directly related to samples. labels Jul 22, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request simplifies the Mailjet configuration by removing the deprecated nodemailer-smtp-transport dependency and passing options directly to nodemailer.createTransport. It also updates the corresponding unit tests. Feedback points out that the specified nodemailer version ^9.0.0 does not exist and will cause installation failures, and identifies a typo in the API key placeholder string.

Comment thread compute/package.json
Comment thread compute/mailjet.js Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: compute Issues related to the Compute Engine API. samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant