Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update xml-encryption to v1.2.3 #562

Merged
merged 1 commit into from
Mar 18, 2021

Conversation

forty
Copy link
Contributor

@forty forty commented Mar 18, 2021

This update xmldom to a non vulnerable version.

@cjbarth cjbarth added the semver-patch This change requires at least a semver-patch version bump label Mar 18, 2021
@cjbarth cjbarth merged commit e5f1151 into node-saml:2.x Mar 18, 2021
@cjbarth
Copy link
Collaborator

cjbarth commented Mar 18, 2021

@forty Did you see that this broke the build?

@forty
Copy link
Contributor Author

forty commented Mar 18, 2021

@cjbarth Sorry, I have no idea, I cannot reproduce issue here :/ can you?

@forty
Copy link
Contributor Author

forty commented Mar 18, 2021

@cjbarth hum, running npm ls it looks like I messed up the package-lock. I did run an npm dedup after my npm install, but I always does, and that usually doesn't cause any trouble 🤔

Another weird thing is that it also seems to be messed up on master, but that did no make the build fail 🤷

Do you want me to open a PR with a fresh package-lock, regenerated from a clean npm install ?

@cjbarth
Copy link
Collaborator

cjbarth commented Mar 18, 2021

Let me have a closer look myself. Thanks for the research.

cjbarth added a commit that referenced this pull request Mar 18, 2021
cjbarth added a commit that referenced this pull request Mar 18, 2021
@cjbarth cjbarth mentioned this pull request May 10, 2021
@cjbarth cjbarth added dependencies Pull requests that update a dependency file and removed semver-patch This change requires at least a semver-patch version bump labels May 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants