Skip to content
This repository has been archived by the owner on May 6, 2021. It is now read-only.

Security Updates #70

Open
wants to merge 42 commits into
base: master
Choose a base branch
from
Open

Security Updates #70

wants to merge 42 commits into from

Commits on Apr 22, 2021

  1. Configuration menu
    Copy the full SHA
    d8e8c28 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #61 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/react-dom-17.0.2
    
    Bump react-dom from 16.8.6 to 17.0.2
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    1e0bb16 View commit details
    Browse the repository at this point in the history
  3. Bump winston from 3.1.0 to 3.3.3

    Bumps [winston](https://github.com/winstonjs/winston) from 3.1.0 to 3.3.3.
    - [Release notes](https://github.com/winstonjs/winston/releases)
    - [Changelog](https://github.com/winstonjs/winston/blob/master/CHANGELOG.md)
    - [Commits](winstonjs/winston@3.1.0...v3.3.3)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    b4f9358 View commit details
    Browse the repository at this point in the history
  4. Merge pull request #62 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/winston-3.3.3
    
    Bump winston from 3.1.0 to 3.3.3
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    bf5c0a4 View commit details
    Browse the repository at this point in the history
  5. [Security] Bump elliptic from 6.5.3 to 6.5.4

    Bumps [elliptic](https://github.com/indutny/elliptic) from 6.5.3 to 6.5.4. **This update includes a security fix.**
    - [Release notes](https://github.com/indutny/elliptic/releases)
    - [Commits](indutny/elliptic@v6.5.3...v6.5.4)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    a5653bb View commit details
    Browse the repository at this point in the history
  6. Bump passport-facebook from 2.1.1 to 3.0.0

    Bumps [passport-facebook](https://github.com/jaredhanson/passport-facebook) from 2.1.1 to 3.0.0.
    - [Release notes](https://github.com/jaredhanson/passport-facebook/releases)
    - [Commits](jaredhanson/passport-facebook@v2.1.1...v3.0.0)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    87dab09 View commit details
    Browse the repository at this point in the history
  7. Merge pull request #63 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/passport-facebook-3.0.0
    
    Bump passport-facebook from 2.1.1 to 3.0.0
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    1aa3923 View commit details
    Browse the repository at this point in the history
  8. Merge pull request #55 from Fairbanks-io/dependabot/npm_and_yarn/elli…

    …ptic-6.5.4
    
    [Security] Bump elliptic from 6.5.3 to 6.5.4
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    d0ebdb2 View commit details
    Browse the repository at this point in the history
  9. Bump lru-cache from 4.1.3 to 6.0.0

    Bumps [lru-cache](https://github.com/isaacs/node-lru-cache) from 4.1.3 to 6.0.0.
    - [Release notes](https://github.com/isaacs/node-lru-cache/releases)
    - [Commits](isaacs/node-lru-cache@v4.1.3...v6.0.0)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    0c04cbc View commit details
    Browse the repository at this point in the history
  10. Merge pull request #64 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/lru-cache-6.0.0
    
    Bump lru-cache from 4.1.3 to 6.0.0
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    aede862 View commit details
    Browse the repository at this point in the history
  11. Configuration menu
    Copy the full SHA
    7182621 View commit details
    Browse the repository at this point in the history
  12. Bump passport-google-oauth from 1.0.0 to 2.0.0

    Bumps [passport-google-oauth](https://github.com/jaredhanson/passport-google-oauth) from 1.0.0 to 2.0.0.
    - [Release notes](https://github.com/jaredhanson/passport-google-oauth/releases)
    - [Commits](jaredhanson/passport-google-oauth@v1.0.0...v2.0.0)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    e2275b2 View commit details
    Browse the repository at this point in the history
  13. Bump express-session from 1.15.6 to 1.17.1

    Bumps [express-session](https://github.com/expressjs/session) from 1.15.6 to 1.17.1.
    - [Release notes](https://github.com/expressjs/session/releases)
    - [Changelog](https://github.com/expressjs/session/blob/master/HISTORY.md)
    - [Commits](expressjs/session@v1.15.6...v1.17.1)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    e649286 View commit details
    Browse the repository at this point in the history
  14. Merge pull request #65 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/react-jss-10.6.0
    
    Bump react-jss from 8.6.1 to 10.6.0
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    63ab27e View commit details
    Browse the repository at this point in the history
  15. Merge pull request #66 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/passport-google-oauth-2.0.0
    
    Bump passport-google-oauth from 1.0.0 to 2.0.0
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    68516a6 View commit details
    Browse the repository at this point in the history
  16. Merge pull request #67 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/express-session-1.17.1
    
    Bump express-session from 1.15.6 to 1.17.1
    jonfairbanks authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    5099297 View commit details
    Browse the repository at this point in the history
  17. Security Updates Only

    jonfairbanks committed Apr 22, 2021
    Configuration menu
    Copy the full SHA
    9e72713 View commit details
    Browse the repository at this point in the history
  18. Configuration menu
    Copy the full SHA
    eeed2fa View commit details
    Browse the repository at this point in the history
  19. [Security] Bump next-auth from 1.12.1 to 3.3.0

    Bumps [next-auth](https://github.com/nextauthjs/next-auth) from 1.12.1 to 3.3.0. **This update includes a security fix.**
    - [Release notes](https://github.com/nextauthjs/next-auth/releases)
    - [Changelog](https://github.com/nextauthjs/next-auth/blob/main/CHANGELOG.md)
    - [Commits](https://github.com/nextauthjs/next-auth/commits/v3.3.0)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 22, 2021
    Configuration menu
    Copy the full SHA
    d10b08f View commit details
    Browse the repository at this point in the history

Commits on Apr 23, 2021

  1. [Security] Bump ssri from 6.0.1 to 6.0.2

    Bumps [ssri](https://github.com/npm/ssri) from 6.0.1 to 6.0.2. **This update includes a security fix.**
    - [Release notes](https://github.com/npm/ssri/releases)
    - [Changelog](https://github.com/npm/ssri/blob/v6.0.2/CHANGELOG.md)
    - [Commits](npm/ssri@v6.0.1...v6.0.2)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    9e26426 View commit details
    Browse the repository at this point in the history
  2. [Security] Bump y18n from 4.0.0 to 4.0.3

    Bumps [y18n](https://github.com/yargs/y18n) from 4.0.0 to 4.0.3. **This update includes a security fix.**
    - [Release notes](https://github.com/yargs/y18n/releases)
    - [Changelog](https://github.com/yargs/y18n/blob/y18n-v4.0.3/CHANGELOG.md)
    - [Commits](yargs/y18n@v4.0.0...y18n-v4.0.3)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    6f6c40f View commit details
    Browse the repository at this point in the history
  3. Merge pull request #81 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/next-auth-3.3.0
    
    [Security] Bump next-auth from 1.12.1 to 3.3.0
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    b67ed16 View commit details
    Browse the repository at this point in the history
  4. Merge pull request #82 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/ssri-6.0.2
    
    [Security] Bump ssri from 6.0.1 to 6.0.2
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    1eac521 View commit details
    Browse the repository at this point in the history
  5. Merge pull request #83 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/y18n-4.0.3
    
    [Security] Bump y18n from 4.0.0 to 4.0.3
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    9ce3b52 View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    3d12c46 View commit details
    Browse the repository at this point in the history
  7. Configuration menu
    Copy the full SHA
    a3642d4 View commit details
    Browse the repository at this point in the history
  8. Configuration menu
    Copy the full SHA
    57ca1d6 View commit details
    Browse the repository at this point in the history
  9. Bump jss from 9.8.7 to 10.6.0

    Bumps [jss](https://github.com/cssinjs/jss) from 9.8.7 to 10.6.0.
    - [Release notes](https://github.com/cssinjs/jss/releases)
    - [Changelog](https://github.com/cssinjs/jss/blob/master/changelog.md)
    - [Commits](cssinjs/jss@v9.8.7...v10.6.0)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    8da52c7 View commit details
    Browse the repository at this point in the history
  10. Configuration menu
    Copy the full SHA
    39f3304 View commit details
    Browse the repository at this point in the history
  11. Merge pull request #71 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/react-google-button-0.7.2
    
    Bump react-google-button from 0.5.3 to 0.7.2
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    d51c8e0 View commit details
    Browse the repository at this point in the history
  12. Merge pull request #72 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/nodemailer-6.5.0
    
    Bump nodemailer from 4.6.8 to 6.5.0
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    56a947b View commit details
    Browse the repository at this point in the history
  13. Merge pull request #74 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/mongoose-5.12.5
    
    Bump mongoose from 5.7.5 to 5.12.5
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    59a484c View commit details
    Browse the repository at this point in the history
  14. Merge pull request #77 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/jss-10.6.0
    
    Bump jss from 9.8.7 to 10.6.0
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    9264633 View commit details
    Browse the repository at this point in the history
  15. Merge pull request #73 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/react-16.14.0
    
    Bump react from 16.11.0 to 16.14.0
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    27f805c View commit details
    Browse the repository at this point in the history
  16. Bump next from 9.3.2 to 10.1.3

    Bumps [next](https://github.com/vercel/next.js) from 9.3.2 to 10.1.3.
    - [Release notes](https://github.com/vercel/next.js/releases)
    - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js)
    - [Commits](vercel/next.js@v9.3.2...v10.1.3)
    
    Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
    dependabot-preview[bot] authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    4fd43b6 View commit details
    Browse the repository at this point in the history
  17. Merge pull request #75 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/next-10.1.3
    
    Bump next from 9.3.2 to 10.1.3
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    29105d8 View commit details
    Browse the repository at this point in the history
  18. Configuration menu
    Copy the full SHA
    3c7b4ff View commit details
    Browse the repository at this point in the history
  19. Configuration menu
    Copy the full SHA
    dea5b45 View commit details
    Browse the repository at this point in the history
  20. Merge pull request #80 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/connect-mongo-4.4.1
    
    Bump connect-mongo from 2.0.1 to 4.4.1
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    d88a043 View commit details
    Browse the repository at this point in the history
  21. Merge pull request #76 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/universal-cookie-4.0.4
    
    Bump universal-cookie from 2.2.0 to 4.0.4
    jonfairbanks authored Apr 23, 2021
    Configuration menu
    Copy the full SHA
    ef94b47 View commit details
    Browse the repository at this point in the history

Commits on Apr 24, 2021

  1. Configuration menu
    Copy the full SHA
    38248b6 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #84 from Fairbanks-io/dependabot/npm_and_yarn/deve…

    …lop/next-auth-3.17.0
    
    Bump next-auth from 3.3.0 to 3.17.0
    jonfairbanks authored Apr 24, 2021
    Configuration menu
    Copy the full SHA
    2b1ede8 View commit details
    Browse the repository at this point in the history