[Snyk] Upgrade @nextcloud/auth from 2.4.0 to 2.5.2 #6
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade @nextcloud/auth from 2.4.0 to 2.5.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 3 versions ahead of your current version.
The recommended version was released 4 months ago.
Issues fixed by the recommended upgrade:
SNYK-JS-AXIOS-12613773
SNYK-JS-AXIOS-9292519
SNYK-JS-AXIOS-9403194
SNYK-JS-BABELRUNTIME-10044504
SNYK-JS-BRACEEXPANSION-9789073
SNYK-JS-BRACEEXPANSION-9789073
SNYK-JS-DOMPURIFY-8722251
SNYK-JS-FORMDATA-10841150
SNYK-JS-NODEGETTEXT-6100943
SNYK-JS-PBKDF2-10495496
SNYK-JS-PBKDF2-10495498
SNYK-JS-SHAJS-12089400
Release notes
Package name: @nextcloud/auth
-
2.5.2 - 2025-07-07
- fix(files_sharing): fallback self.crypto.randomUUID by @ skjnldsv in #822
- chore(deps-dev): Bump happy-dom from 17.4.6 to 17.4.7 in #805
- chore(deps-dev): Bump @ vitest/coverage-v8 from 3.1.3 to 3.1.4 in #808
- chore(deps-dev): Bump typedoc from 0.28.4 to 0.28.5 in #810
- chore: fix date in CHANGELOG.md by @ nickvergessen in #807
- chore(deps-dev): Bump happy-dom from 17.4.7 to 17.5.6 in #812
- chore(deps-dev): Bump happy-dom from 17.5.6 to 17.6.3 in #814
- chore(deps-dev): Bump @ vitest/coverage-v8 from 3.1.4 to 3.2.2 in #815
- chore(deps-dev): Bump @ vitest/coverage-v8 from 3.2.2 to 3.2.3 in #816
- chore(deps-dev): Bump eslint from 8.57.1 to 9.29.0 in #817
- chore(deps-dev): Bump happy-dom from 17.6.3 to 18.0.1 in #819
- chore(deps-dev): Bump @ vitest/coverage-v8 from 3.2.3 to 3.2.4 in #820
- chore: update supported node versions by @ susnux in #823
-
2.5.1 - 2025-05-13
- fix: listen to guest changes by @ skjnldsv in #803
-
2.5.0 - 2025-05-12
- feat: add guest user by @ skjnldsv in #795
- fix: returns
- chore: Update workflows by @ susnux in #678
- chore(deps-dev): Bump @ nextcloud/eslint-config from 8.4.1 to 8.4.2 by @ dependabot
- chore(deps-dev): Bump @ nextcloud/vite-config from 2.2.2 to 2.3.5 by @ dependabot
- chore(deps-dev): Bump @ vitest/coverage-v8 from 2.0.5 to 2.1.8 by @ dependabot
- chore(deps-dev): Bump elliptic from 6.5.5 to 6.6.0 by @ dependabot
- chore(deps-dev): Bump eslint from 8.57.0 to 8.57.1 by @ dependabot
- chore(deps-dev): Bump happy-dom from 14.12.3 to 17.4.4 by @ dependabot
- chore(deps-dev): Bump typedoc from 0.26.10 to 0.28.4 by @ dependabot
- chore(deps-dev): Bump typescript from 5.5.4 to 5.8.3 by @ dependabot
- chore(deps-dev): Bump vite from 5.4.0 to 5.4.10 by @ dependabot
- chore(deps): Bump @ nextcloud/event-bus from 3.3.1 to 3.3.2 by @ dependabot
- chore(deps): Bump rollup from 4.21.0 to 4.22.4 by @ dependabot
-
2.4.0 - 2024-08-13
- chore(deps-dev): Bump @ nextcloud/vite-config from 1.2.2 to 1.2.3 by @ dependabot in #634
- chore(deps-dev): Bump @ vitest/coverage-v8 from 1.5.0 to 1.5.2 by @ dependabot in #635
- chore(deps-dev): Bump vite from 5.2.10 to 5.2.11 by @ dependabot in #636
- chore(deps-dev): Bump @ vitest/coverage-v8 from 1.5.2 to 1.6.0 by @ dependabot in #637
- chore(deps-dev): Bump happy-dom from 14.7.1 to 14.10.1 by @ dependabot in #638
- chore(deps-dev): Bump happy-dom from 14.10.1 to 14.11.0 by @ dependabot in #639
- chore(deps): Bump @ nextcloud/event-bus from 3.2.0 to 3.3.0 by @ dependabot in #641
- chore(deps-dev): Bump @ nextcloud/eslint-config from 8.3.0 to 8.4.1 by @ dependabot in #642
- chore(deps): Bump @ nextcloud/event-bus from 3.3.0 to 3.3.1 by @ dependabot in #644
- chore(deps-dev): Bump vite from 5.2.11 to 5.2.12 by @ dependabot in #645
- chore(deps-dev): Bump happy-dom from 14.11.0 to 14.12.0 by @ dependabot in #646
- chore(deps-dev): Bump vite from 5.2.12 to 5.2.13 by @ dependabot in #647
- chore(deps-dev): Bump vite from 5.2.13 to 5.3.1 by @ dependabot in #649
- chore(deps-dev): Bump braces from 3.0.2 to 3.0.3 by @ dependabot in #650
- chore(deps-dev): Bump ws from 8.13.0 to 8.17.1 by @ dependabot in #651
- chore(deps-dev): Bump typedoc from 0.25.13 to 0.26.0 by @ dependabot in #652
- chore(deps-dev): Bump typescript from 5.4.5 to 5.5.2 by @ dependabot in #655
- chore(deps-dev): Bump happy-dom from 14.12.0 to 14.12.3 by @ dependabot in #654
- chore(deps-dev): Bump typedoc from 0.26.0 to 0.26.3 by @ dependabot in #656
- chore(deps-dev): Bump @ nextcloud/typings from 1.8.0 to 1.9.0 by @ dependabot in #658
- chore(deps-dev): Bump vite from 5.3.1 to 5.3.2 by @ dependabot in #657
- chore(deps-dev): Bump vite from 5.3.2 to 5.3.3 by @ dependabot in #660
- chore(deps-dev): Bump @ nextcloud/typings from 1.9.0 to 1.9.1 by @ dependabot in #661
- chore(deps-dev): Bump typescript from 5.5.2 to 5.5.3 by @ dependabot in #659
- chore(deps-dev): Bump typedoc from 0.26.3 to 0.26.4 by @ dependabot in #663
- chore(deps-dev): Bump vitest and @ vitest/coverage-v8 by @ dependabot in #662
- Add SPDX header by @ AndyScherzinger in #664
- docs: Fix link to online docs by @ ChristophWurst in #643
- chore(deps-dev): Bump @ vitest/coverage-v8 from 2.0.2 to 2.0.3 by @ dependabot in #665
- chore(deps-dev): Bump @ nextcloud/vite-config from 1.2.3 to 2.1.0 by @ dependabot in #653
- feat: add guest nickname handling by @ skjnldsv in #666
- chore(deps-dev): Bump vite from 5.3.3 to 5.3.4 by @ dependabot in #667
- chore(deps-dev): Bump @ vitest/coverage-v8 from 2.0.3 to 2.0.4 by @ dependabot in #668
- chore(deps-dev): Bump typedoc from 0.26.4 to 0.26.5 by @ dependabot in #670
- chore(deps-dev): Bump typescript from 5.5.3 to 5.5.4 by @ dependabot in #669
- chore(deps-dev): Bump vite from 5.3.4 to 5.3.5 by @ dependabot in #671
- test: Add missing tests for request token by @ susnux in #672
- chore(deps-dev): Bump @ vitest/coverage-v8 from 2.0.4 to 2.0.5 by @ dependabot in #674
- chore(deps-dev): Bump vite from 5.3.5 to 5.4.0 by @ dependabot in #675
- chore(deps-dev): Bump @ nextcloud/vite-config from 2.1.0 to 2.2.2 by @ dependabot in #676
- feat: Add CSP nonce handling by @ susnux in #673
- chore: Prepare v2.4.0 by @ susnux in #677
- @ AndyScherzinger made their first contribution in #664
from @nextcloud/auth GitHub release notes2.5.2 - 2025-07-07
Fixed
Changed
2.5.1 - 2025-08-123
Fixed
2.5.0 - 2025-05-12
Added
Fixed
NextcloudUserinstead ofGuestUserby @ skjnldsv in #799Changed
Full Changelog: v2.4.0...v2.5.0
What's Changed
New Contributors
Full Changelog: v2.3.0...v2.4.0
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: