rage / mooc.fi

https://mooc.fi
5 stars 6 forks source link

Bump jsonwebtoken and @graphql-tools/prisma-loader in /frontend #1078

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps jsonwebtoken and @graphql-tools/prisma-loader. These dependencies needed to be updated together. Updates jsonwebtoken from 8.5.1 to 9.0.0

Changelog

Sourced from jsonwebtoken's changelog.

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
Commits
  • e1fa9dc Merge pull request from GHSA-8cf7-32gw-wr33
  • 5eaedbf chore(ci): remove github test actions job (#861)
  • cd4163e chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)
  • ecdf6cc fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...
  • 8345030 fix(sign&verify)!: Remove default none support from sign and verify met...
  • 7e6a86b Upload OpsLevel YAML (#849)
  • 74d5719 docs: update references vercel/ms references (#770)
  • d71e383 docs: document "invalid token" error
  • 3765003 docs: fix spelling in README.md: Peak -> Peek (#754)
  • a46097e docs: make decode impossible to discover before verify
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.


Updates @graphql-tools/prisma-loader from 7.2.8 to 7.2.50

Changelog

Sourced from @​graphql-tools/prisma-loader's changelog.

7.2.50

Patch Changes

  • Updated dependencies []:
    • @​graphql-tools/url-loader@​7.16.29

7.2.49

Patch Changes

7.2.48

Patch Changes

  • Updated dependencies []:
    • @​graphql-tools/url-loader@​7.16.28

7.2.47

Patch Changes

  • Updated dependencies []:
    • @​graphql-tools/url-loader@​7.16.27

7.2.46

Patch Changes

  • Updated dependencies []:
    • @​graphql-tools/url-loader@​7.16.26

7.2.45

Patch Changes

  • Updated dependencies []:
    • @​graphql-tools/url-loader@​7.16.25

7.2.44

Patch Changes

  • Updated dependencies [904fe770]:
    • @​graphql-tools/utils@​9.1.3
    • @​graphql-tools/url-loader@​7.16.24

... (truncated)

Commits
  • d0dacb8 chore(release): update monorepo packages versions (#4935)
  • cd0994d chore(release): update monorepo packages versions (#4926)
  • c10d688 fix(deps): update dependency jsonwebtoken to v9 (#4923)
  • 0c6a63a chore(release): update monorepo packages versions (#4921)
  • 2016daf chore(release): update monorepo packages versions (#4916)
  • ea159dd chore(release): update monorepo packages versions (#4892)
  • 5927768 chore(release): update monorepo packages versions (#4891)
  • 9436db0 chore(release): update monorepo packages versions (#4888)
  • 90011f0 chore(release): update monorepo packages versions (#4884)
  • 9958427 chore(release): update monorepo packages versions (#4876)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/rage/mooc.fi/network/alerts).
codecov[bot] commented 1 year ago

Codecov Report

Merging #1078 (769140a) into master (9c5a0b4) will not change coverage. The diff coverage is n/a.

@@           Coverage Diff           @@
##           master    #1078   +/-   ##
=======================================
  Coverage   67.01%   67.01%           
=======================================
  Files         110      110           
  Lines        4171     4171           
  Branches      896      896           
=======================================
  Hits         2795     2795           
  Misses       1273     1273           
  Partials      103      103           
Flag Coverage Δ
backend 66.98% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

:mega: We’re building smart automated test selection to slash your CI/CD build times. Learn more

dependabot[bot] commented 1 year ago

Looks like these dependencies are up-to-date now, so this is no longer needed.