Skip to content
This repository has been archived by the owner on May 6, 2021. It is now read-only.

Security Updates #70

Open
wants to merge 42 commits into
base: master
Choose a base branch
from
Open

Security Updates #70

wants to merge 42 commits into from

Conversation

jonfairbanks
Copy link
Member

No description provided.

dependabot-preview bot and others added 30 commits April 22, 2021 16:52
…lop/react-dom-17.0.2

Bump react-dom from 16.8.6 to 17.0.2
…lop/winston-3.3.3

Bump winston from 3.1.0 to 3.3.3
Bumps [elliptic](https://github.com/indutny/elliptic) from 6.5.3 to 6.5.4. **This update includes a security fix.**
- [Release notes](https://github.com/indutny/elliptic/releases)
- [Commits](indutny/elliptic@v6.5.3...v6.5.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [passport-facebook](https://github.com/jaredhanson/passport-facebook) from 2.1.1 to 3.0.0.
- [Release notes](https://github.com/jaredhanson/passport-facebook/releases)
- [Commits](jaredhanson/passport-facebook@v2.1.1...v3.0.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…lop/passport-facebook-3.0.0

Bump passport-facebook from 2.1.1 to 3.0.0
…ptic-6.5.4

[Security] Bump elliptic from 6.5.3 to 6.5.4
Bumps [lru-cache](https://github.com/isaacs/node-lru-cache) from 4.1.3 to 6.0.0.
- [Release notes](https://github.com/isaacs/node-lru-cache/releases)
- [Commits](isaacs/node-lru-cache@v4.1.3...v6.0.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…lop/lru-cache-6.0.0

Bump lru-cache from 4.1.3 to 6.0.0
…lop/react-jss-10.6.0

Bump react-jss from 8.6.1 to 10.6.0
…lop/passport-google-oauth-2.0.0

Bump passport-google-oauth from 1.0.0 to 2.0.0
…lop/express-session-1.17.1

Bump express-session from 1.15.6 to 1.17.1
Bumps [ssri](https://github.com/npm/ssri) from 6.0.1 to 6.0.2. **This update includes a security fix.**
- [Release notes](https://github.com/npm/ssri/releases)
- [Changelog](https://github.com/npm/ssri/blob/v6.0.2/CHANGELOG.md)
- [Commits](npm/ssri@v6.0.1...v6.0.2)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [y18n](https://github.com/yargs/y18n) from 4.0.0 to 4.0.3. **This update includes a security fix.**
- [Release notes](https://github.com/yargs/y18n/releases)
- [Changelog](https://github.com/yargs/y18n/blob/y18n-v4.0.3/CHANGELOG.md)
- [Commits](yargs/y18n@v4.0.0...y18n-v4.0.3)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…lop/next-auth-3.3.0

[Security] Bump next-auth from 1.12.1 to 3.3.0
…lop/ssri-6.0.2

[Security] Bump ssri from 6.0.1 to 6.0.2
…lop/y18n-4.0.3

[Security] Bump y18n from 4.0.0 to 4.0.3
Bumps [jss](https://github.com/cssinjs/jss) from 9.8.7 to 10.6.0.
- [Release notes](https://github.com/cssinjs/jss/releases)
- [Changelog](https://github.com/cssinjs/jss/blob/master/changelog.md)
- [Commits](cssinjs/jss@v9.8.7...v10.6.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…lop/react-google-button-0.7.2

Bump react-google-button from 0.5.3 to 0.7.2
jonfairbanks and others added 10 commits April 23, 2021 12:09
…lop/nodemailer-6.5.0

Bump nodemailer from 4.6.8 to 6.5.0
…lop/mongoose-5.12.5

Bump mongoose from 5.7.5 to 5.12.5
…lop/jss-10.6.0

Bump jss from 9.8.7 to 10.6.0
…lop/react-16.14.0

Bump react from 16.11.0 to 16.14.0
…lop/next-10.1.3

Bump next from 9.3.2 to 10.1.3
…lop/connect-mongo-4.4.1

Bump connect-mongo from 2.0.1 to 4.4.1
…lop/universal-cookie-4.0.4

Bump universal-cookie from 2.2.0 to 4.0.4
@jonfairbanks jonfairbanks added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Apr 23, 2021
@jonfairbanks jonfairbanks changed the title Security Updates Only Security Updates Apr 23, 2021
@jonfairbanks jonfairbanks requested a review from bsord April 23, 2021 20:15
dependabot-preview bot and others added 2 commits April 24, 2021 08:53
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant