Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade openid-client from 4.1.1 to 4.9.1 #112

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

roma8389
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade openid-client from 4.1.1 to 4.9.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 21 versions ahead of your current version.

  • The recommended version was released on 3 years ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Open Redirect
SNYK-JS-GOT-2932019
270 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTTPCACHESEMANTICS-3248783
270 Proof of Concept
Release notes
Package name: openid-client
  • 4.9.1 - 2021-10-13

    Bug Fixes

    • do not implicitly calculate key ids for Client instances (46e44e7), closes #379
  • 4.9.0 - 2021-09-20

    Features

  • 4.8.0 - 2021-09-15

    Features

    • OAuth 2.0 Pushed Authorization Requests (PAR) is now a stable feature (327f366)
  • 4.7.5 - 2021-08-30

    Bug Fixes

    • typescript: add remaining properties from RFC7662 (#398) (166e89b)
  • 4.7.4 - 2021-05-25

    Bug Fixes

    • typescript: add a missing PATCH method to requestResource (6b2c3ce), closes #368
  • 4.7.3 - 2021-04-30

    Bug Fixes

    • fapi: validate ID Token's iat regardless of which channel it came from (b68b9ab)
  • 4.7.2 - 2021-04-23

    Bug Fixes

    • typescript: add types for 4.6.0 additions (9064136)
  • 4.7.1 - 2021-04-22

    Bug Fixes

    • typescript: add types for 4.7.0 additions (2c1d2ab)
  • 4.7.0 - 2021-04-22

    Features

  • 4.6.0 - 2021-03-25

    Features

    • added OAuth 2.0 Pushed Authorization Requests client API (e7af9f5), closes #259
  • 4.5.2 - 2021-03-24
  • 4.5.1 - 2021-03-15
  • 4.5.0 - 2021-03-10
  • 4.4.2 - 2021-03-07
  • 4.4.1 - 2021-02-26
  • 4.4.0 - 2021-01-29
  • 4.3.0 - 2021-01-22
  • 4.2.3 - 2021-01-18
  • 4.2.2 - 2020-11-30
  • 4.2.1 - 2020-10-27
  • 4.2.0 - 2020-10-03
  • 4.1.1 - 2020-09-14
from openid-client GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade openid-client from 4.1.1 to 4.9.1.

See this package in npm:
openid-client

See this project in Snyk:
https://app.snyk.io/org/roma8389/project/7873cf15-3c44-4d49-b218-ced57450efdb?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

github-actions bot commented May 24, 2024

Mega-Linter status: ❌ ERROR

Descriptor Linter Files Fixed Errors Elapsed time
❌ COPYPASTE jscpd yes 5637 214.68s
❌ CREDENTIALS secretlint yes 1 340.05s
✅ EDITORCONFIG editorconfig-checker 2 0 1.77s
✅ GIT git_diff yes no 0.98s
✅ JSON eslint-plugin-jsonc 2 0 0 3.1s
✅ JSON jsonlint 2 0 2.91s
✅ JSON prettier 2 2 0 2.74s
✅ JSON v8r 2 0 10.87s
❌ SPELL cspell 2 12 2.83s
✅ SPELL misspell 2 0 0 1.08s

See errors details in artifact Mega-Linter reports on GitHub Action page
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
2 participants