Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update npm modules - primarily to pull in latest xmldom #76

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

KrayzeeKev
Copy link

By submitting a PR to this repository, you agree to the terms within the Auth0 Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Describe the purpose of this PR along with any background information and the impacts of the proposed change. For the benefit of the community, please do not assume prior context.

Provide details that support your chosen implementation, including: breaking changes, alternatives considered, changes to the API, etc.

If the UI is being changed, please provide screenshots.

Update npm modules to latest versions. Primarily to pull in latest xmldom. Old xmldom is subject to CVE-2021-21366 which is fixed in xmldom 0.5.0. This PR pulls in 0.6.0

References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21366
https://nvd.nist.gov/vuln/detail/CVE-2021-21366
https://github.com/xmldom/xmldom/releases/tag/0.5.0

Include any links supporting this change such as a:

  • GitHub Issue/PR number addressed or fixed
  • Auth0 Community post
  • StackOverflow post
  • Support forum thread
  • Related pull requests/issues from other repos

If there are no references, simply delete this section.

Testing

Describe how this can be tested by reviewers. Be specific about anything not tested and reasons why. If this library has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Also include details of the environment this PR was developed in (language/platform/browser version).

  • [N/A ] This change adds test coverage for new/changed/fixed functionality

Checklist

  • [N/A ] I have added documentation for new/changed functionality in this PR or in auth0.com/docs
  • [X ] All active GitHub checks for tests, formatting, and security are passing
  • [ X] The correct base branch is being used, if not master

@jungRoit
Copy link

Can we please review,merge and deploy this fix quickly.

@sean-kates
Copy link

Would be great to get this merged soon to fix the xmldom issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants