Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump jsonwebtoken and firebase-tools in /react/acm-chapter-website #236

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 6, 2023

Bumps jsonwebtoken to 9.0.2 and updates ancestor dependency firebase-tools. These dependencies need to be updated together.

Updates jsonwebtoken from 8.5.1 to 9.0.2

Changelog

Sourced from jsonwebtoken's changelog.

9.0.2 - 2023-08-30

  • security: updating semver to 7.5.4 to resolve CVE-2022-25883, closes #921.
  • refactor: reduce library size by using lodash specific dependencies, closes #878.

9.0.1 - 2023-07-05

  • fix(stubs): allow decode method to be stubbed

9.0.0 - 2022-12-21

Breaking changes: See Migration from v8 to v9

Breaking changes

  • Removed support for Node versions 11 and below.
  • The verify() function no longer accepts unsigned tokens by default. ([834503079514b72264fd13023a3b8d648afd6a16]auth0/node-jsonwebtoken@8345030)
  • RSA key size must be 2048 bits or greater. ([ecdf6cc6073ea13a7e71df5fad043550f08d0fa6]auth0/node-jsonwebtoken@ecdf6cc)
  • Key types must be valid for the signing / verification algorithm

Security fixes

  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
Commits
Maintainer changes

This version was pushed to npm by charlesrea, a new releaser for jsonwebtoken since your current version.


Updates firebase-tools from 9.23.3 to 12.9.1

Release notes

Sourced from firebase-tools's releases.

v12.9.1

  • Fixes issue where initializing Hosting fails when selecting a project. (#6527)

v12.9.0

  • Revert enabling preferRest by default to avoid performance degradations for some users (#6520).
  • Fix blocking functions in the emulator when using multiple codebases (#6504).
  • Add force flag call-out for bypassing prompts (#6506).
  • Fixed an issue where the functions emulator did not respect the --log-verbosity flag (#2859).
  • Add the ability to look for the default Hosting site via Hosting's API.
  • Add logic to create a Hosting site when one is not available in a project.
  • Add checks for the default Hosting site when one is assumed to exist.

v12.8.1

  • Fixed 2 bugs (unintended database mode changes and disabling of PITR or delete-protection) when updating Firestore databases (#6478)

v12.8.0

  • Enable preferRest option by default for Firestore functions. (#6147)
  • Fixed a bug where re-deploying 2nd Gen Firestore function failed after updating secrets. (#6456)
  • Fixed a bug where similarly-named Hosting channels would cause issues when updating authorized domains. (#6356)

v12.7.0

  • Fix type mismatch for parametrized function region. (#6205)
  • Ignore FIRESTORE_EMULATOR_HOST environment variable on functions deploy. (#6442)
  • Added support for enabling, disabling, and displaying Point In Time Recovery enablement state on Firestore databases (#6388)
  • Added a --verbosity flag to emulators:* commands that limits what logs are printed (#2859)
  • Fixed an issue where params would not be resolved when used to set VPC connector during functions deployment (#6327)

v12.6.2

  • Fixed an issue with deploying multilevel grouped functions containing v2 functions. (#6419)
  • Fixed an issue where functions deployment required a new permission.

v12.6.1

  • Fixed an issue where the functions service account option was not treated as a param (#6389).
  • Fixed an issue with deploying function groups containing v2 functions. (#6408)
  • Use GetDefaultBucket endpoint to fetch Storage Default Bucket.

v12.6.0

  • Improve performance and reliability when deploying multiple 2nd gen functions using single builds. (#6376)
  • Fixed an issue where emulators:export did not check if the target folder is empty. (#6313)
  • Fixed an issue where retry could not be set for event triggered functions. (#6391)
  • Fixed "Could not find the next executable" on Next.js deployments (#6372)
  • Fixed issues caused by breaking changes in Next >=v13.5.0. (#6382)

v12.5.4

  • Released Firestore emulator v1.18.2.
    • Removed nano precision in timestamp used in Firestore emulator (#5893)
    • Fixed a bug where query behaves differently from production.
  • Fixed an issue where very long command outputs would be cut off. (#3286)

v12.5.3

... (truncated)

Commits
  • e400a63 12.9.1
  • 6e52869 fix issues where project ID was missing in Hosting setup (#6528)
  • 3b345d5 [firebase-release] Removed change log and reset repo after 12.9.0 release
  • 05ab89e 12.9.0
  • 11d6946 Revert "Enable preferRest option by default for Firestore functions" (#6520)
  • 61523b9 adds a check for a hosting site to exist in hosting init (#6493)
  • aeb2901 Ensure functionsEmulator respects logVerbosity (#6521)
  • ea58114 Add force flag call-out for bypassing prompts (#6506)
  • 55d3584 Fix blocking functions in the emulator when using multiple codebases (#6504)
  • 5bca9b5 Svn main 001 rem (#6492)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) to 9.0.2 and updates ancestor dependency [firebase-tools](https://github.com/firebase/firebase-tools). These dependencies need to be updated together.


Updates `jsonwebtoken` from 8.5.1 to 9.0.2
- [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](auth0/node-jsonwebtoken@v8.5.1...v9.0.2)

Updates `firebase-tools` from 9.23.3 to 12.9.1
- [Release notes](https://github.com/firebase/firebase-tools/releases)
- [Changelog](https://github.com/firebase/firebase-tools/blob/master/CHANGELOG.md)
- [Commits](firebase/firebase-tools@v9.23.3...v12.9.1)

---
updated-dependencies:
- dependency-name: jsonwebtoken
  dependency-type: indirect
- dependency-name: firebase-tools
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Dec 6, 2023
@No767 No767 closed this Dec 19, 2023
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 19, 2023

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/react/acm-chapter-website/jsonwebtoken-and-firebase-tools-9.0.2 branch December 19, 2023 07:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant