txstate-etc / mssql-async

A wrapper for mssql for added convenience when working with async/await and inside docker containers.
MIT License
1 stars 0 forks source link

Bump jsonwebtoken and mssql #16

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps jsonwebtoken to 9.0.0 and updates ancestor dependency mssql. These dependencies need to be updated together.

Updates jsonwebtoken from 8.5.1 to 9.0.0

Changelog

Sourced from jsonwebtoken's changelog.

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
Commits
  • e1fa9dc Merge pull request from GHSA-8cf7-32gw-wr33
  • 5eaedbf chore(ci): remove github test actions job (#861)
  • cd4163e chore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)
  • ecdf6cc fix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...
  • 8345030 fix(sign&verify)!: Remove default none support from sign and verify met...
  • 7e6a86b Upload OpsLevel YAML (#849)
  • 74d5719 docs: update references vercel/ms references (#770)
  • d71e383 docs: document "invalid token" error
  • 3765003 docs: fix spelling in README.md: Peak -> Peek (#754)
  • a46097e docs: make decode impossible to discover before verify
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by julien.wollscheid, a new releaser for jsonwebtoken since your current version.


Updates mssql from 7.3.1 to 9.0.1

Release notes

Sourced from mssql's releases.

v9.0.0

What's Changed

Full Changelog: https://github.com/tediousjs/node-mssql/compare/v8.1.3...v9.0.0

v8.1.3

What's Changed

New Contributors

Full Changelog: https://github.com/tediousjs/node-mssql/compare/v8.1.2...v8.1.3

v8.1.1

What's Changed

New Contributors

Full Changelog: https://github.com/tediousjs/node-mssql/compare/v8.1.0...v8.1.1

v8.1.0

v8.0.2

What's Changed

  • Add node 14 to test matrix by @​dhensby in tediousjs/node-mssql#1339
  • Transaction/PreparedStatements expose the config from their parent connection (#1338)
  • Inherited request configs from the pool. Specifically stream and arrayRowMode now inherit accurately from the connection config (#1338)

v8.0.1

What's Changed

... (truncated)

Changelog

Sourced from mssql's changelog.

v9.0.1 (2022-08-18)

[fix] fix regression in requestTimout option not accepting 0 as a value (#1421)

v9.0.0 (2022-08-10)

[change] Upgrade tedious to v15 (#1417) [removed] Removed NodeJS 10 & 12 support (#1417)

v8.1.4 (2022-08-18)

[fix] fix regression in requestTimout option not accepting 0 as a value (#1421)

v8.1.3 (2022-08-08)

[fix] requestTimeout correctly resolved (#1398) [fix] Forcibly deny use of useColumnNames tedious config option that can be passed in the config object (#1416)

v8.1.2 (2022-05-27)

[fix] quote identifiers in table constraint declaration (#1397)

v8.1.1 (2022-05-18)

[fix] quote identifiers in table primary keys (#1394)

v8.1.0 (2022-04-06)

[new] MSSQL CLI tool now accepts some options to allow overriding config file ((#1381](tediousjs/node-mssql#1381)) [fix] nodemsqlv8 driver tests working against Node 10 (#1368)

v8.0.2 (2022-02-07)

Merge up missing fixes from v7.3.0 [new] Transaction/PreparedStatements expose the config from their parent connection (#1338) [fix] Fix inherited request configs from the pool. Specifically stream and arrayRowMode now inherit accurately from the connection config (#1338)

v8.0.1 (2022-01-30)

Re-release of v8.0.0

v8.0.0 (2022-01-30)

[new] Add table.rows.clear() method to allow for chunking updates (#1094) [new] Add valueHandler map to store callbacks that are used to process row values (#1356) [change] msnodesqlv8 driver detects os platform and attempts to pick correct connections string for it ((#1318)[https://github-redirect.dependabot.com/tediousjs/node-mssql/pull/1318]) [change] Updated to latest Tedious 14 ((#1312)[https://github-redirect.dependabot.com/tediousjs/node-mssql/pull/1312]) [change] Errors for bad bulk load parameters have slightly different error messages ((#1318)[https://github-redirect.dependabot.com/tediousjs/node-mssql/pull/1318]) [change] Options provided to the driver via the config.options object will not be overridden with other values if set explicitly ((#1340)[https://github-redirect.dependabot.com/tediousjs/node-mssql/pull/1340]) [change] Duplicate column names will now be presented as an array even if the values are empty ((#1240)[https://github-redirect.dependabot.com/tediousjs/node-mssql/pull/1240])

... (truncated)

Commits


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/txstate-etc/mssql-async/network/alerts).