Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgraded dependencies from security advisories #1848

Merged
merged 17 commits into from
Apr 20, 2020
Merged

Upgraded dependencies from security advisories #1848

merged 17 commits into from
Apr 20, 2020

Conversation

stevehobbsdev
Copy link
Contributor

@stevehobbsdev stevehobbsdev commented Apr 17, 2020

Changes

A number of dependencies have been upgraded based on security advisories that have been raised (details in commit log).

Testing

  • This change adds unit test coverage
  • This change adds integration test coverage
  • This change has been tested on the latest version of the platform/language

Checklist

@stevehobbsdev stevehobbsdev added CH: Security dependencies One or more dependencies are being bumped labels Apr 17, 2020
@stevehobbsdev stevehobbsdev added this to the vNext milestone Apr 17, 2020
@stevehobbsdev stevehobbsdev requested a review from a team April 17, 2020 12:54
@lbalmaceda
Copy link
Contributor

These are all for dev dependencies. These vulnerabilities had no impact on the library usage 👍

@stevehobbsdev stevehobbsdev merged commit e584e1a into master Apr 20, 2020
@stevehobbsdev stevehobbsdev deleted the deps branch April 20, 2020 09:01
stevehobbsdev pushed a commit that referenced this pull request Apr 21, 2020
stevehobbsdev pushed a commit that referenced this pull request Apr 21, 2020
davidpatrick pushed a commit to davidpatrick/lock that referenced this pull request Jun 12, 2020
* Resolved minimist to 0.2.1 (sec vuln)

* Resolved handlebars to 4.7.6

* Resolved set-value to 3.0.2

* Resolved js-yaml to 3.13.1

* Resolved minimatch to 3.0.4

* Resolved cryptiles to 4.1.3

* Resolved mime to 2.4.4

* Resolved mime to 1.4.1

* Resolved lodash to 4.17.15, upgraded Grunt ecosystem

* Resolved underscore.string to 3.3.5

* Resolved tunnel-agent to 0.6.0

* Resolved request to 2.68.0

* Upgraded jsonwebtoken, resolved hoek to 4.2.1

* Resolved mem to 6.1.0

* Updated circle build image to Node 10
davidpatrick pushed a commit to davidpatrick/lock that referenced this pull request Jun 12, 2020
jfromaniello pushed a commit to jfromaniello/auth0-lock that referenced this pull request Jul 23, 2020
* Resolved minimist to 0.2.1 (sec vuln)

* Resolved handlebars to 4.7.6

* Resolved set-value to 3.0.2

* Resolved js-yaml to 3.13.1

* Resolved minimatch to 3.0.4

* Resolved cryptiles to 4.1.3

* Resolved mime to 2.4.4

* Resolved mime to 1.4.1

* Resolved lodash to 4.17.15, upgraded Grunt ecosystem

* Resolved underscore.string to 3.3.5

* Resolved tunnel-agent to 0.6.0

* Resolved request to 2.68.0

* Upgraded jsonwebtoken, resolved hoek to 4.2.1

* Resolved mem to 6.1.0

* Updated circle build image to Node 10
jfromaniello pushed a commit to jfromaniello/auth0-lock that referenced this pull request Jul 23, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies One or more dependencies are being bumped
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants