[Security] Bump tough-cookie from 4.0.0 to 4.1.3
Bumps tough-cookie from 4.0.0 to 4.1.3. This update includes a security fix.
Vulnerabilities fixed
tough-cookie Prototype Pollution vulnerability Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in
rejectPublicSuffixes=false
mode. This issue arises from the manner in which the objects are initialized.Patched versions: 4.1.3 Affected versions: < 4.1.3
Release notes
Sourced from tough-cookie's releases.
4.1.3
Security fix for Prototype Pollution discovery in #282. This is a minor release, although output from the
inspect
utility is affected by this change, we felt this change was important enough to be pushed into the next patch.4.1.2 -- Patch and Bugfix Release
What's Changed
- fix: allow set cookies with localhost by
@colincasey
in salesforce/tough-cookie#253Full Changelog: https://github.com/salesforce/tough-cookie/compare/v4.1.1...v4.1.2
4.1.1
Patch Release
What's Changed
- fix: allow special use domains by default by
@colincasey
in salesforce/tough-cookie#249- 4.1.1 Patch -- allow special use domains by default by
@awaterma
in salesforce/tough-cookie#250Full Changelog: https://github.com/salesforce/tough-cookie/compare/v4.1.0...v4.1.1
4.1.0
v4.1.0
Minor release, focused mainly on resolving reported issues and some minor feature work.
What's Changed
- Create CHANGELOG.md by
@ShivanKaul
in salesforce/tough-cookie#189- Missing param validation issue145 by
@medelibero-sfdc
in salesforce/tough-cookie#193- Create SECURITY.md by
@ShivanKaul
in salesforce/tough-cookie#201- Create CODE_OF_CONDUCT.md by
@ShivanKaul
in salesforce/tough-cookie#200- Fix for issue #195 by
@medelibero-sfdc
in salesforce/tough-cookie#202- Add explanation and more special-use domains by
@ShivanKaul
in salesforce/tough-cookie#203- Sync of constructor options for serialization by
@medelibero-sfdc
in salesforce/tough-cookie#204- Returned null in case of empty cookie value by
@vsin12
in salesforce/tough-cookie#196- 132 str trim not a function by
@awaterma
in salesforce/tough-cookie#209- Fix for issue #153 by
@medelibero-sfdc
in salesforce/tough-cookie#210- Fix permuteDomain with trailing dot by
@ruoho-sfdc
in salesforce/tough-cookie#216- Issue #213 -- added gh-actions flow for building and testing tough-co… by
@awaterma
in salesforce/tough-cookie#218- Issue #210 -- Updated workflow to use npm install. by
@awaterma
in salesforce/tough-cookie#220- @GH-215 -- Tests that document localhost behavior when set as domain. by
@awaterma
in salesforce/tough-cookie#221- fix: MemoryCookieStore methods should exist on the prototype, not on the class. by
@wjhsf
in salesforce/tough-cookie#226- Unit test cases for
allowSpecialUseDomain
option by@colincasey
in salesforce/tough-cookie#225- [Snyk] Upgrade universalify from 0.1.2 to 0.2.0 by
@snyk-bot
in salesforce/tough-cookie#228- React Native Support by
@colincasey
in salesforce/tough-cookie#227- Adding Updating CODEOWNERS with ECCN as per Export Control Compliance by
@svc-scm
in salesforce/tough-cookie#223- fix: domain match routine by
@colincasey
in salesforce/tough-cookie#236- Stop using the internal NodeJS punycode module by
@gboer
in salesforce/tough-cookie#238- Initial documentation review by
@mcarey86
in salesforce/tough-cookie#234- fix: distinguish between no samesite and samesite=none by
@colincasey
in salesforce/tough-cookie#240- Prepare tough-cookie 4.1 for publishing (updated GitHub actions, move… by
@awaterma
in salesforce/tough-cookie#242- 4.1.0 release to NPM by
@awaterma
in salesforce/tough-cookie#245
... (truncated)
Commits
-
4ff4d29
4.1.3 release preparation, update the package and lib/version to 4.1.3. (#284) -
12d4747
Prevent prototype pollution in cookie memstore (#283) -
f06b72d
Fix documentation for store.findCookies, missing allowSpecialUseDomain proper... -
b1a8898
fix: allow set cookies with localhost (#253) -
ec70796
4.1.1 Patch -- allow special use domains by default (#250) -
d4ac580
fix: allow special use domains by default (#249) -
79c2f7d
4.1.0 release to NPM (#245) -
4fafc17
Prepare tough-cookie 4.1 for publishing (updated GitHub actions, move Dockerf... -
aa4396d
fix: distinguish between no samesite and samesite=none (#240) -
b8d7511
Modernize README (#234) - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot rebase
will rebase this MR -
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts