SocialGouv / reva

https://reva.beta.gouv.fr
Apache License 2.0
3 stars 3 forks source link

chore(deps): bump keycloak-connect from 18.0.1 to 21.0.1 #647

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps keycloak-connect from 18.0.1 to 21.0.1.

Commits
  • a11466f Set version to 21.0.1
  • 15ef5df Prevent open redirect when checking SSO
  • e4bd6b7 Add a deprecation message to the README (#449)
  • a56a309 Bump @​octokit/rest from 19.0.4 to 19.0.5 (#440)
  • f8e397c Bump body-parser from 1.20.0 to 1.20.1 (#436)
  • 9061a73 Bump express from 4.18.1 to 4.18.2 (#437)
  • c34daa0 Remove status badges that are no longer updated (#432)
  • e5921ff Bump node-fetch from 3.2.9 to 3.2.10 (#409)
  • 3587ea4 Bump @​octokit/rest from 19.0.3 to 19.0.4 (#415)
  • 1eef597 Bump chromedriver from 105.0.0 to 105.0.1 (#430)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by keycloak.bot, a new releaser for keycloak-connect since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/SocialGouv/reva/network/alerts).
socket-security[bot] commented 1 year ago

Socket Security Pull Request Report

Dependency issues detected: If you merge this pull request, you will not be alerted to the instances of these issues again.

📜 Install scripts

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Package Script field Source
chromedriver@110.0.0 (upgraded) install package-lock.json, packages/reva-api/package.json via keycloak-connect@21.0.1
elm@0.19.1-5 (added) install package-lock.json, packages/reva-admin/package.json
Pull request report summary
Issue Status
Install scripts ⚠️ 2 issues
Native code ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues
Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore chromedriver@110.0.0
  • @SocketSecurity ignore elm@0.19.1-5

Powered by socket.dev