Skip to main content

Maintaining Your Application

Security Patching​

As a developer, it is essential to keep your application and its dependencies up-to-date, ensuring that there are no vulnerabilities. With each update, you should bump the version number and submit it for review. Our team will manually review and approve each update, ensuring the safety and stability of the platform. We are continuously scanning apps on the platform for vulnerabilities and not upgrading your app can cause it to be disabled.

Upgrading SDK Packages​

We will periodically release updates for our SDK libraries. It is crucial to keep your applications using the latest versions to maintain compatibility as our platform evolves. You may receive a warning in the terminal when submitting your app if your SDK is outdated. While you can initially ignore this warning, outdated SDK versions may eventually result in your app not being approved or even removed from the platform.

Upgrade with the @trackunit/migrations package. It moves every @trackunit/* dependency in your package.json to its latest published version and applies any code migrations those new versions ship.

Workspaces created before this package existed do not have it. Add it once:

npm install -D @trackunit/migrations

Then run the two-step flow from your project root:

npx nx g @trackunit/migrations:migrate
npx nx g @trackunit/migrations:run-migrations

migrate updates your dependency versions, installs them, and writes any pending migrations to trackunit-migrations.json. Review that file, then run-migrations applies them to your source.

Two things are worth knowing:

  • One run of migrate is enough. Migrations ship inside the packages themselves, so migrate upgrades package.json, installs, and only then discovers and queues the migrations from the new versions. If the install fails, the run fails and tells you to install and run migrate again. Pass --skipInstall if you would rather run the install yourself; that run writes no migrations file, so install and then run migrate again.
  • Every @trackunit/* dependency is upgraded, not only the ones that ship migrations. Your version ranges are preserved, so a ^-ranged dependency stays ^-ranged rather than becoming pinned.

Migrations that have already been applied are recorded in trackunit-migrations.json and will not run again, so it is safe to commit that file.

Updating Your Nx Workspace​

The SDK relies on specific Nx and Node.js versions. Ensure that your application complies with the required versions at all times. Do not update your Nx workspace immediately when a new Nx version is released. Instead, only upgrade when our SDKs depend on a newer version. If in doubt, refer to the prerequisites page. It will be updated whenever our packages depend on new Nx and Node versions.

@trackunit/iris-app depends on an exact Nx version, so that is the version to migrate to. You can check it with:

npm view @trackunit/iris-app dependencies.nx

Migrating an existing Nx workspace to a new version is relatively simple as long as you follow our guidelines and their best-practices when working with Nx.

For more information on how to migrate an Nx workspace refer to the official NX documentation and the nx migrate command.