ChuckJonas / ts-force

A Salesforce REST Client written in Typescript for Typescript
88 stars 21 forks source link

Bump jsonwebtoken and @salesforce/core in /ts-force-gen #133

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps jsonwebtoken to 9.0.0 and updates ancestor dependency @salesforce/core. These dependencies need to be updated together.

Updates jsonwebtoken from 8.5.0 to 9.0.0

Changelog

Sourced from jsonwebtoken's changelog.

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539

8.5.1 - 2019-03-18

Bug fix

Docs

Commits
  • e1fa9dc Merge pull request from GHSA-8cf7-32gw-wr33
  • 5eaedbf chore(ci): remove github test actions job (#861)
  • cd4163e chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)
  • ecdf6cc fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...
  • 8345030 fix(sign&verify)!: Remove default none support from sign and verify met...
  • 7e6a86b Upload OpsLevel YAML (#849)
  • 74d5719 docs: update references vercel/ms references (#770)
  • d71e383 docs: document "invalid token" error
  • 3765003 docs: fix spelling in README.md: Peak -> Peek (#754)
  • a46097e docs: make decode impossible to discover before verify
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.


Updates @salesforce/core from 2.12.3 to 3.32.12

Release notes

Sourced from @​salesforce/core's releases.

3.32.12

Bug Fixes

  • deps: bump jsonwebtoken from 8.5.1 to 9.0.0 (c40ea0a)

3.32.11

Bug Fixes

3.32.10

Bug Fixes

3.32.9

Bug Fixes

  • add password property to (1995c01)

3.32.8

Bug Fixes

  • deps: bump ajv from 8.11.0 to 8.11.2 (78eb48d)

3.32.7

Bug Fixes

  • deps: bump decode-uri-component from 0.2.0 to 0.2.2 (bb4c0d1)

3.32.6

Bug Fixes

  • remove refs to legacy client id (82689ea)

3.32.5

Bug Fixes

  • update a few tests (6952b44)
  • use API version cache more often (36b0e81)

3.32.4

Bug Fixes

  • deps: bump @​types/semver from 7.3.10 to 7.3.13 (0584bf6)

3.32.3

Bug Fixes

  • deps: bump @​salesforce/schemas from 1.1.3 to 1.4.0 (9b0f2a9)

... (truncated)

Changelog

Sourced from @​salesforce/core's changelog.

3.32.12 (2022-12-23)

Bug Fixes

  • deps: bump jsonwebtoken from 8.5.1 to 9.0.0 (c40ea0a)

3.32.11 (2022-12-16)

Bug Fixes

3.32.10 (2022-12-15)

Bug Fixes

3.32.9 (2022-12-08)

Bug Fixes

  • add password property to (1995c01)

3.32.8 (2022-12-04)

Bug Fixes

  • deps: bump ajv from 8.11.0 to 8.11.2 (78eb48d)

3.32.7 (2022-12-04)

Bug Fixes

... (truncated)

Commits
  • a173e77 chore(release): 3.32.12 [skip ci]
  • 09f041a Merge pull request #734 from forcedotcom/dependabot-npm_and_yarn-jsonwebtoken...
  • c40ea0a fix(deps): bump jsonwebtoken from 8.5.1 to 9.0.0
  • c486d1d Merge pull request #730 from forcedotcom/dependabot-npm_and_yarn-typescript-e...
  • f6526c0 chore(dev-deps): bump @​typescript-eslint/parser from 5.45.0 to 5.46.1
  • 8ab97cd chore(release): 3.32.11 [skip ci]
  • 00ee0fc fix: add password to mock org getConfig (#729)
  • 5a48a30 chore(release): 3.32.10 [skip ci]
  • 98b2503 fix: provide way to stub user data (#728)
  • dbc3ef5 Merge pull request #723 from forcedotcom/dependabot-npm_and_yarn-typescript-4...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by salesforce-releases, a new releaser for @​salesforce/core since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ChuckJonas/ts-force/network/alerts).
dependabot[bot] commented 1 year ago

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.