oracle-devrel / oci-devops-examples

Collection instruction based samples of OCI Devops. - [Quick view](https://github.com/oracle-devrel/oci-devops-examples/blob/main/AIO.md)
Universal Permissive License v1.0
33 stars 61 forks source link

Bump jsonwebtoken, oci-common and oci-devops in /oci-pipeline-examples/oci-cascaded-pipelines/same-region/trigger-deploy-from-build/node-function #53

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps jsonwebtoken to 9.0.0 and updates ancestor dependencies jsonwebtoken, oci-common and oci-devops. These dependencies need to be updated together.

Updates jsonwebtoken from 8.5.1 to 9.0.0

Changelog

Sourced from jsonwebtoken's changelog.

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
Commits
  • e1fa9dc Merge pull request from GHSA-8cf7-32gw-wr33
  • 5eaedbf chore(ci): remove github test actions job (#861)
  • cd4163e chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)
  • ecdf6cc fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...
  • 8345030 fix(sign&verify)!: Remove default none support from sign and verify met...
  • 7e6a86b Upload OpsLevel YAML (#849)
  • 74d5719 docs: update references vercel/ms references (#770)
  • d71e383 docs: document "invalid token" error
  • 3765003 docs: fix spelling in README.md: Peak -> Peek (#754)
  • a46097e docs: make decode impossible to discover before verify
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.


Updates oci-common from 2.21.0 to 2.52.0

Release notes

Sourced from oci-common's releases.

2.52.0

Added

  • Support for the Visual Builder Studio service

  • Support for the Autonomous Recovery service

  • Support for selecting specific database servers when creating autonomous VM clusters in the Database service

  • Support for creating autonomous VMs during the creation of autonomous VM clusters in the Database service

Breaking Changes

  • Support for retries by default on operations of the Compute service

File Checksums (SHA256)

oci-typescript-sdk.zip 657ef4f3811a39306b8eb139c3f38af5d89ce09420f37fdfe63998a7d7c1b4a3 npm_artifacts.zip 26cdbdc49b7469d21dbc87035dce6134e6c7839018528ea284ebb5012f7f387e

2.51.0

Added

  • Support for changing Data Guard role of a database instance within the Database service

  • Support for listing autonomous container database versions in the Database service

  • Support for specifying a database version when creating or updating an autonomous container database in the Database service

  • Support for specifying an eCPU count when creating or updating autonomous shared databases in the Database service

  • Support for Helm attestation and Helm arguments on deploy operations in the DevOps service

  • Support for uploading master key wallets for deployments in the GoldenGate service

  • Support for custom configurations in the Operations Insights service

  • Support for refreshing the session token in SessionTokenAuthenticationDetailsProvider

Breaking Changes

  • The property cpuCoreCount has been made optional in AutonomousDatabase and AutonomousDatabaseSummary model in the Database service

... (truncated)

Changelog

Sourced from oci-common's changelog.

2.52.0 - 2023-02-14

Added

  • Support for the Visual Builder Studio service
  • Support for the Autonomous Recovery service
  • Support for selecting specific database servers when creating autonomous VM clusters in the Database service
  • Support for creating autonomous VMs during the creation of autonomous VM clusters in the Database service

Breaking Changes

  • Support for retries by default on operations of the Compute service

2.51.0 - 2023-02-07

Added

  • Support for changing Data Guard role of a database instance within the Database service
  • Support for listing autonomous container database versions in the Database service
  • Support for specifying a database version when creating or updating an autonomous container database in the Database service
  • Support for specifying an eCPU count when creating or updating autonomous shared databases in the Database service
  • Support for Helm attestation and Helm arguments on deploy operations in the DevOps service
  • Support for uploading master key wallets for deployments in the GoldenGate service
  • Support for custom configurations in the Operations Insights service
  • Support for refreshing the session token in SessionTokenAuthenticationDetailsProvider

Breaking Changes

  • The property cpuCoreCount has been made optional in AutonomousDatabase and AutonomousDatabaseSummary model in the Database service

2.50.4 - 2023-01-31

Added

  • Support for ECPU billing for autonomous databases and dedicated autonomous databases on Exadata Cloud at Customer in the Database service
  • Support for providing a vault secret ID when creating or updating autonomous shared databases in the Database service
  • Support for including ORDS and database transform URLs as autonomous database connections in the Database service
  • Support for role-based access control on OpenSearch clusters in the Search service
  • Support for managed shell stages on deployments in the DevOps service
  • Support for memory encryption on confidential VMs in the Compute service
  • Support for configuration items, and reporting ownership of configuration items, in the Application Performance Monitoring service

2.50.3 - 2023-01-24

Added

  • Support for the Cloud Migrations service
  • Support for setting up custom private IPs while creating private endpoints in the Database service
  • Support for machine learning pipelines in the Data Science service
  • Support for personally identifiable information detection in the AI Language service

2.50.2 - 2023-01-17

Added

  • Support for calling Oracle Cloud Infrastructure services in the us-chicago-1 region
  • Support for cross-region replication in the File Storage service
  • Support for setting up private DNS on ExaCS systems during provisioning in the Database service

... (truncated)

Commits


Updates oci-devops from 2.21.0 to 2.52.0

Release notes

Sourced from oci-devops's releases.

2.52.0

Added

  • Support for the Visual Builder Studio service

  • Support for the Autonomous Recovery service

  • Support for selecting specific database servers when creating autonomous VM clusters in the Database service

  • Support for creating autonomous VMs during the creation of autonomous VM clusters in the Database service

Breaking Changes

  • Support for retries by default on operations of the Compute service

File Checksums (SHA256)

oci-typescript-sdk.zip 657ef4f3811a39306b8eb139c3f38af5d89ce09420f37fdfe63998a7d7c1b4a3 npm_artifacts.zip 26cdbdc49b7469d21dbc87035dce6134e6c7839018528ea284ebb5012f7f387e

2.51.0

Added

  • Support for changing Data Guard role of a database instance within the Database service

  • Support for listing autonomous container database versions in the Database service

  • Support for specifying a database version when creating or updating an autonomous container database in the Database service

  • Support for specifying an eCPU count when creating or updating autonomous shared databases in the Database service

  • Support for Helm attestation and Helm arguments on deploy operations in the DevOps service

  • Support for uploading master key wallets for deployments in the GoldenGate service

  • Support for custom configurations in the Operations Insights service

  • Support for refreshing the session token in SessionTokenAuthenticationDetailsProvider

Breaking Changes

  • The property cpuCoreCount has been made optional in AutonomousDatabase and AutonomousDatabaseSummary model in the Database service

... (truncated)

Changelog

Sourced from oci-devops's changelog.

2.52.0 - 2023-02-14

Added

  • Support for the Visual Builder Studio service
  • Support for the Autonomous Recovery service
  • Support for selecting specific database servers when creating autonomous VM clusters in the Database service
  • Support for creating autonomous VMs during the creation of autonomous VM clusters in the Database service

Breaking Changes

  • Support for retries by default on operations of the Compute service

2.51.0 - 2023-02-07

Added

  • Support for changing Data Guard role of a database instance within the Database service
  • Support for listing autonomous container database versions in the Database service
  • Support for specifying a database version when creating or updating an autonomous container database in the Database service
  • Support for specifying an eCPU count when creating or updating autonomous shared databases in the Database service
  • Support for Helm attestation and Helm arguments on deploy operations in the DevOps service
  • Support for uploading master key wallets for deployments in the GoldenGate service
  • Support for custom configurations in the Operations Insights service
  • Support for refreshing the session token in SessionTokenAuthenticationDetailsProvider

Breaking Changes

  • The property cpuCoreCount has been made optional in AutonomousDatabase and AutonomousDatabaseSummary model in the Database service

2.50.4 - 2023-01-31

Added

  • Support for ECPU billing for autonomous databases and dedicated autonomous databases on Exadata Cloud at Customer in the Database service
  • Support for providing a vault secret ID when creating or updating autonomous shared databases in the Database service
  • Support for including ORDS and database transform URLs as autonomous database connections in the Database service
  • Support for role-based access control on OpenSearch clusters in the Search service
  • Support for managed shell stages on deployments in the DevOps service
  • Support for memory encryption on confidential VMs in the Compute service
  • Support for configuration items, and reporting ownership of configuration items, in the Application Performance Monitoring service

2.50.3 - 2023-01-24

Added

  • Support for the Cloud Migrations service
  • Support for setting up custom private IPs while creating private endpoints in the Database service
  • Support for machine learning pipelines in the Data Science service
  • Support for personally identifiable information detection in the AI Language service

2.50.2 - 2023-01-17

Added

  • Support for calling Oracle Cloud Infrastructure services in the us-chicago-1 region
  • Support for cross-region replication in the File Storage service
  • Support for setting up private DNS on ExaCS systems during provisioning in the Database service

... (truncated)

Commits


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/oracle-devrel/oci-devops-examples/network/alerts).
github-actions[bot] commented 1 year ago

:warning: WARNING: Missing Copyright Notice(s) It's a good idea to have copyright notices at the top of each file. It looks like at least one file was missing this (though it might be further down in the file - this might be a false-positive).

Details: :warning: - :

github-actions[bot] commented 1 year ago

:no_entry: License Inspection Requires manual inspection. There are some licenses which dictate further analysis and review.