msanvarov / nest-rest-mongo-boilerplate

🍱 backend with nest (typescript), mongoose, and authentication
https://msanvarov.github.io/nest-rest-mongo-boilerplate/
MIT License
284 stars 42 forks source link

Bump jsonwebtoken, @nestjs/jwt and passport-jwt #1246

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps jsonwebtoken to 9.0.0 and updates ancestor dependencies jsonwebtoken, @nestjs/jwt and passport-jwt. These dependencies need to be updated together.

Updates jsonwebtoken from 8.5.1 to 9.0.0

Changelog

Sourced from jsonwebtoken's changelog.

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
Commits
  • e1fa9dc Merge pull request from GHSA-8cf7-32gw-wr33
  • 5eaedbf chore(ci): remove github test actions job (#861)
  • cd4163e chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)
  • ecdf6cc fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...
  • 8345030 fix(sign&verify)!: Remove default none support from sign and verify met...
  • 7e6a86b Upload OpsLevel YAML (#849)
  • 74d5719 docs: update references vercel/ms references (#770)
  • d71e383 docs: document "invalid token" error
  • 3765003 docs: fix spelling in README.md: Peak -> Peek (#754)
  • a46097e docs: make decode impossible to discover before verify
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.


Updates @nestjs/jwt from 9.0.0 to 10.0.1

Release notes

Sourced from @​nestjs/jwt's releases.

Release 10.0.1

  • chore(husky): change npx --no to --no-install (7218087)
  • Merge pull request #1144 from nestjs/renovate/typescript-eslint-monorepo (0274acc)
  • Merge pull request #1150 from nestjs/renovate/prettier-2.x (c6bbf14)
  • chore(deps): update typescript-eslint monorepo to v5.47.1 (414aea3)
  • chore(deps): update dependency prettier to v2.8.1 (44fd45a)
  • Merge pull request #1149 from nestjs/renovate/commitlint-monorepo (d8ed56a)
  • Merge pull request #1057 from nestjs/renovate/jsonwebtoken-8.x (74a21f9)
  • Merge pull request #1159 from nestjs/renovate/release-it-15.x (f367329)
  • chore(deps): update dependency release-it to v15.5.1 (b3f4fc7)
  • chore(deps): update commitlint monorepo to v17.3.0 (15ad133)
  • fix(deps): update dependency @​types/jsonwebtoken to v8.5.9 (d14521f)
  • Merge pull request #1158 from nestjs/renovate/node-18.x (cc04cce)
  • chore(deps): update dependency @​types/node to v18.11.18 (3ebfaf0)
  • Merge pull request #1146 from nestjs/renovate/typescript-4.x (a14a3be)
  • chore(deps): update dependency typescript to v4.9.4 (df59940)
  • Merge pull request #1157 from nestjs/dependabot/npm_and_yarn/minimatch-3.1.2 (e5661b9)
  • Merge pull request #1151 from nestjs/renovate/lint-staged-13.x (8d74976)
  • Merge pull request #1148 from nestjs/renovate/eslint-8.x (76b0ee3)
  • chore(deps): bump minimatch from 3.0.4 to 3.1.2 (f3dd100)
  • chore(deps): update dependency lint-staged to v13.1.0 (7b3319a)
  • Merge pull request #1145 from nestjs/renovate/jest-monorepo (a97c753)
  • Merge pull request #1155 from nestjs/renovate/npm-jsonwebtoken-vulnerability (73a7440)
  • chore(deps): update dependency eslint to v8.30.0 (8a6a459)
  • chore(deps): update dependency @​types/jest to v29.2.4 (20c2366)
  • chore(deps): update dependency jsonwebtoken to 9.0.0 [security] (98a4464)
  • chore: use npm v8 (27d843c)
  • chore(deps): update dependency jest to v29.3.1 (ef435fb)
  • chore(deps): update dependency husky to v8.0.2 (9582491)
  • chore(deps): update dependency jest to v29.3.0 (52fef84)
  • chore(deps): update typescript-eslint monorepo to v5.42.1 (e2d47cc)
  • chore(deps): update nest monorepo to v9.2.0 (fcb7300)
  • chore(deps): update dependency eslint to v8.27.0 (8d99cb8)
  • chore(deps): update dependency @​types/jest to v29.2.2 (8094086)
  • chore(deps): update dependency @​types/node to v18.11.9 (f36d84b)
  • chore(deps): update dependency @​types/jest to v29.2.1 (c15602f)
  • chore(deps): update typescript-eslint monorepo to v5.42.0 (ca2de19)
  • chore(deps): update commitlint monorepo to v17.2.0 (a5ed87c)
  • chore(deps): update dependency @​types/node to v18.11.8 (78834c9)
  • chore(deps): update dependency @​types/node to v18.11.7 (3a6ce6f)
  • chore(deps): update dependency @​types/node to v18.11.6 (8235062)
  • chore(deps): update dependency @​types/node to v18 (697649c)
  • chore(deps): update typescript-eslint monorepo to v5.41.0 (a168713)
  • chore(deps): update dependency jest to v29.2.2 (44181e6)
  • chore(deps): update nest monorepo to v9.1.6 (79a5f32)
  • chore(deps): update dependency @​types/node to v16.18.0 (167b84f)
  • chore(deps): update dependency eslint to v8.26.0 (76af6b2)
  • chore(deps): update nest monorepo to v9.1.5 (ab124c9)
  • chore(deps): update dependency @​types/node to v16.11.68 (5cc2ce3)
  • chore(deps): update dependency jest to v29.2.1 (41bdc6a)

... (truncated)

Commits
  • 53b90d0 chore(): release v10.0.1
  • 7218087 chore(husky): change npx --no to --no-install
  • 0274acc Merge pull request #1144 from nestjs/renovate/typescript-eslint-monorepo
  • c6bbf14 Merge pull request #1150 from nestjs/renovate/prettier-2.x
  • 414aea3 chore(deps): update typescript-eslint monorepo to v5.47.1
  • 44fd45a chore(deps): update dependency prettier to v2.8.1
  • d8ed56a Merge pull request #1149 from nestjs/renovate/commitlint-monorepo
  • 74a21f9 Merge pull request #1057 from nestjs/renovate/jsonwebtoken-8.x
  • f367329 Merge pull request #1159 from nestjs/renovate/release-it-15.x
  • b3f4fc7 chore(deps): update dependency release-it to v15.5.1
  • Additional commits viewable in compare view


Updates passport-jwt from 4.0.0 to 4.0.1

Commits
  • fed94fa 4.0.1 release
  • cfb5566 Merge pull request #248 from mikenicholson/update-minmatch
  • 8e4ad5b Address minmatch vulnerability
  • e9cf2ce Merge pull request #247 from mikenicholson/jsonwebtoken-9
  • bfbc6cc Update jsonwebtoken to 9.0.0
  • a49b43e Update minimist due to prototype pollution vulnerability in previous version
  • a5137c6 Merge pull request #192 from markhoney/patch-1
  • ea824cd Update jsonwebtoken and run npm audit fix
  • 8e57eec Remove older node versions shiping npm without support for "ci"
  • 3ab9305 Add CI workflow in GitHub Actions
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/msanvarov/nest-rest-mongo-boilerplate/network/alerts).
sonarcloud[bot] commented 1 year ago

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication