chore(deps): bump openpgp from 5.10.1 to 5.11.3
Type: Pull Request
State: Open
Association: Contributor
Comments: 1
(about 1 year ago)
(about 1 year ago)
dependencies javascript
⚠️ Dependabot is rebasing this PR ⚠️
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps openpgp from 5.10.1 to 5.11.3.
Release notes
Sourced from openpgp's releases.
v5.11.3 - Security Patch
- Address CVE-2025-47934 (Message signature verification could be spoofed)
v5.11.2
What's Changed
openpgp.verify: fix bug preventing verification of detached signatures over streamed data (#1762)Full Changelog: https://github.com/openpgpjs/openpgpjs/compare/v5.11.1...v5.11.2
v5.11.1
What's Changed
- Patch for Node v18.19.1+, 20.11.1+ and 21.6.2+: use JS fallback code for RSA decryption on Node when PKCS#1 is not supported (see #1728).
Full Changelog: https://github.com/openpgpjs/openpgpjs/compare/v5.11.0...v5.11.1
v5.11.0
What's Changed
crypto-refresh: minor fixes and updates for X25519/Ed25519 (new format) (openpgpjs/openpgpjs#1687)
- Introduce
enums.publicKey.eddsaLegacy, set to replaceenums.publicKey.eddsain v6- Introduce
enums.curve.ed25519Legacyand.curve25519Legacy, set to replaceenums.curve.ed25519and.curve25519in v6- Fix stream closure when using Node's stream.pipeline (openpgpjs/openpgpjs#1691)
- Fix binding signature generation using shorter hash than expected for some ECDSA subkeys
- Always use NodeCrypto over WebCrypto in Node 20 (openpgpjs/openpgpjs#1692)
- TS: Allow nullable date in
VerifyOptions(openpgpjs/openpgpjs#1644)Full Changelog: https://github.com/openpgpjs/openpgpjs/compare/v5.10.2...v5.11.0
v5.10.2
What's Changed
- Fix CFB decryption performance in JS fallback for ciphers other than AES (#1679)
- Minor: fix packet validity check for new curve25519 keys without key flags
Full Changelog: https://github.com/openpgpjs/openpgpjs/compare/v5.10.1...v5.10.2
Commits
b9edc545.11.343f5f4eDon't mutate message during verificationa0337785.11.23eba29dMerge pull request #176275f1095Tests: move away from global streameddata1ce2df1Avoid using stream.clone over polyfilled steam in test6ace4a0Update web-stream-tools to fix passiveClone cancellation race condition in testsa315c46openpgp.verify: fix bug preventing verification of detached signature over ...026b3485.11.1711c418Run npm audit- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
0
0
+0
-0
Package Dependencies
Technical Details
| ID: | 513282 |
| UUID: | 3075384617 |
| Node ID: | PR_kwDOATMJfM6WzlC3 |
| Host: | GitHub |
| Repository: | BitGo/BitGoJS |