OpenNetworkingFoundation / cla-manager

Automated CLA management and verification for ONF projects on Github and Gerrit
https://cla.opennetworking.org
3 stars 6 forks source link

Bump jsonwebtoken and firebase-admin #353

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps jsonwebtoken to 9.0.0 and updates ancestor dependency firebase-admin. These dependencies need to be updated together.

Updates jsonwebtoken from 8.5.1 to 9.0.0

Changelog

Sourced from jsonwebtoken's changelog.

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
Commits
  • e1fa9dc Merge pull request from GHSA-8cf7-32gw-wr33
  • 5eaedbf chore(ci): remove github test actions job (#861)
  • cd4163e chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)
  • ecdf6cc fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...
  • 8345030 fix(sign&verify)!: Remove default none support from sign and verify met...
  • 7e6a86b Upload OpsLevel YAML (#849)
  • 74d5719 docs: update references vercel/ms references (#770)
  • d71e383 docs: document "invalid token" error
  • 3765003 docs: fix spelling in README.md: Peak -> Peek (#754)
  • a46097e docs: make decode impossible to discover before verify
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.


Updates firebase-admin from 9.2.0 to 11.4.1

Release notes

Sourced from firebase-admin's releases.

Firebase Admin Node.js SDK v11.4.1

Bug Fixes

  • fix: Update jsonwebtoken to v9.0.0 (#2025)

Miscellaneous

  • [chore] Release 11.4.1 (#2026)
  • build(deps-dev): bump mocha from 10.1.0 to 10.2.0 (#2019)
  • build(deps-dev): bump @​typescript-eslint/parser from 5.42.1 to 5.47.0 (#2020)
  • build(deps-dev): bump @​typescript-eslint/eslint-plugin (#2018)

Firebase Admin Node.js SDK v11.4.0

Breaking Changes

  • change: Deprecate AutoML model support (#2013)

New Features

  • feat(fs): preferRest app option for Firestore (#1901)

Bug Fixes

  • fix(fcm): Increase batch send timeout to 15 seconds (#1999)
  • fix: Unregister socket timeout listener to prevent MaxListenersExceededWarning (#1993)

Miscellaneous

  • [chore] Release 11.4.0 (#2015)
  • build(deps): bump @​google-cloud/storage from 6.6.0 to 6.8.0 (#2008)
  • build(deps): bump @​types/node from 18.11.9 to 18.11.14 (#2012)
  • build(deps-dev): bump @​typescript-eslint/eslint-plugin (#2009)
  • build(deps): bump decode-uri-component from 0.2.0 to 0.2.2 (#1998)
  • build(deps): bump qs from 6.5.2 to 6.5.3 in /.github/actions/send-tweet (#2006)
  • build(deps-dev): bump eslint from 8.28.0 to 8.29.0 (#2003)
  • build(deps-dev): bump @​types/lodash from 4.14.186 to 4.14.191 (#1997)
  • build(deps-dev): bump eslint from 8.24.0 to 8.28.0 (#1991)
  • build(deps-dev): bump chai from 4.3.6 to 4.3.7 (#1990)
  • build(deps-dev): bump sinon from 14.0.1 to 14.0.2 (#1984)
  • build(deps-dev): bump @​firebase/auth-types from 0.11.0 to 0.11.1 (#1985)
  • build(deps): bump @​types/node from 18.7.23 to 18.11.9 (#1983)

Firebase Admin Node.js SDK v11.3.0

New Features

  • feat(extensions): Add extensions namespace (#1960)

Miscellaneous

  • [chore] Release 11.3.0 (#1981)

... (truncated)

Commits
  • 88ae832 [chore] Release 11.4.1 (#2026)
  • ccffa13 build(deps-dev): bump mocha from 10.1.0 to 10.2.0 (#2019)
  • 8c5ac01 build(deps-dev): bump @​typescript-eslint/parser from 5.42.1 to 5.47.0 (#2020)
  • 8d3501f build(deps-dev): bump @​typescript-eslint/eslint-plugin (#2018)
  • d23b1c5 fix: Update jsonwebtoken to v9.0.0 (#2025)
  • 1acdb67 [chore] Release 11.4.0 (#2015)
  • ba5ec2e change: Deprecate AutoML model support (#2013)
  • 8b8c874 build(deps): bump @​google-cloud/storage from 6.6.0 to 6.8.0 (#2008)
  • f079949 build(deps): bump @​types/node from 18.11.9 to 18.11.14 (#2012)
  • d385b93 build(deps-dev): bump @​typescript-eslint/eslint-plugin (#2009)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/OpenNetworkingFoundation/cla-manager/network/alerts).