From b4afa08849ecec87ebd03b9bfc5ee44398a3c69d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 29 Nov 2024 03:46:47 +0000 Subject: [PATCH] fix: upgrade @boxyhq/saml20 from 1.5.1 to 1.6.0 Snyk has created this PR to upgrade @boxyhq/saml20 from 1.5.1 to 1.6.0. See this package in npm: @boxyhq/saml20 See this project in Snyk: https://app.snyk.io/org/boxyhq/project/4135eaa3-c381-48c6-aff7-27b60874ae6a?utm_source=github&utm_medium=referral&page=upgrade-pr --- package-lock.json | 20 +++++++++++++++----- package.json | 2 +- 2 files changed, 16 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index 93644fa3..2c77c913 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,7 +9,7 @@ "version": "1.3.9", "license": "Apache 2.0", "dependencies": { - "@boxyhq/saml20": "1.5.1", + "@boxyhq/saml20": "^1.6.0", "daisyui": "4.12.14", "next": "15.0.3", "react": "18.3.1", @@ -168,18 +168,28 @@ } }, "node_modules/@boxyhq/saml20": { - "version": "1.5.1", - "resolved": "https://registry.npmjs.org/@boxyhq/saml20/-/saml20-1.5.1.tgz", - "integrity": "sha512-SpM/i7s11v05akleLCpcYqNoQdlykVy51TEOt6i186KJ2ZqMX5FsPSNxjjluM3v3FpfvAqiy3Vf9eCw0B0JtYQ==", + "version": "1.6.0", + "resolved": "https://registry.npmjs.org/@boxyhq/saml20/-/saml20-1.6.0.tgz", + "integrity": "sha512-Qf5az14Ti8vWnWwiG2yMhvNrlZfNGapg2POOy7W2LuXHccd083PGNslh+ssa/P1TptFbHgoF8lBrMSmHuQW2Cw==", "license": "MIT", "dependencies": { - "@xmldom/xmldom": "0.8.10", + "@xmldom/xmldom": "0.9.4", "xml-crypto": "6.0.0", "xml-encryption": "3.0.2", "xml2js": "0.6.2", "xmlbuilder": "15.1.1" } }, + "node_modules/@boxyhq/saml20/node_modules/@xmldom/xmldom": { + "version": "0.9.4", + "resolved": "https://registry.npmjs.org/@xmldom/xmldom/-/xmldom-0.9.4.tgz", + "integrity": "sha512-zglELfWx7g1cEpVMRBZ0srIQO5nEvKvraJ6CVUC/c5Ky1GgX8OIjtUj5qOweTYULYZo5VnXs/LpUUUNiGpX/rA==", + "deprecated": "this version has critical issues, please update to the latest version", + "license": "MIT", + "engines": { + "node": ">=14.6" + } + }, "node_modules/@emnapi/runtime": { "version": "1.3.1", "resolved": "https://registry.npmjs.org/@emnapi/runtime/-/runtime-1.3.1.tgz", diff --git a/package.json b/package.json index b52c9956..3148cb52 100644 --- a/package.json +++ b/package.json @@ -14,7 +14,7 @@ "release": "git checkout release && git merge origin/main && release-it && git checkout main && git merge origin/release && git push origin main" }, "dependencies": { - "@boxyhq/saml20": "1.5.1", + "@boxyhq/saml20": "1.6.0", "daisyui": "4.12.14", "next": "15.0.3", "react": "18.3.1",