azure-devops-npm-auth
azure-devops-npm-auth copied to clipboard
Bump cacheable-request and openid-client
Removes cacheable-request. It's no longer used after updating ancestor dependency openid-client. These dependencies need to be updated together.
Removes cacheable-request
Updates openid-client from 3.15.10 to 5.4.0
Release notes
Sourced from openid-client's releases.
v5.4.0
Features
v5.3.4
Refactor
Fixes
- regression introduced in v5.3.3 (4f6e847)
v5.3.2
Fixes
v5.3.1
Fixes
v5.3.0
Features
- JARM is now a stable feature (10e3a37)
v5.2.1
Fixes
- typescript: add client_id and logout_hint to EndSessionParameters (b7b5438)
v5.2.0
Features
- add client_id to endSessionUrl query strings (6fd9350)
Fixes
- allow endSessionUrl defaults to be overriden (7cc2402)
v5.1.10
Refactor
- engines: remove package.json engines restriction (9aefba3)
v5.1.9
... (truncated)
Changelog
Sourced from openid-client's changelog.
5.4.0 (2023-02-05)
Features
5.3.4 (2023-02-02)
Fixes
- regression introduced in v5.3.3 (4f6e847)
5.3.3 (2023-02-02)
Refactor
5.3.2 (2023-01-20)
Fixes
5.3.1 (2022-11-28)
Fixes
5.3.0 (2022-11-09)
Features
- JARM is now a stable feature (10e3a37)
5.2.1 (2022-10-20)
Fixes
- typescript: add client_id and logout_hint to EndSessionParameters (b7b5438)
5.2.0 (2022-10-19)
... (truncated)
Commits
a6f3f0achore(release): 5.4.0568709afeat: allow third party initiated login requests to trigger strategy363c215chore(release): 5.3.44f6e847fix: regression introduced in v5.3.35dbe8bcchore(release): 5.3.3f1881bcrefactor: remove use of Node.js v8 builtin7bd3e8ddocs: link out to oauth4webapif73caadci: update lock.yml7ffb0c1chore(release): 5.3.293f788dchore: fixup 43daff3- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.
This would be great to get merged as it would resolve an npm audit issue:
# npm audit report
got <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97
No fix available
node_modules/got
openid-client <=3.15.10
Depends on vulnerable versions of got
node_modules/openid-client
azure-devops-npm-auth *
Depends on vulnerable versions of openid-client
node_modules/azure-devops-npm-auth