Skip to content

fix(deps): update dependency @davidzemon/passport-okta-oauth to ^0.0.7#6349

Closed
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/davidzemon-passport-okta-oauth-0.x
Closed

fix(deps): update dependency @davidzemon/passport-okta-oauth to ^0.0.7#6349
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/davidzemon-passport-okta-oauth-0.x

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate Bot commented Jul 3, 2025

This PR contains the following updates:

Package Change Age Confidence
@davidzemon/passport-okta-oauth ^0.0.5^0.0.7 age confidence

Release Notes

DavidZemon/passport-okta-oauth (@​davidzemon/passport-okta-oauth)

v0.0.7

Compare Source

v0.0.6

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jul 3, 2025
@codesandbox
Copy link
Copy Markdown

codesandbox Bot commented Jul 3, 2025

Review or Edit in CodeSandbox

Open the branch in Web EditorVS CodeInsiders

Open Preview

@sourcery-ai
Copy link
Copy Markdown

sourcery-ai Bot commented Jul 3, 2025

Reviewer's Guide

Bumps the @davidzemon/passport-okta-oauth dependency to v0.0.7 in the auth-backend plugin and regenerates the yarn.lock to reflect the new version.

File-Level Changes

Change Details Files
Bump @davidzemon/passport-okta-oauth dependency version
  • Updated version spec from ^0.0.5 to ^0.0.7 in package.json
plugins/auth-backend/package.json
Regenerate lockfile to capture updated dependency
  • Updated yarn.lock entries for passport-okta-oauth
yarn.lock

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@github-actions github-actions Bot added the auth label Jul 3, 2025
@snyk-io
Copy link
Copy Markdown

snyk-io Bot commented Jul 3, 2025

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

@renovate renovate Bot force-pushed the renovate/davidzemon-passport-okta-oauth-0.x branch from 0d85971 to 3ed7674 Compare August 21, 2025 04:41
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Aug 21, 2025

@socket-security
Copy link
Copy Markdown

socket-security Bot commented Aug 21, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
jsonpath-plus@7.1.0 has a Critical CVE.

CVE: GHSA-pppg-cpfq-h7wr JSONPath Plus Remote Code Execution (RCE) Vulnerability (CRITICAL)

Affected versions: < 10.2.0

Patched version: 10.2.0

From: yarn.locknpm/@stoplight/spectral-core@1.18.0npm/jsonpath-plus@7.1.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsonpath-plus@7.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions
Copy link
Copy Markdown

This PR has been automatically marked as stale because it has not had recent activity from the author. It will be closed if no further activity occurs. If the PR was closed and you want it re-opened, let us know and we'll re-open the PR so that you can continue the contribution!

@github-actions github-actions Bot added the stale label Aug 28, 2025
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot force-pushed the renovate/davidzemon-passport-okta-oauth-0.x branch from 3ed7674 to 736afca Compare September 1, 2025 01:22
@github-actions github-actions Bot removed the stale label Sep 3, 2025
@github-actions
Copy link
Copy Markdown

This PR has been automatically marked as stale because it has not had recent activity from the author. It will be closed if no further activity occurs. If the PR was closed and you want it re-opened, let us know and we'll re-open the PR so that you can continue the contribution!

@github-actions github-actions Bot added stale and removed stale labels Sep 10, 2025
@github-actions
Copy link
Copy Markdown

This PR has been automatically marked as stale because it has not had recent activity from the author. It will be closed if no further activity occurs. If the PR was closed and you want it re-opened, let us know and we'll re-open the PR so that you can continue the contribution!

@github-actions github-actions Bot added the stale label Sep 22, 2025
@github-actions github-actions Bot removed the stale label Sep 30, 2025
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Oct 8, 2025

This PR has been automatically marked as stale because it has not had recent activity from the author. It will be closed if no further activity occurs. If the PR was closed and you want it re-opened, let us know and we'll re-open the PR so that you can continue the contribution!

@github-actions github-actions Bot added the stale label Oct 8, 2025
@github-actions github-actions Bot removed the stale label Oct 15, 2025
@github-actions
Copy link
Copy Markdown

This PR has been automatically marked as stale because it has not had recent activity from the author. It will be closed if no further activity occurs. If the PR was closed and you want it re-opened, let us know and we'll re-open the PR so that you can continue the contribution!

@github-actions github-actions Bot added the stale label Oct 22, 2025
@github-actions github-actions Bot closed this Oct 27, 2025
@renovate
Copy link
Copy Markdown
Author

renovate Bot commented Oct 29, 2025

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (^0.0.7). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate Bot deleted the renovate/davidzemon-passport-okta-oauth-0.x branch October 29, 2025 07:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auth dependencies Pull requests that update a dependency file stale

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants