-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency passport to ^0.6.0 [security] #615
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate/npm-passport-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 7, 2022 09:51
3055aff
to
7a86e58
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Jul 7, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 16, 2022 12:04
7a86e58
to
2f98aa3
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v [security]
Jul 16, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 16, 2022 13:41
2f98aa3
to
f3439f0
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Jul 16, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 16, 2022 21:30
f3439f0
to
f78eab7
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v [security]
Jul 16, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 16, 2022 21:34
f78eab7
to
b4e7261
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Jul 16, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 21, 2022 05:37
b4e7261
to
e5e0a9c
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v [security]
Jul 21, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 21, 2022 13:39
e5e0a9c
to
79a8320
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Jul 21, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 24, 2022 10:36
79a8320
to
2f1985e
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v [security]
Jul 24, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
July 24, 2022 12:49
2f1985e
to
0a5457f
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Jul 24, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 1, 2022 15:11
0a5457f
to
b4d6e75
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v [security]
Aug 1, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 1, 2022 19:56
b4d6e75
to
2cc0054
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Aug 1, 2022
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to [security]
Aug 9, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
2 times, most recently
from
August 9, 2022 17:52
f4a94c7
to
877f695
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Aug 9, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 20, 2022 16:45
877f695
to
8d9347f
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v0.4.1 [security]
Aug 20, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 20, 2022 19:28
8d9347f
to
85e55a2
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v0.4.1 [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Aug 20, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 22, 2022 13:50
85e55a2
to
6e35f0d
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v0.4.1 [security]
Aug 22, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 22, 2022 17:39
6e35f0d
to
a2530c2
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v0.4.1 [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Aug 22, 2022
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v0.4.1 [security]
Aug 30, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 30, 2022 13:31
a2530c2
to
29d1ff6
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v0.4.1 [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Aug 30, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
August 30, 2022 18:02
29d1ff6
to
645a04a
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v0.4.1 [security]
Sep 2, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
2 times, most recently
from
September 2, 2022 12:58
0ec5d2d
to
ed6e5f4
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v0.4.1 [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Sep 2, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
September 6, 2022 12:51
ed6e5f4
to
dc69853
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v0.4.1 [security]
Sep 6, 2022
renovate
bot
changed the title
fix(deps): pin dependency passport to v0.4.1 [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Sep 6, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
September 6, 2022 16:30
dc69853
to
af7f827
Compare
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v0.4.1 [security]
Sep 7, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
2 times, most recently
from
September 7, 2022 21:17
807bda0
to
7e617d6
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v0.4.1 [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Sep 7, 2022
renovate
bot
changed the title
fix(deps): update dependency passport to ^0.6.0 [security]
fix(deps): pin dependency passport to v0.4.1 [security]
Sep 14, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
2 times, most recently
from
September 14, 2022 23:29
4c5ad48
to
8516194
Compare
renovate
bot
changed the title
fix(deps): pin dependency passport to v0.4.1 [security]
fix(deps): update dependency passport to ^0.6.0 [security]
Sep 14, 2022
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
March 17, 2023 05:35
8516194
to
d461748
Compare
renovate
bot
force-pushed
the
renovate/npm-passport-vulnerability
branch
from
April 27, 2023 20:57
d461748
to
67c80bc
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.4.1
->^0.6.0
GitHub Vulnerability Alerts
CVE-2022-25896
This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.
Release Notes
jaredhanson/passport
v0.6.0
Compare Source
Added
authenticate()
,req#login
, andreq#logout
accept akeepSessionInfo: true
option to keep session information after regeneratingthe session.
Changed
req#login()
andreq#logout()
regenerate the the session and clear sessioninformation by default.
req#logout()
is now an asynchronous function and requires a callbackfunction as the last argument.
Security
physical access to the same system or the application is susceptible to
cross-site scripting (XSS).
v0.5.3
Compare Source
Fixed
initialize()
middleware extends request withlogin()
,logIn()
,logout()
,logOut()
,isAuthenticated()
, andisUnauthenticated()
functionsagain, reverting change from 0.5.1.
v0.5.2
Compare Source
Fixed
[email protected]
or earlier (such aspassport-azure-ad
), which werebroken by the removal of private variables in
[email protected]
.v0.5.1
Compare Source
Added
available.
Changed
authenticate()
middleware, rather thaninitialize()
middleware, extendsrequest with
login()
,logIn()
,logout()
,logOut()
,isAuthenticated()
,and
isUnauthenticated()
functions.v0.5.0
Compare Source
Changed
initialize()
middleware extends request withlogin()
,logIn()
,logout()
,logOut()
,isAuthenticated()
, andisUnauthenticated()
functions.
Removed
login()
,logIn()
,logout()
,logOut()
,isAuthenticated()
, andisUnauthenticated()
functions no longer added tohttp.IncomingMessage.prototype
.Fixed
userProperty
option toinitialize()
middleware only affects the currentrequest, rather than all requests processed via singleton Passport instance,
eliminating a race condition in situations where
initialize()
middleware isused multiple times in an application with
userProperty
set to differentvalues.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.