[Snyk] Upgrade jsrsasign from 10.6.1 to 10.8.6 #1367

Closed
opened 2026-04-05 16:27:03 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 12/2/2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade jsrsasign from 10.6.1 to 10.8.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 8 versions ahead of your current version.
  • The recommended version was released 7 months ago, on 2023-04-26.
Release notes
Package name: jsrsasign
  • 10.8.6 - 2023-04-26
    • Changes from 10.8.5 to 10.8.6 (2023-Apr-26)
      • src/x509.js
        • another bugfix X509.getExtSubjectDirectoryAttributes method
  • 10.8.5 - 2023-04-26
    • Changes from 10.8.4 to 10.8.5 (2023-Apr-26)
      • src/x509.js
        • bugfix X509.getExtSubjectDirectoryAttributes method
  • 10.8.4 - 2023-04-26
    • Changes from 10.8.3 to 10.8.4 (2023-Apr-26)
      • src/asn1x509.js
        • SubjectDirectoryAttributes class
          • add array of array support for arbitrary attribute value
      • src/x509.js
        • add X509.getExtSubjectDirectoryAttributes method for
          ExtSubjectDirectoryAttributes extension
        • update X509.getExtParam method
          • support SubjectDirectoryAttributes
          • parse unknown extension as ASN.1
      • src/base64x.js
        • bugfix foldnl function: when length of s is multiple of n,
          result has unnecessary new line in the end of string.
      • qunit-do-{asn1x509,x509-ext,base64x,x500-param}.html
        • update and add some test cases for above
  • 10.8.3 - 2023-04-19
    • Changes from 10.8.2 to 10.8.3 (2023-Apr-20)
      • src/asn1x509.js
        • Add OIDs for CABR S/MIME BR policy OIDs and GN givenName attribute type
  • 10.8.2 - 2023-04-15
    • Changes from 10.8.1 to 10.8.2 (2023-Apr-15)
      • ext/rsa.js
        • fix RSAEncryptOAEP for RSA OAEP encryption #582 #583
          In rare cases, it have been generated ciphertext that
          could not be decrpyted.
  • 10.8.1 - 2023-04-09
    • Changes from 10.8.0 to 10.8.1 (2023-Apr-09)
      • npm/{package.json, lib/footer.js}
  • 10.8.0 - 2023-04-08
    • Changes from 10.7.0 to 10.8.0 (2023-Apr-8)
      • x509.js
        • X509.getUserNotice supports NoticeReference
        • add asn1ToDisplayText method
      • base64x.js
        • add function msectozulu
        • add aryval for nested JSON value access
      • asn1.js
        • DERInteger refactoring
      • test/qunit-do-{asn1,asn1x509,base64x,x509-ext}.html
        • update and add some test cases for above
  • 10.7.0 - 2023-03-12
    • Changes from 10.6.1 to 10.7.0 (2023-Mar-12)
      • x509.js
        • add X509.registExtParser(): register custom extension parser
      • base64x.js
        • add utility functions
          • b64topem() Base64 string to PEM
          • pemtob64() PEM to Base64 string
          • foldnl() wrap string to fit in specified width
          • timetogen() align to UTCTime to GeneralizedTime
      • test/qunit-do-{x509-ext,base64x}.html
        • update and add some test cases for above
  • 10.6.1 - 2022-11-20
    • Changes from 10.6.0 to 10.6.1 (2022-Nov-20)
      • asn1x509.js
        • KJUR.asn1.x509.{PolicyMappings,PolicyConstraints,InhibitAnyPolicy} class added
        • KJUR.asn1.x509.Extension updated to support
          PolicyMappings, PolicyConstraints and InhibitAnyPolicy
      • x509.js
        • X509.getExt{PolicyMappings,PolicyConstraints,InhibitAnyPolicy} method added
        • X509.getCriticalExtV utility method added
        • X509.getExtParam updated to support
          {PolicyMappings,PolicyConstraints,InhibitAnyPolicy}
        • X509.getInfo updated to support
          {PolicyMappings,PolicyConstraints,InhibitAnyPolicy}
      • test/qunit-do-{asn1x509-tbscert,x509-ext,x509-getinfo,x509-param}.html
        • update and add some test cases for above
from jsrsasign GitHub release notes
Commit messages
Package name: jsrsasign

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

*Originally created by @simlarsen on 12/2/2023* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to upgrade jsrsasign from 10.6.1 to 10.8.6.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **8 versions** ahead of your current version. - The recommended version was released **7 months ago**, on 2023-04-26. <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>jsrsasign</b></summary> <ul> <li> <b>10.8.6</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.8.6">2023-04-26</a></br><ul> <li>Changes from 10.8.5 to 10.8.6 (2023-Apr-26) <ul> <li>src/x509.js <ul> <li>another bugfix X509.getExtSubjectDirectoryAttributes method</li> </ul> </li> </ul> </li> </ul> </li> <li> <b>10.8.5</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.8.5">2023-04-26</a></br><ul> <li>Changes from 10.8.4 to 10.8.5 (2023-Apr-26) <ul> <li>src/x509.js <ul> <li>bugfix X509.getExtSubjectDirectoryAttributes method</li> </ul> </li> </ul> </li> </ul> </li> <li> <b>10.8.4</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.8.4">2023-04-26</a></br><ul> <li>Changes from 10.8.3 to 10.8.4 (2023-Apr-26) <ul> <li>src/asn1x509.js <ul> <li>SubjectDirectoryAttributes class <ul> <li>add array of array support for arbitrary attribute value</li> </ul> </li> </ul> </li> <li>src/x509.js <ul> <li>add X509.getExtSubjectDirectoryAttributes method for<br> ExtSubjectDirectoryAttributes extension</li> <li>update X509.getExtParam method <ul> <li>support SubjectDirectoryAttributes</li> <li>parse unknown extension as ASN.1</li> </ul> </li> </ul> </li> <li>src/base64x.js <ul> <li>bugfix foldnl function: when length of s is multiple of n,<br> result has unnecessary new line in the end of string.</li> </ul> </li> <li>qunit-do-{asn1x509,x509-ext,base64x,x500-param}.html <ul> <li>update and add some test cases for above</li> </ul> </li> </ul> </li> </ul> </li> <li> <b>10.8.3</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.8.3">2023-04-19</a></br><ul> <li>Changes from 10.8.2 to 10.8.3 (2023-Apr-20) <ul> <li>src/asn1x509.js <ul> <li>Add OIDs for CABR S/MIME BR policy OIDs and GN givenName attribute type</li> </ul> </li> </ul> </li> </ul> </li> <li> <b>10.8.2</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.8.2">2023-04-15</a></br><ul> <li>Changes from 10.8.1 to 10.8.2 (2023-Apr-15) <ul> <li>ext/rsa.js <ul> <li>fix RSAEncryptOAEP for RSA OAEP encryption <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1661663747" data-permission-text="Title is private" data-url="https://github.com/kjur/jsrsasign/issues/582" data-hovercard-type="issue" data-hovercard-url="/kjur/jsrsasign/issues/582/hovercard" href="https://snyk.io/redirect/github/kjur/jsrsasign/issues/582">#582</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1668102654" data-permission-text="Title is private" data-url="https://github.com/kjur/jsrsasign/issues/583" data-hovercard-type="pull_request" data-hovercard-url="/kjur/jsrsasign/pull/583/hovercard" href="https://snyk.io/redirect/github/kjur/jsrsasign/pull/583">#583</a><br> In rare cases, it have been generated ciphertext that<br> could not be decrpyted.</li> </ul> </li> </ul> </li> </ul> </li> <li> <b>10.8.1</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.8.1">2023-04-09</a></br><ul> <li>Changes from 10.8.0 to 10.8.1 (2023-Apr-09) <ul> <li>npm/{package.json, lib/footer.js}</li> </ul> </li> </ul> </li> <li> <b>10.8.0</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.8.0">2023-04-08</a></br><ul> <li>Changes from 10.7.0 to 10.8.0 (2023-Apr-8) <ul> <li>x509.js <ul> <li>X509.getUserNotice supports NoticeReference</li> <li>add asn1ToDisplayText method</li> </ul> </li> <li>base64x.js <ul> <li>add function msectozulu</li> <li>add aryval for nested JSON value access</li> </ul> </li> <li>asn1.js <ul> <li>DERInteger refactoring</li> </ul> </li> <li>test/qunit-do-{asn1,asn1x509,base64x,x509-ext}.html <ul> <li>update and add some test cases for above</li> </ul> </li> </ul> </li> </ul> </li> <li> <b>10.7.0</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.7.0">2023-03-12</a></br><ul> <li>Changes from 10.6.1 to 10.7.0 (2023-Mar-12) <ul> <li>x509.js <ul> <li>add X509.registExtParser(): register custom extension parser</li> </ul> </li> <li>base64x.js <ul> <li>add utility functions <ul> <li>b64topem() Base64 string to PEM</li> <li>pemtob64() PEM to Base64 string</li> <li>foldnl() wrap string to fit in specified width</li> <li>timetogen() align to UTCTime to GeneralizedTime</li> </ul> </li> </ul> </li> <li>test/qunit-do-{x509-ext,base64x}.html <ul> <li>update and add some test cases for above</li> </ul> </li> </ul> </li> </ul> </li> <li> <b>10.6.1</b> - <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases/tag/10.6.1">2022-11-20</a></br><ul> <li>Changes from 10.6.0 to 10.6.1 (2022-Nov-20) <ul> <li>asn1x509.js <ul> <li>KJUR.asn1.x509.{PolicyMappings,PolicyConstraints,InhibitAnyPolicy} class added</li> <li>KJUR.asn1.x509.Extension updated to support<br> PolicyMappings, PolicyConstraints and InhibitAnyPolicy</li> </ul> </li> <li>x509.js <ul> <li>X509.getExt{PolicyMappings,PolicyConstraints,InhibitAnyPolicy} method added</li> <li>X509.getCriticalExtV utility method added</li> <li>X509.getExtParam updated to support<br> {PolicyMappings,PolicyConstraints,InhibitAnyPolicy}</li> <li>X509.getInfo updated to support<br> {PolicyMappings,PolicyConstraints,InhibitAnyPolicy}</li> </ul> </li> <li>test/qunit-do-{asn1x509-tbscert,x509-ext,x509-getinfo,x509-param}.html <ul> <li>update and add some test cases for above</li> </ul> </li> </ul> </li> </ul> </li> </ul> from <a href="https://snyk.io/redirect/github/kjur/jsrsasign/releases">jsrsasign GitHub release notes</a> </details> </details> <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>jsrsasign</b></summary> <ul> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/59920c4a502ac1b8eb35d7a0bcad205f63a1884b">59920c4</a> 10.8.6 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/c195be81ed5b751affc563a5b784dbc97bcad79d">c195be8</a> 10.8.5 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/04af7f528399b06e78f612700a332fde8adffc64">04af7f5</a> 10.8.4 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/d679050bb81bfbddea314571f1be5b7b555b4788">d679050</a> 10.8.3 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/97921fb2a0a0e1acafadf1a8247e3d6ace1ceeaa">97921fb</a> 10.8.2 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/d332357a78332ab7e1758ba28fe42123b712dd8b">d332357</a> Merge pull request #583 from davedoesdev/master</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/1cfd9394429b23bd2d00b484a62e0072037b606c">1cfd939</a> Fix OAEP padding</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/9671f4b35992df3ceed61682aa713af216f06292">9671f4b</a> 10.8.1 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/19608d279ee9c75adec84428d781f4a8a85e9a5f">19608d2</a> 10.8.0 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/574e9adfa02a7377f95b6a60dd08920c37f447cc">574e9ad</a> 10.7.0 release</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/8625124366ef2f6a4adc438f38d31a482c3456e3">8625124</a> Merge pull request #569 from samueldiethelm/master</li> <li><a href="https://snyk.io/redirect/github/kjur/jsrsasign/commit/2cc5305ed6a4c76d4bcac3dd3f55a1701944f75e">2cc5305</a> Fix error loading library in Postman</li> </ul> <a href="https://snyk.io/redirect/github/kjur/jsrsasign/compare/f3e32c71beb7e00e08f702543413d70636e7c862...59920c4a502ac1b8eb35d7a0bcad205f63a1884b">Compare</a> </details> </details> <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIwZDQ0YTI5Ny0yNDlkLTRmMGEtYmM4YS1jMDNmOTkyMTE0YzgiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjBkNDRhMjk3LTI0OWQtNGYwYS1iYzhhLWMwM2Y5OTIxMTRjOCJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/274dd1b5-2589-4279-bb73-2a2367ad9639?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/274dd1b5-2589-4279-bb73-2a2367ad9639/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/274dd1b5-2589-4279-bb73-2a2367ad9639/settings/integration?pkg&#x3D;jsrsasign&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"0d44a297-249d-4f0a-bc8a-c03f992114c8","prPublicId":"0d44a297-249d-4f0a-bc8a-c03f992114c8","dependencies":[{"name":"jsrsasign","from":"10.6.1","to":"10.8.6"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/274dd1b5-2589-4279-bb73-2a2367ad9639?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"274dd1b5-2589-4279-bb73-2a2367ad9639","env":"prod","prType":"upgrade","vulns":[],"issuesToFix":[],"upgrade":[],"upgradeInfo":{"versionsDiff":8,"publishedDate":"2023-04-26T14:09:48.038Z"},"templateVariants":[],"hasFixes":false,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[]}) --->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1367