Skip to content

Bump jsonwebtoken from 8.5.1 to 9.0.0#104

Open
renovate-pagopa[bot] wants to merge 1 commit intomasterfrom
renovate/jsonwebtoken-to-9.0.0
Open

Bump jsonwebtoken from 8.5.1 to 9.0.0#104
renovate-pagopa[bot] wants to merge 1 commit intomasterfrom
renovate/jsonwebtoken-to-9.0.0

Conversation

@renovate-pagopa
Copy link

@renovate-pagopa renovate-pagopa bot commented Jan 20, 2025

This PR contains the following updates:

Package Change Age Confidence
jsonwebtoken ^8.5.1 -> ^9.0.0 age confidence

For further information on security, please refer to the Confluence page link


Release Notes

auth0/node-jsonwebtoken (jsonwebtoken)

v9.0.0

Compare Source

Breaking changes: See Migration from v8 to v9

Breaking changes
  • Removed support for Node versions 11 and below.
  • The verify() function no longer accepts unsigned tokens by default. ([8345030]8345030)
  • RSA key size must be 2048 bits or greater. ([ecdf6cc]ecdf6cc)
  • Key types must be valid for the signing / verification algorithm
Security fixes
  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@github-actions
Copy link

Jira Pull request Link

It seems this Pull Request has no issues that refers to Jira!!!
Please check it out.

@sonarqubecloud
Copy link

@renovate-pagopa renovate-pagopa bot force-pushed the renovate/jsonwebtoken-to-9.0.0 branch from 4b72ca6 to 54684ae Compare March 20, 2025 04:42
@sonarqubecloud
Copy link

@renovate-pagopa renovate-pagopa bot changed the title Bump jsonwebtoken from 8.5.1 to 9.0.0 Bump jsonwebtoken from 8.5.1 to 9.0.0 - autoclosed Aug 5, 2025
@renovate-pagopa renovate-pagopa bot closed this Aug 5, 2025
@renovate-pagopa renovate-pagopa bot deleted the renovate/jsonwebtoken-to-9.0.0 branch August 5, 2025 04:52
@renovate-pagopa renovate-pagopa bot restored the renovate/jsonwebtoken-to-9.0.0 branch August 5, 2025 08:52
@renovate-pagopa renovate-pagopa bot changed the title Bump jsonwebtoken from 8.5.1 to 9.0.0 - autoclosed Bump jsonwebtoken from 8.5.1 to 9.0.0 Aug 5, 2025
@renovate-pagopa renovate-pagopa bot reopened this Aug 5, 2025
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/jsonwebtoken-to-9.0.0 branch from 54684ae to 722b76e Compare August 5, 2025 08:53
@sonarqubecloud
Copy link

sonarqubecloud bot commented Aug 5, 2025

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants