Skip to content

fix(deps): update dependency jsonwebtoken to v9#360

Closed
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/jsonwebtoken-9.x
Closed

fix(deps): update dependency jsonwebtoken to v9#360
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/jsonwebtoken-9.x

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 21, 2022

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
jsonwebtoken ^8.5.1 -> ^9.0.0 age adoption passing confidence
@types/jsonwebtoken (source) 8.5.9 -> 9.0.5 age adoption passing confidence

Release Notes

auth0/node-jsonwebtoken (jsonwebtoken)

v9.0.2

Compare Source

  • security: updating semver to 7.5.4 to resolve CVE-2022-25883, closes #​921.
  • refactor: reduce library size by using lodash specific dependencies, closes #​878.

v9.0.1

Compare Source

  • fix(stubs): allow decode method to be stubbed

v9.0.0

Compare Source

Breaking changes: See Migration from v8 to v9

Breaking changes
Security fixes
  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 5 times, most recently from 4be89fa to fe8bd8b Compare December 29, 2022 19:50
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 5 times, most recently from 02ba875 to 4939fbc Compare January 3, 2023 14:15
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 7 times, most recently from 885311b to 8412c80 Compare January 12, 2023 20:56
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 8 times, most recently from 0ef72c2 to 3f15cdd Compare February 22, 2023 13:44
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 3 times, most recently from 2ac5dce to 4d230df Compare March 14, 2023 11:41
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 2 times, most recently from d295ead to 7d9bda6 Compare April 11, 2023 02:40
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch from 7d9bda6 to 76aa179 Compare April 27, 2023 13:14
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 2 times, most recently from c4576de to 54d24ea Compare May 13, 2023 03:47
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch from 54d24ea to 87da366 Compare September 16, 2023 02:03
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch from 87da366 to 933e002 Compare September 24, 2023 12:50
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch 4 times, most recently from d57e814 to 4b01ee4 Compare October 18, 2023 14:38
@renovate renovate bot force-pushed the renovate/jsonwebtoken-9.x branch from 4b01ee4 to d554e0d Compare November 7, 2023 10:33
@stale
Copy link

stale bot commented Feb 2, 2024

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the wontfix This will not be worked on label Feb 2, 2024
@stale stale bot closed this Feb 9, 2024
@renovate
Copy link
Contributor Author

renovate bot commented Feb 9, 2024

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 9.x releases. But if you manually upgrade to 9.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/jsonwebtoken-9.x branch February 9, 2024 04:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

wontfix This will not be worked on

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants