Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

bump jwks-rsa #769

Merged
merged 3 commits into from
Dec 22, 2022
Merged

bump jwks-rsa #769

merged 3 commits into from
Dec 22, 2022

Conversation

adamjmcgrath
Copy link
Contributor

@adamjmcgrath adamjmcgrath commented Dec 22, 2022

Changes

jwks-rsa@1 includes jsonwebtoken@8 so needs to be bumped. It doesn't use this jsonwebtoken, so is not affected by v8's vulnerabilities - but we should upgrade to remove the audit warning.

None of the breaking changes from 1->2 or 2->3 should affect it, so this is just a case of bumping the package version.

fixes #762

Checklist

@adamjmcgrath adamjmcgrath added the review:small Small review label Dec 22, 2022
@adamjmcgrath adamjmcgrath requested a review from a team as a code owner December 22, 2022 20:56
@adamjmcgrath adamjmcgrath merged commit 62052ee into master Dec 22, 2022
@adamjmcgrath adamjmcgrath deleted the jwks-rsa-upgrade branch December 22, 2022 21:09
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
review:small Small review
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Cannot find type definition file for 'express-unless'
2 participants