leonekmi / scrobbly

↩️ Scrobble your animes to Anilist, Kitsu!
https://scrobbly.leonekmi.fr
GNU General Public License v3.0
23 stars 1 forks source link

Bump jsonwebtoken and sign-addon #45

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps jsonwebtoken and sign-addon. These dependencies needed to be updated together. Updates jsonwebtoken from 8.2.1 to 9.0.0

Changelog

Sourced from jsonwebtoken's changelog.

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539

8.5.1 - 2019-03-18

Bug fix

Docs

8.5.0 - 2019-02-20

New Functionality

Test Improvements

Docs

8.4.0 - 2018-11-14

New Functionality

... (truncated)

Commits
  • e1fa9dc Merge pull request from GHSA-8cf7-32gw-wr33
  • 5eaedbf chore(ci): remove github test actions job (#861)
  • cd4163e chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)
  • ecdf6cc fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...
  • 8345030 fix(sign&verify)!: Remove default none support from sign and verify met...
  • 7e6a86b Upload OpsLevel YAML (#849)
  • 74d5719 docs: update references vercel/ms references (#770)
  • d71e383 docs: document "invalid token" error
  • 3765003 docs: fix spelling in README.md: Peak -> Peek (#754)
  • a46097e docs: make decode impossible to discover before verify
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.


Updates sign-addon from 0.3.1 to 5.2.0

Release notes

Sourced from sign-addon's releases.

5.2.0 (2023-01-02)

Main changes

None (dependency updates only, though jsonwebtoken was updated because its latest version fixed a security issue).

dependencies

  • Updated: dependency core-js to v3.27.1 (#1181)
  • Updated: dependency jsonwebtoken to 9.0.0 [security] (#1175)

dev dependencies

  • Updated: dependency @babel/core to v7.20.5 (#1167)
  • Updated: dependency @babel/preset-env to v7.19.4 (#1139)
  • Updated: dependency @types/jest to v29.2.5 (#1182)
  • Updated: dependency @types/jsonwebtoken to v9 (#1178)
  • Updated: dependency babel-loader to v9 (#1165)
  • Updated: dependency babel to v7.20.7 (#1177)
  • Updated: dependency eslint to v8.31.0 (#1183)
  • Updated: dependency jest to v29.3.1 (#1143, #1159)
  • Updated: dependency prettier to v2.8.1 (#1170)
  • Updated: dependency typescript to v4.9.4 (#1171)

others

  • Updated: dependency codecov orb to v3.2.4 (#1141)
  • Updated: dependency loader-utils to 2.0.4 (#1161)

5.1.0 (2022-10-04)

Main changes

None. Only (dev) dependency updates.

dependencies

  • Updated: dependency core-js to v3.25.3 (#1133)

dev dependencies

  • Updated: dependency @babel/core to v7.18.13 (#1119)
  • Updated: dependency @types/jest to v28.1.7 (#1117)
  • Updated: dependency @types/jsonwebtoken to v8.5.9 (#1121)
  • Updated: dependency eslint to v8.24.0 (#1132)
  • Updated: dependency jest to v29 (major) (#1124)
  • Updated: dependency prettier to v2.7.1 (#1089)
  • Updated: dependency typescript to v4.8.4 (#1135)
  • Updated: dependency babel to v7.19.3 (#1134)
  • Updated: dependency terser to 5.14.2 (#1109)

5.0.0 (2022-06-07)

... (truncated)

Commits
  • c81f9d5 chore(release): :arrow_up: release 5.2.0
  • 42e45ec chore(deps): lock file maintenance (#1184)
  • 7049da4 chore(deps): update dependency babel-loader to v9 (#1165)
  • 98eb3e1 chore(deps): update dependency @​types/jsonwebtoken to v9 (#1178)
  • b750c5f chore(deps): update dependency eslint to v8.31.0 (#1183)
  • 63978ac chore(deps): update dependency @​types/jest to v29.2.5 (#1182)
  • 68d5676 fix(deps): update dependency core-js to v3.27.1 (#1181)
  • 7b2221c chore(deps): update node.js to v16.19 (#1180)
  • f5c5c46 fix(deps): update dependency core-js to v3.27.0 (#1179)
  • ea1dd33 chore(deps): update babel monorepo to v7.20.7 (#1177)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/leonekmi/scrobbly/network/alerts).