Skip to content
This repository has been archived by the owner on Apr 25, 2023. It is now read-only.

build(deps): bump openid-client from 4.9.0 to 5.4.0 #238

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Feb 22, 2023

Bumps openid-client from 4.9.0 to 5.4.0.

Release notes

Sourced from openid-client's releases.

v5.4.0

Features

  • allow third party initiated login requests to trigger strategy (568709a), closes #510 #564

v5.3.4

Refactor

Fixes

  • regression introduced in v5.3.3 (4f6e847)

v5.3.2

Fixes

  • passport: ignore static state and nonce passed to Strategy() (#556) (43daff3)

v5.3.1

Fixes

  • typescript: requestResource returns a Promise (#546) (8bc9519), closes #488

v5.3.0

Features

  • JARM is now a stable feature (10e3a37)

v5.2.1

Fixes

  • typescript: add client_id and logout_hint to EndSessionParameters (b7b5438)

v5.2.0

Features

  • add client_id to endSessionUrl query strings (6fd9350)

Fixes

  • allow endSessionUrl defaults to be overriden (7cc2402)

v5.1.10

Refactor

  • engines: remove package.json engines restriction (9aefba3)

v5.1.9

... (truncated)

Changelog

Sourced from openid-client's changelog.

5.4.0 (2023-02-05)

Features

  • allow third party initiated login requests to trigger strategy (568709a), closes #510 #564

5.3.4 (2023-02-02)

Fixes

  • regression introduced in v5.3.3 (4f6e847)

5.3.3 (2023-02-02)

Refactor

5.3.2 (2023-01-20)

Fixes

  • passport: ignore static state and nonce passed to Strategy() (#556) (43daff3)

5.3.1 (2022-11-28)

Fixes

  • typescript: requestResource returns a Promise (#546) (8bc9519), closes #488

5.3.0 (2022-11-09)

Features

  • JARM is now a stable feature (10e3a37)

5.2.1 (2022-10-20)

Fixes

  • typescript: add client_id and logout_hint to EndSessionParameters (b7b5438)

5.2.0 (2022-10-19)

... (truncated)

Commits
  • a6f3f0a chore(release): 5.4.0
  • 568709a feat: allow third party initiated login requests to trigger strategy
  • 363c215 chore(release): 5.3.4
  • 4f6e847 fix: regression introduced in v5.3.3
  • 5dbe8bc chore(release): 5.3.3
  • f1881bc refactor: remove use of Node.js v8 builtin
  • 7bd3e8d docs: link out to oauth4webapi
  • f73caad ci: update lock.yml
  • 7ffb0c1 chore(release): 5.3.2
  • 93f788d chore: fixup 43daff3
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [openid-client](https://github.com/panva/node-openid-client) from 4.9.0 to 5.4.0.
- [Release notes](https://github.com/panva/node-openid-client/releases)
- [Changelog](https://github.com/panva/node-openid-client/blob/main/CHANGELOG.md)
- [Commits](panva/openid-client@v4.9.0...v5.4.0)

---
updated-dependencies:
- dependency-name: openid-client
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Feb 22, 2023
@ImagineBuildBot
Copy link

Scan submitted to Checkmarx

@ImagineBuildBot
Copy link

Logo
Checkmarx SAST - Scan Summary & Details

Cx-SAST Summary

Total of 70 vulnerabilities
High 33 High
Medium 37 Medium
Low 0 Low
Info 0 Info

Checkmarx Scan Summary

Severity Count
High 33
Medium 37
Low 0
Informational 0

Violation Summary

High 28 High
Medium 21 Medium

View more details on Checkmarx UI

Cx-SAST Details

Lines Severity Category File Link
81 Medium Unchecked_Input_For_Loop_Condition plugins/catalog-graph/src/components/CatalogGraphPage/useCatalogGraphPage.ts Checkmarx
172 Medium Privacy_Violation plugins/scaffolder-backend/src/service/router.ts Checkmarx
73 Medium Privacy_Violation plugins/todo-backend/src/service/router.ts Checkmarx
89 Medium Missing_HSTS_Header contrib/catalog/ImmediateEntityProvider.ts Checkmarx
198 219 Medium Client_ReDoS_From_Regex_Injection plugins/catalog-backend-module-bitbucket/src/BitbucketDiscoveryProcessor.test.ts Checkmarx
104 Medium Client_ReDoS_From_Regex_Injection plugins/catalog-backend-module-github/src/GithubDiscoveryProcessor.ts Checkmarx
102 121 126 129 130 151 161 Medium Client_ReDoS_From_Regex_Injection plugins/catalog-backend-module-bitbucket/src/BitbucketDiscoveryProcessor.ts Checkmarx
91 116 Medium Client_ReDoS_From_Regex_Injection plugins/catalog-backend-module-github/src/GithubDiscoveryProcessor.test.ts Checkmarx
221 Medium Client_Privacy_Violation packages/backend-common/src/scm/git.ts Checkmarx
168 Medium Client_Privacy_Violation packages/integration/src/bitbucket/core.ts Checkmarx
90 Medium Client_Privacy_Violation plugins/auth-backend/src/providers/microsoft/provider.ts Checkmarx
155 Medium Client_Privacy_Violation plugins/scaffolder-backend/src/scaffolder/actions/builtin/publish/bitbucket.ts Checkmarx
149 Medium Client_HTML5_Store_Sensitive_data_In_Web_Storage packages/core-app-api/src/lib/AuthSessionManager/AuthSessionStore.ts Checkmarx
77 100 High Stored_XSS plugins/code-coverage-backend/src/service/CodeCoverageDatabase.ts Checkmarx
44 High Reflected_XSS plugins/bazaar-backend/src/service/router.ts Checkmarx
108 High Reflected_XSS plugins/search-backend/src/service/router.ts Checkmarx
48 86 High Reflected_XSS plugins/badges-backend/src/service/router.ts Checkmarx
50 High Reflected_XSS plugins/periskop-backend/src/service/router.ts Checkmarx
46 83 High Reflected_XSS plugins/jenkins-backend/src/service/router.ts Checkmarx
242 High Reflected_XSS plugins/techdocs-node/src/stages/publish/openStackSwift.ts Checkmarx
372 High Reflected_XSS plugins/techdocs-node/src/stages/publish/awsS3.ts Checkmarx
53 59 65 66 72 73 79 80 High Reflected_XSS plugins/rollbar-backend/src/service/router.ts Checkmarx
40 High Reflected_XSS plugins/app-backend/src/lib/assets/createStaticAssetMiddleware.ts Checkmarx
335 High Reflected_XSS plugins/techdocs-node/src/stages/publish/azureBlobStorage.ts Checkmarx
126 129 130 High Prototype_Pollution plugins/catalog-backend-module-bitbucket/src/BitbucketDiscoveryProcessor.ts Checkmarx
36 High Insecure_Storage_of_Sensitive_Data plugins/auth-backend/src/service/standaloneServer.ts Checkmarx
62 High Client_DOM_XSS plugins/git-release-manager/src/hooks/useQueryHandler.ts Checkmarx
64 High Client_DOM_XSS plugins/gcp-projects/src/components/ProjectDetailsPage/ProjectDetailsPage.tsx Checkmarx
30 High Client_DOM_XSS plugins/catalog-backend/src/util/conversion.ts Checkmarx

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant