chore(deps): bump the npm_and_yarn group across 2 directories with 8 updates#6
Open
dependabot[bot] wants to merge 1 commit intomasterfrom
Open
chore(deps): bump the npm_and_yarn group across 2 directories with 8 updates#6dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
…updates Bumps the npm_and_yarn group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [semver](https://github.com/npm/node-semver) | `7.3.8` | `7.5.2` | | [tar](https://github.com/isaacs/node-tar) | `6.1.11` | `6.2.1` | | [@koa/cors](https://github.com/koajs/cors) | `4.0.0` | `5.0.0` | | [jose](https://github.com/panva/jose) | `4.11.0` | `4.15.5` | | [@azure/msal-node](https://github.com/AzureAD/microsoft-authentication-library-for-js) | `1.12.0` | `2.9.2` | | [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `4.2.5` | `4.2.6` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `6.9.1` | `6.9.9` | Bumps the npm_and_yarn group with 2 updates in the /packages/core directory: [@koa/cors](https://github.com/koajs/cors) and [jose](https://github.com/panva/jose). Updates `semver` from 7.3.8 to 7.5.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md) - [Commits](npm/node-semver@v7.3.8...v7.5.2) Updates `tar` from 6.1.11 to 6.2.1 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v6.1.11...v6.2.1) Updates `@koa/cors` from 4.0.0 to 5.0.0 - [Changelog](https://github.com/koajs/cors/blob/master/History.md) - [Commits](koajs/cors@4.0.0...5.0.0) Updates `jose` from 4.11.0 to 4.15.5 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/v4.15.5/CHANGELOG.md) - [Commits](panva/jose@v4.11.0...v4.15.5) Updates `@azure/msal-node` from 1.12.0 to 2.9.2 - [Release notes](https://github.com/AzureAD/microsoft-authentication-library-for-js/releases) - [Commits](AzureAD/microsoft-authentication-library-for-js@msal-node-v1.12.0...msal-node-v2.9.2) Updates `fast-xml-parser` from 4.2.5 to 4.2.6 - [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases) - [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md) - [Commits](NaturalIntelligence/fast-xml-parser@v4.2.5...v4.2.6) Updates `nodemailer` from 6.9.1 to 6.9.9 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v6.9.1...v6.9.9) Updates `jsonwebtoken` from 8.5.1 to 9.0.2 - [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md) - [Commits](auth0/node-jsonwebtoken@v8.5.1...v9.0.2) Updates `@koa/cors` from 4.0.0 to 5.0.0 - [Changelog](https://github.com/koajs/cors/blob/master/History.md) - [Commits](koajs/cors@4.0.0...5.0.0) Updates `jose` from 4.15.5 to 5.4.0 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/v4.15.5/CHANGELOG.md) - [Commits](panva/jose@v4.11.0...v4.15.5) --- updated-dependencies: - dependency-name: semver dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tar dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@koa/cors" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: jose dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: "@azure/msal-node" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: fast-xml-parser dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: nodemailer dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: jsonwebtoken dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: "@koa/cors" dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: jose dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
COMPARE TO
|
| Name | Diff |
|---|---|
| packages/cli/package.json | 📉 -1 Bytes |
| packages/connectors/connector-apple/package.json | 📉 -1 Bytes |
| packages/connectors/connector-azuread/package.json | 📉 -1 Bytes |
| packages/connectors/connector-oidc/package.json | 📉 -1 Bytes |
| packages/connectors/connector-saml/package.json | 0 Bytes |
| packages/connectors/connector-smtp/package.json | 0 Bytes |
| packages/core/package.json | 📉 -1 Bytes |
| pnpm-lock.yaml | 📉 -174 Bytes |
|
This PR is stale because it has been open 10 for days with no activity. Remove stale label or comment or this will be closed in 5 days. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 7 updates in the / directory:
7.3.87.5.26.1.116.2.14.0.05.0.04.11.04.15.51.12.02.9.24.2.54.2.66.9.16.9.9Bumps the npm_and_yarn group with 2 updates in the /packages/core directory: @koa/cors and jose.
Updates
semverfrom 7.3.8 to 7.5.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
e7b78dechore: release 7.5.258c791ffix: diff when detecting major change from prerelease (#566)5c8efbcfix: preserve build in raw after inc (#565)717534efix: better handling of whitespace (#564)2f738e9chore: bump@npmcli/template-ossfrom 4.14.1 to 4.15.1 (#558)aa016a6chore: release 7.5.1d30d25afix: show type on invalid semver error (#559)09c69e2chore: bump@npmcli/template-ossfrom 4.13.0 to 4.14.1 (#555)5b02ad7chore: release 7.5.0e219bb4fix: throw on bad version with correct error message (#552)Maintainer changes
This version was pushed to npm by npm-cli-ops, a new releaser for semver since your current version.
Updates
tarfrom 6.1.11 to 6.2.1Release notes
Sourced from tar's releases.
Changelog
Sourced from tar's changelog.
... (truncated)
Commits
bef7b1e6.2.1fe8cd57prevent extraction in excessively deep subfoldersfe7ebfdremove security.md5bc9d406.2.0fe1ef5echangelog 6.2e483220get rid of npm lint stuff689928aci that works outside of npm orgdb6f539file inference improvements for .tbr and .tgz336fa8frefactor: dry and other pr commentseeba222chore: lint fixesUpdates
@koa/corsfrom 4.0.0 to 5.0.0Changelog
Sourced from
@koa/cors's changelog.Commits
c33bd69Release 5.0.0f31dac9Merge pull request from GHSA-qxrj-hx23-xp82Updates
josefrom 4.11.0 to 4.15.5Release notes
Sourced from jose's releases.
... (truncated)
Changelog
Sourced from jose's changelog.
... (truncated)
Commits
765aafdchore(release): 4.15.5b36e45etest: add export check to x509 pem import testse839ecbtest: stop testing JWE RSA1_5 Algorithm1b91d88fix: add a maxOutputLength option to zlib inflate9ca2b24build: remove release actionf3035d8chore: cleanup after releasef0bb220chore(release): 4.15.46f38554chore: bump dev deps936c9dffix(types): export GetKeyFunction (#592)5ac6619chore: bump dev depsUpdates
@azure/msal-nodefrom 1.12.0 to 2.9.2Release notes
Sourced from
@azure/msal-node's releases.... (truncated)
Commits
1b0fc20Bump package versions5685c8cUpdate lab request scope (#7155)25aefeaSupport pop as optional for full framed apps (#7119)7563498Update package-lock (#7152)3893cceUpdate gatsby and angular samples (#7150)3ee9c68Implementation Based on Feature Request (#7151)cc18b42Remove outdated TS Sample (#7149)46f6e8aBump package versions8e4b664Fix MSAL Angular MsalInterceptor bug matching to query string (#7137)69e58c3Update regional-authorities.md (#7078)Maintainer changes
This version was pushed to npm by azuread, a new releaser for
@azure/msal-nodesince your current version.Updates
fast-xml-parserfrom 4.2.5 to 4.2.6Changelog
Sourced from fast-xml-parser's changelog.
... (truncated)
Commits
edb30ddupdate package2f2f787Remove trailing slash from jPath for self-closing tags (#595)Updates
nodemailerfrom 6.9.1 to 6.9.9Release notes
Sourced from nodemailer's releases.
Changelog
Sourced from nodemailer's changelog.
... (truncated)
Commits
5a2e10fchore(master): release 6.9.9 [skip-ci] (#1606)dd8f5e8fix(security): Fix issues described in GHSA-9h6g-pr28-7cqp. Do not use eterna...2c2b46achore: do not use caret in version specifierbe45c1bfix(tests): Use native node test runner, added code coverage support, removed...4233f6fchore(master): release 6.9.8 [skip-ci] (#1605)09d502fchore: removed double fileb4d0e0cfix(punycode): do not use native punycode module8376c02Test new github notice syntax for READMEbc46a3bUpdated stale github action78bdaf8chore: remove redundant AWS SDK for JavaScript v2 (#1593)Updates
jsonwebtokenfrom 8.5.1 to 9.0.2Changelog
Sourced from jsonwebtoken's changelog.
Commits
bc28861Release 9.0.2 (#935)96b8906refactor: use specific lodash packages (#933)ed35062security: Updating semver to 7.5.4 to resolve CVE-2022-25883 (#932)84539b2Updating package version to 9.0.1 (#920)a99fd4bfix(stubs): allow decode method to be stubbed (#876)e1fa9dcMerge pull request from GHSA-8cf7-32gw-wr335eaedbfchore(ci): remove github test actions job (#861)cd4163echore(ci): configure Github Actions jobs for Tests & Security Scanning (#856)ecdf6ccfix!: Prevent accidental use of insecure key sizes & misconfiguration of secr...8345030fix(sign&verify)!: Remove defaultnonesupport fromsignandverifymet...Maintainer changes
This version was pushed to npm by charlesrea, a new releaser for jsonwebtoken since your current version.
Updates
@koa/corsfrom 4.0.0 to 5.0.0Changelog
Sourced from
@koa/cors's changelog.Commits
c33bd69Release 5.0.0f31dac9Merge pull request from GHSA-qxrj-hx23-xp82Updates
josefrom 4.15.5 to 5.4.0Release notes
Sourced from jose's releases.
... (truncated)
Changelog
Sourced from jose's changelog.
... (truncated)
Commits
765aafdchore(release): 4.15.5b36e45etest: add export check to x509 pem import testse839ecbtest: stop testing JWE RSA1_5 Algorithm