wambugucoder / MERN-STACK-APP-FCC-CHALLENGE

A Polling App integrated with a chatbot to help people understand how the App works
1 stars 1 forks source link

[Snyk] Upgrade passport-jwt from 4.0.0 to 4.0.1 #619

Open wambugucoder opened 9 months ago

wambugucoder commented 9 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade passport-jwt from 4.0.0 to 4.0.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **1 version** ahead of your current version. - The recommended version was released **a year ago**, on 2022-12-24.
Release notes
Package name: passport-jwt
  • 4.0.1 - 2022-12-24
    • Updates jsonwebtoken dependency to ^9.0.0 to address high severity
      vulnerability CVE-2022-3517
    • Updates a number of other dependencies
    • Fixes a number of typos

    [Developer facing]

    • Updates CI to use github actions
  • 4.0.0 - 2018-03-13

    Fixes #147 - Vulnerability due to dependency on jsonwebtoken 7.x.x

      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/mikenicholson/passport-jwt/releases">passport-jwt GitHub release notes</a>

Commit messages
Package name: passport-jwt
  • fed94fa 4.0.1 release
  • cfb5566 Merge pull request #248 from mikenicholson/update-minmatch
  • 8e4ad5b Address minmatch vulnerability
  • e9cf2ce Merge pull request #247 from mikenicholson/jsonwebtoken-9
  • bfbc6cc Update jsonwebtoken to 9.0.0
  • a49b43e Update minimist due to prototype pollution vulnerability in previous version
  • a5137c6 Merge pull request #192 from markhoney/patch-1
  • ea824cd Update jsonwebtoken and run npm audit fix
  • 8e57eec Remove older node versions shiping npm without support for "ci"
  • 3ab9305 Add CI workflow in GitHub Actions
  • 96a6e55 Merge pull request #218 from Sambego/patch-1
  • 809cdbf Update Auth0 sponsorship link
  • ec35fa4 Add nodejs 13 & 14 to CI
  • 2cab4dd Update mocha to resolve vulnerabilities
  • b196eb8 Use nyc for coverage
  • ddafcd2 Fix typo
  • 6b92631 Merge pull request #176 from epicfaace/patch-1
  • 154af70 Stop building for Node v5 and earlier
  • d311551 Add newer node versions to Travis CI build
  • 0e39a48 Update dependencies to resolve vulnerabilities.
  • d488147 Update URLs to reference new GitHub username
  • 89152d5 Rename extrators-test.js to extractors-test.js
  • 0bb68bf Clarify use of custom extractor function.
  • 499bd4a Add js formatting to extractor example in README.
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs