Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 16, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
passport (source) ^0.5.3 -> ^0.6.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-25896

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.


Release Notes

jaredhanson/passport (passport)

v0.6.0

Compare Source

Added
  • authenticate(), req#login, and req#logout accept a
    keepSessionInfo: true option to keep session information after regenerating
    the session.
Changed
  • req#login() and req#logout() regenerate the the session and clear session
    information by default.
  • req#logout() is now an asynchronous function and requires a callback
    function as the last argument.
Security
  • Improved robustness against session fixation attacks in cases where there is
    physical access to the same system or the application is susceptible to
    cross-site scripting (XSS).

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added dependencies Pull requests that update a dependency file SECURITY labels Sep 16, 2025
@renovate renovate bot requested a review from raymondfeng as a code owner September 16, 2025 19:53
@renovate renovate bot added SECURITY dependencies Pull requests that update a dependency file labels Sep 16, 2025
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Sep 16, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from 78d1d87 to c3a9448 Compare September 16, 2025 23:45
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Sep 17, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from c3a9448 to 0f18266 Compare September 17, 2025 00:45
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from 0f18266 to 32776e0 Compare September 24, 2025 15:02
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Sep 24, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch 3 times, most recently from 2d925d6 to 1c17f8b Compare September 24, 2025 20:31
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Sep 24, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from 1c17f8b to e1d9b0d Compare September 25, 2025 00:40
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from e1d9b0d to f41fe94 Compare September 25, 2025 05:02
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from f41fe94 to 03ef9db Compare September 25, 2025 13:09
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch 2 times, most recently from 6d35198 to 6644903 Compare September 25, 2025 20:03
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from 6644903 to 0c2389a Compare September 25, 2025 21:57
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Sep 26, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch 3 times, most recently from 67b2230 to e007c86 Compare September 26, 2025 16:30
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Sep 26, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from c101005 to fed86d1 Compare November 27, 2025 18:24
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Nov 27, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from fed86d1 to 8c71507 Compare November 27, 2025 18:31
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Nov 27, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from 8c71507 to a5eb434 Compare November 29, 2025 04:01
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Nov 29, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch 2 times, most recently from d073c52 to f25f688 Compare November 29, 2025 05:35
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Nov 29, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from f25f688 to c2ee0c5 Compare November 29, 2025 22:48
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Nov 29, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from c2ee0c5 to e754134 Compare November 29, 2025 22:55
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Nov 29, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from e754134 to 1873db5 Compare November 30, 2025 02:44
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Nov 30, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch 2 times, most recently from 150c7f8 to e94a47b Compare November 30, 2025 03:39
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Nov 30, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch 2 times, most recently from f2d5efc to 8ffda25 Compare November 30, 2025 23:29
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Nov 30, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch 3 times, most recently from 873e83a to aa3c6dd Compare December 1, 2025 01:58
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Dec 1, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from aa3c6dd to fbe8d55 Compare December 1, 2025 14:21
@renovate renovate bot changed the title chore: update dependency passport to ^0.6.0 [security] chore: update dependency passport to ^0.7.0 [security] Dec 1, 2025
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot changed the title chore: update dependency passport to ^0.7.0 [security] chore: update dependency passport to ^0.6.0 [security] Dec 1, 2025
@renovate renovate bot force-pushed the renovate/npm-passport-vulnerability branch from fbe8d55 to ed51e50 Compare December 1, 2025 14:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file SECURITY

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant