GluuFederation / gluu-passport

Gluu interface to Passport.js to support social login and inbound identity.
Apache License 2.0
6 stars 17 forks source link

build(deps): bump jose from 4.4.0 to 4.7.0 #436

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps jose from 4.4.0 to 4.7.0.

Release notes

Sourced from jose's releases.

v4.7.0

Features

  • add createRemoteJWKSet cacheMaxAge option (5017d95), closes #394

v4.6.2

Fixes

  • dont check JWT iat is in the past unless maxTokenAge is used (96d85c7)

v4.6.1

This release contains only code refactoring and documentation updates.

v4.6.0

Features

  • mark APIs and parameters that can lead to footguns as deprecated (0ddbcc6)
  • types: include JSDoc in the types (74187a9)

v4.5.3

Fixes

  • web api runtime: rely on default fetch init values (df6d966)

v4.5.2

Fixes

  • decrypting empty ciphertext compact JWEs (#374) (95fe597)

v4.5.1

Fixes

  • typescript: allow synchronous get key functions (7c99153)

v4.5.0

Features

  • add jose.decodeJwt utility (3d2a2b8)

Fixes

  • concurrent fetch await in cloudflare (e44cd18), closes #355
Changelog

Sourced from jose's changelog.

4.7.0 (2022-04-21)

Features

  • add createRemoteJWKSet cacheMaxAge option (5017d95), closes #394

4.6.2 (2022-04-19)

Fixes

  • dont check JWT iat is in the past unless maxTokenAge is used (96d85c7)

4.6.1 (2022-04-11)

4.6.0 (2022-03-06)

Features

  • mark APIs and parameters that can lead to footguns as deprecated (0ddbcc6)
  • types: include JSDoc in the types (74187a9)

4.5.3 (2022-03-05)

Fixes

  • web api runtime: rely on default fetch init values (df6d966)

4.5.2 (2022-03-04)

Fixes

  • decrypting empty ciphertext compact JWEs (#374) (95fe597)

4.5.1 (2022-02-22)

Fixes

  • typescript: allow synchronous get key functions (7c99153)

4.5.0 (2022-02-07)

Features

... (truncated)

Commits
  • 06d8b93 chore(release): 4.7.0
  • 5017d95 feat: add createRemoteJWKSet cacheMaxAge option
  • 0849d0e chore: cleanup after publish
  • f669552 chore(release): 4.6.2
  • 96d85c7 fix: dont check JWT iat is in the past unless maxTokenAge is used
  • fbb72ab chore: cleanup after publish
  • a92f2a8 chore(release): 4.6.1
  • 041aef7 refactor(webapi): faster base64url decode
  • 263cc0c chore: ignore type errors for node's webcrypto
  • de56117 refactor: simplify concat kdf
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
christian-hawk commented 2 years ago

Can one of the admins verify this patch?

codecov[bot] commented 2 years ago

Codecov Report

Merging #436 (b201dc2) into master (ca8f7d7) will not change coverage. The diff coverage is n/a.

:exclamation: Current head b201dc2 differs from pull request most recent head f371fc5. Consider uploading reports for the commit f371fc5 to get more accurate results

@@           Coverage Diff           @@
##           master     #436   +/-   ##
=======================================
  Coverage   78.58%   78.58%           
=======================================
  Files          36       36           
  Lines         780      780           
=======================================
  Hits          613      613           
  Misses        167      167           

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update ca8f7d7...f371fc5. Read the comment docs.

dependabot[bot] commented 2 years ago

Superseded by #438.