auth0 / auth0.js

Auth0 headless browser sdk
MIT License
998 stars 492 forks source link

Update dependencies for security fixes #1413

Closed joshiste closed 8 months ago

joshiste commented 8 months ago

Especially CVE-2022-25883

frederikprijck commented 8 months ago

Thanks 🚀

joshiste commented 7 months ago

@frederikprijck can we expect a release with this soonish?

frederikprijck commented 7 months ago

👋 @joshiste, can you help me understand the need for a new release? We do not publish our lockfile, and the updates are to devDependencies for as far as I can tell, which is why I was planning to let this one release with one of the future releases, instead of cutting a release for this specifically.

Is any tool complaining of auth0-js having a vulnerable dependency or what's the reason for expecting a new release?