Skip to content

Bump koa, oidc-provider and rollup-plugin-dev #868

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 29, 2025

Bumps koa to 3.0.1 and updates ancestor dependencies koa, oidc-provider and rollup-plugin-dev. These dependencies need to be updated together.

Updates koa from 2.16.1 to 3.0.1

Release notes

Sourced from koa's releases.

v3.0.1

What's Changed

Full Changelog: koajs/koa@v3.0.0...v3.0.1

v3.0.0

This is a major release.

Breaking

  • Minimum node v18
  • Removes .redirect('back'), adds .back(fallback_url) @​fl0w koajs/koa#1115
  • For .redirect(), don't render redirect values in anchor ref koajs/koa@ff25eb4
  • req.origin should display the origin header if it exists, not the current hostname koajs/koa#1008. origin now aligns with the Origin header as used in CORS.
  • .body=<json> should not overwrite type if type already json koajs/koa#1120
  • Remove special ENOENT support koajs/koa#1861 - this is a big change and will require any file servers to adapt to this change for handling 404s / files not found
  • Removes generator deprecation messages. Generators are no longer supported. Koa no longer asserts if generators are used. Set content-length: 0 if body is explicitly set to null @​ognjenjevremovic #1528 Remove obsolete createAsyncCtxStorageMiddleware koajs/koa#1817
  • ctx.throw now requires a format of ctx.throw(status, error, properties). See: https://www.npmjs.com/package/http-errors

New

Fixes

... (truncated)

Changelog

Sourced from koa's changelog.

[!IMPORTANT] Moving forwards we are using the GitHub releases page at https://github.com/koajs/koa/releases in combination with np for publishing releases and their changelogs.


3.0.0-alpha.3 / 2025-02-11

fixes

  • Avoid redos on host and protocol getter

3.0.0-alpha.2 / 2024-11-04

breaking changes

  • Update http-errors to v2.0.0 #1486
  • Remove res.redirect('back'), add back() method to ctx #1115
  • Replace node querystring with URLSearchParams #1828
  • Remove obsolete createAsyncCtxStorageMiddleware #1817

features

  • Add support for web WHATWG #1830

updates

  • Update cookies to ~0.9.1 #1846
  • Update statuses to ^2.0.1
  • Update supertest to ^7.0.0 #1841

fixes

  • Fix exports.defaults in package.json #1630
  • Fix leaky handles in tests #1838
  • Fix body null checks #1814
  • Fix reformatting redirect URLs #1805 #1804
  • Fix passing ctx in error handler #1758

migrations

  • Migrate from jest to the native node test runner #1845

3.0.0-alpha.1 / 2023-04-12

fixes

3.0.0-alpha.0 / 2023-01-02

Breaking Changes

... (truncated)

Commits
  • 1ddb048 3.0.1
  • 422c551 Merge commit from fork
  • 6e51eb1 build(deps-dev): bump form-data from 4.0.3 to 4.0.4 (#1894)
  • d378e5c build(deps-dev): bump supertest from 7.1.1 to 7.1.4 (#1895)
  • cb22d8d build(deps): bump statuses from 2.0.1 to 2.0.2 (#1888)
  • 0acad8f feat: replace cache-content-type with mime-types directly (#1886)
  • 2f6e814 feat: replace debug module with pure node:util::debuglog (#1885)
  • 8620ced build(deps): bump debug from 4.4.0 to 4.4.1 (#1880)
  • dec1ffc build(deps-dev): bump supertest from 7.1.0 to 7.1.1 (#1879)
  • 9057541 chore: removes done callbacks in tests [CHORE-1870] (#1875)
  • Additional commits viewable in compare view

Updates oidc-provider from 8.8.1 to 9.4.0

Release notes

Sourced from oidc-provider's releases.

v9.4.0

Features

  • Experimental support for Attestation-Based Client Authentication (d655ebd)

Refactor

  • consistently lowercase header names and use req/res aliases (1748a54)
  • cors: update default client-based cors helper (77e06eb)
  • reconcile dpop and attestation challenge implementations (e31f639)

Documentation

  • updated documentation for configuration options (5710d61)

v9.3.0

Features

  • revocation: add an allowed token revocation policy helper (a7e47e4)

Documentation

Fixes

  • introspection: use unsupported_token_type to indicate structured jwt tokens cannot be introspected (c9001be)
  • revocation: use unsupported_token_type to indicate structured jwt tokens cannot be revoked (b45b00c)

Refactor

  • pull structured token rejection to a shared middleware (30367af)

v9.2.0

Features

  • expose RFC8414 Authorization Server Metadata route (c5bd90f)

v9.1.3

Fixes

  • ensure an account's accountId and claims().sub is the same (9b89153), closes #1336

v9.1.2

Fixes

... (truncated)

Changelog

Sourced from oidc-provider's changelog.

9.4.0 (2025-07-17)

Features

  • Experimental support for Attestation-Based Client Authentication (d655ebd)

Refactor

  • consistently lowercase header names and use req/res aliases (1748a54)
  • cors: update default client-based cors helper (77e06eb)
  • reconcile dpop and attestation challenge implementations (e31f639)

Documentation

  • updated documentation for configuration options (5710d61)

9.3.0 (2025-07-16)

Features

  • revocation: add an allowed token revocation policy helper (a7e47e4)

Documentation

Fixes

  • introspection: use unsupported_token_type to indicate structured jwt tokens cannot be introspected (c9001be)
  • revocation: use unsupported_token_type to indicate structured jwt tokens cannot be revoked (b45b00c)

Refactor

  • pull structured token rejection to a shared middleware (30367af)

9.2.0 (2025-06-24)

Features

  • expose RFC8414 Authorization Server Metadata route (c5bd90f)

9.1.3 (2025-06-02)

... (truncated)

Commits
  • e310d4a chore(release): 9.4.0
  • 5710d61 docs: updated documentation for configuration options
  • e31f639 refactor: reconcile dpop and attestation challenge implementations
  • d655ebd feat: Experimental support for Attestation-Based Client Authentication
  • 77e06eb refactor(cors): update default client-based cors helper
  • 1748a54 refactor: consistently lowercase header names and use req/res aliases
  • f4b6421 chore: use correct implementers draft wording (no apostrophe)
  • ad2705a chore: update rp-metadata-choices links to ID1
  • 8ec58b2 chore(release): 9.3.0
  • 30367af refactor: pull structured token rejection to a shared middleware
  • Additional commits viewable in compare view

Updates rollup-plugin-dev from 1.1.3 to 2.0.5

Release notes

Sourced from rollup-plugin-dev's releases.

Version 2 is a complete rewrite of this plugin, and thus comes with a few breaking changes where they couldn't be avoided.

The most noteworthy changes are:

  • Fastify is now used for the server instead of Koa. Koa's ecosystem has been fairly stagnant, and Fastify's plugin system can handle a wider variety of use cases.
  • The proxy option has changed, it now takes an array instead of an object. It's also far easier now to perform path rewrites.
    • v1: { '/v3/*': 'https://polyfill.io' }
    • v2: [{ from: '/v3/*', to: 'https://polyfill.io' }]
  • The spa option is now handled differently. This file must now reside inside of one of the dirs specified, and should be relative to the dir it resides in.
  • The silent option has changed - it now only allows for a boolean and when true the server will be fully silent.
  • The server will automatically resolve a fallback port if the port specified isn't available when starting.
  • The server will warn about starting/not starting differently; it will no longer warn when not starting, only when being forced to start in non-watch mode.
  • The plugin now includes types for the config options

Some of the major breaking changes are detected/warned about - this behavior will be removed in a future release is removed in 2.0.3.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [koa](https://github.com/koajs/koa) to 3.0.1 and updates ancestor dependencies [koa](https://github.com/koajs/koa), [oidc-provider](https://github.com/panva/node-oidc-provider) and [rollup-plugin-dev](https://github.com/pearofducks/rollup-plugin-dev). These dependencies need to be updated together.


Updates `koa` from 2.16.1 to 3.0.1
- [Release notes](https://github.com/koajs/koa/releases)
- [Changelog](https://github.com/koajs/koa/blob/master/History.md)
- [Commits](koajs/koa@v2.16.1...v3.0.1)

Updates `oidc-provider` from 8.8.1 to 9.4.0
- [Release notes](https://github.com/panva/node-oidc-provider/releases)
- [Changelog](https://github.com/panva/node-oidc-provider/blob/main/CHANGELOG.md)
- [Commits](panva/node-oidc-provider@v8.8.1...v9.4.0)

Updates `rollup-plugin-dev` from 1.1.3 to 2.0.5
- [Release notes](https://github.com/pearofducks/rollup-plugin-dev/releases)
- [Commits](pearofducks/rollup-plugin-dev@v1.1.3...v2.0.5)

---
updated-dependencies:
- dependency-name: koa
  dependency-version: 3.0.1
  dependency-type: indirect
- dependency-name: oidc-provider
  dependency-version: 9.4.0
  dependency-type: direct:development
- dependency-name: rollup-plugin-dev
  dependency-version: 2.0.5
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 29, 2025
@dependabot dependabot bot requested a review from a team as a code owner July 29, 2025 09:41
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants