adbkit
adbkit copied to clipboard
Bump node-forge from 0.7.6 to 0.10.0
Bumps node-forge from 0.7.6 to 0.10.0.
Changelog
Sourced from node-forge's changelog.
0.10.0 - 2020-09-01
Changed
- BREAKING: Node.js 4 no longer supported. The code may still work, and non-invasive patches to keep it working will be considered. However, more modern tools no longer support old Node.js versions making testing difficult.
Removed
- BREAKING: Remove
util.getPath
,util.setPath
, andutil.deletePath
.util.setPath
had a potential prototype pollution security issue when used with unsafe inputs. These functions are not used byforge
itself. They date from an early time whenforge
was targeted at providing general helper functions. The library direction changed to be more focused on cryptography. Many other excellent libraries are more suitable for general utilities. If you need a replacement for these functions, consierget
,set
, andunset
from lodash. But also consider the potential similar security issues with those APIs.0.9.2 - 2020-09-01
Changed
- Added
util.setPath
security note to function docs and to README.Notes
- SECURITY: The
util.setPath
function has the potential to cause prototype pollution if used with unsafe input.
- This function is not used internally by
forge
.- The rest of the library is unaffected by this issue.
- Do not use unsafe input with this function.
- Usage with known input should function as expected. (Including input intentionally using potentially problematic keys.)
- No code changes will be made to address this issue in 0.9.x. The current behavior could be considered a feature rather than a security issue. 0.10.0 will be released that removes
util.getPath
andutil.setPath
. Considerget
andset
from lodash if you need replacements. But also consider the potential similar security issues with those APIs.- https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7720
0.9.1 - 2019-09-26
Fixed
- Ensure DES-CBC given IV is long enough for block size.
0.9.0 - 2019-09-04
Added
- Add ed25519.publicKeyFromAsn1 and ed25519.privateKeyFromAsn1 APIs.
- A few OIDs used in EV certs.
Commits
8018c3e
Release 0.10.0.6a1e3ef
Remove object path functions.30d560c
Remove Node.js 4 support.1ba83ec
Update dependencies.81abd87
Improve linting.7b59028
Test on Node.js 14.ba13a1c
Update webpack.c8d5395
Add travis browser test names.afc5a72
Update dependencies.ba0207f
Test on Node.js 12.- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.