Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade jsonwebtoken from 5.7.0 to 7.4.1 #49

Open
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

crew-security
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

    • package.json
    • package-lock.json
  • Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches.
    Find out more.

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
low severity Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
Yes No Known Exploit
Commit messages
Package name: jsonwebtoken The new version differs by 120 commits.
  • 5e6dc77 update changelog
  • e9c6ddd 7.4.1
  • adcfd6a bump ms to v2 due a ReDoS vuln (#352)
  • 6755049 Update changelog
  • b0e443c 7.4.0
  • 07a47a3 Merge pull request #328 from ziluvatar/npb-exp-iat-docs-numeric-date
  • 659f731 Add docs about numeric date fields
  • 2ec4960 Merge pull request #320 from ziluvatar/make-options-optional-on-async-call
  • e202c4f Make Options object optional for callback-ish sign
  • 636fbd0 Update changelog
  • 94007b3 7.3.0
  • 1b0592e Add more information to `maxAge` option in README
  • 8fdc150 Allow user to specify now. (#274)
  • 7f68fe0 Raise jws.decode error to avoid confusion with "invalid token" error (#294)
  • a542403 Fixed a simple typo (#287)
  • 1b6ec8d Fix handling non string tokens (#305)
  • 35d8415 rauchg/ms.js changed to zeit/ms (#303)
  • 05d9978 update changelog
  • 8da893a 7.2.1
  • 4219c34 add nsp check to find vulnerabilities on npm test
  • 51d4796 revert to joi@^6 to keep ES5 compatibility
  • 445cab7 update changelog
  • e35bcdc Merge pull request #243 from rmharrison/patch-1
  • 3a8b2b6 7.2.0

See the full diff

With a Snyk patch:
Severity Issue Exploit Maturity
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
No Known Exploit

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants