Open dependabot[bot] opened 1 year ago
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase
.
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase
.
Bumps jsonwebtoken to 9.0.0 and updates ancestor dependencies jsonwebtoken, express-jwt and jwks-rsa. These dependencies need to be updated together.
Updates
jsonwebtoken
from 8.5.1 to 9.0.0Changelog
Sourced from jsonwebtoken's changelog.
Commits
e1fa9dc
Merge pull request from GHSA-8cf7-32gw-wr335eaedbf
chore(ci): remove github test actions job (#861)cd4163e
chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)ecdf6cc
fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...8345030
fix(sign&verify)!: Remove defaultnone
support fromsign
andverify
met...7e6a86b
Upload OpsLevel YAML (#849)74d5719
docs: update references vercel/ms references (#770)d71e383
docs: document "invalid token" error3765003
docs: fix spelling in README.md: Peak -> Peek (#754)a46097e
docs: make decode impossible to discover before verifyMaintainer changes
This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.
Updates
express-jwt
from 6.0.0 to 8.2.0Changelog
Sourced from express-jwt's changelog.
... (truncated)
Commits
4905b01
8.2.0ca6c90c
add an optional handler for expired tokens. closes #60484b8f1e6
update changelogcf291b4
8.1.0bcad8af
update type to match jwks-rsa25a30f0
feat: export middleware options type. closes #308c69a0e4
update changelog2157954
8.0.0d8ffa02
upgrade jsonwebtoken to v9c555b48
Merge pull request #306 from auth0/SRE-57-Upload-opslevel-yamlUpdates
jwks-rsa
from 1.7.0 to 3.0.0Release notes
Sourced from jwks-rsa's releases.
... (truncated)
Changelog
Sourced from jwks-rsa's changelog.
... (truncated)
Commits
82e4adb
Merge pull request #335 from auth0/release/v3.0.0f0b864c
Release v3.0.0670bb7d
Merge pull request #333 from panva/bump-jose6ae2849
Apply suggestions from code reviewd9dee3e
Update .circleci/config.yml62554cc
Update .circleci/config.yml13119f8
Merge branch 'master' into bump-josed578c53
[SDK-3706] Update readme to match new design (#332)2532d11
[major] bump jose23a0350
OpsLevel repo catalog - upload opslevel.yml (#331)Maintainer changes
This version was pushed to npm by auth0-oss, a new releaser for jwks-rsa since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/CoVital-Project/pulse-ox-data-collection-web-service/network/alerts).