Apollon77 / daikin-controller-cloud

Connect and Control Daikin Cloud devices
MIT License
96 stars 26 forks source link

Bump openid-client from 4.9.1 to 5.1.5 #67

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps openid-client from 4.9.1 to 5.1.5.

Release notes

Sourced from openid-client's releases.

v5.1.5

Fixes

  • interoperable audience array value for JWT Client auth assertions (again) (96b367d)
  • typescript: add error constructors (#483) (9505cba)

v5.1.4

Fixes

  • dpop: htu without querystring (f6fa149)

v5.1.3

Fixes

  • add application/jwk-set+json to accept header for JWKS calls (#467) (f94d42b), closes #466

v5.1.2

Fixes

  • passing null as checks.nonce should not disable it (5120a07)

v5.1.1

Fixes

  • allow setting timeout to 0 to disable it (32b28b5), closes #443

v5.1.0

Features

  • support OAuth 2.0 Authorization Server Issuer Identification (fb6a141)
  • support server-provided DPoP nonces (update DPoP to draft-04) (a84950a)

Fixes

  • reject oauthCallback when id_token is detected (92ffee5)
  • typescript: ts-ignore missing AbortSignal global (d975c11), closes #433

v5.0.2

Bug Fixes

  • explicitly set content-length again (956c34b), closes #420

v5.0.1

Bug Fixes

  • explicitly set accept: application/json again (89cdbe2)

v5.0.0

⚠ BREAKING CHANGES

... (truncated)

Changelog

Sourced from openid-client's changelog.

5.1.5 (2022-04-14)

Fixes

  • interoperable audience array value for JWT Client auth assertions (again) (96b367d)
  • typescript: add error constructors (#483) (9505cba)

5.1.4 (2022-03-04)

Fixes

  • dpop: htu without querystring (f6fa149)

5.1.3 (2022-02-03)

Fixes

  • add application/jwk-set+json to accept header for JWKS calls (#467) (f94d42b), closes #466

5.1.2 (2022-01-13)

Fixes

  • passing null as checks.nonce should not disable it (5120a07)

5.1.1 (2021-12-20)

Fixes

  • allow setting timeout to 0 to disable it (32b28b5), closes #443

5.1.0 (2021-12-03)

Features

  • support OAuth 2.0 Authorization Server Issuer Identification (fb6a141)
  • support server-provided DPoP nonces (update DPoP to draft-04) (a84950a)

Bug Fixes

  • reject oauthCallback when id_token is detected (92ffee5)
  • typescript: ts-ignore missing AbortSignal global (d975c11), closes #433

... (truncated)

Commits
  • e25eb16 chore(release): 5.1.5
  • 9505cba fix(typescript): add error constructors (#483)
  • 96b367d fix: interoperable audience array value for JWT Client auth assertions (again)
  • 7a417c3 chore: prettier
  • 3adf1a4 ci: audit check in CI
  • a315ad4 ci: update actions/github-script
  • 674b7ed chore(release): 5.1.4
  • f6fa149 fix(dpop): htu without querystring
  • 9cfd910 ci: fix hashFiles
  • 444e770 ci: no need for a secret gitlab token
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 2 years ago

Looks like openid-client is up-to-date now, so this is no longer needed.