fix(deps): update dependency jsonwebtoken to v9#360
Closed
renovate[bot] wants to merge 1 commit intomasterfrom
Closed
fix(deps): update dependency jsonwebtoken to v9#360renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
4be89fa to
fe8bd8b
Compare
02ba875 to
4939fbc
Compare
885311b to
8412c80
Compare
0ef72c2 to
3f15cdd
Compare
2ac5dce to
4d230df
Compare
d295ead to
7d9bda6
Compare
7d9bda6 to
76aa179
Compare
c4576de to
54d24ea
Compare
54d24ea to
87da366
Compare
87da366 to
933e002
Compare
d57e814 to
4b01ee4
Compare
4b01ee4 to
d554e0d
Compare
|
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
Contributor
Author
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^8.5.1->^9.0.08.5.9->9.0.5Release Notes
auth0/node-jsonwebtoken (jsonwebtoken)
v9.0.2Compare Source
v9.0.1Compare Source
v9.0.0Compare Source
Breaking changes: See Migration from v8 to v9
Breaking changes
8345030]auth0/node-jsonwebtoken@8345030)ecdf6cc]auth0/node-jsonwebtoken@ecdf6cc)Security fixes
Arbitrary File Write via verify function- CVE-2022-23529Insecure default algorithm in jwt.verify() could lead to signature validation bypass- CVE-2022-23540Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC- CVE-2022-23541Unrestricted key type could lead to legacy keys usage- CVE-2022-23539Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate. View repository job log here.