Skip to content

deps: update cookie-signature from 1.0.6 to ~1.2.2#169

Closed
Offwhite-Del wants to merge 1 commit into
expressjs:masterfrom
Offwhite-Del:upgrade-cookie-signature-to-v1.2.2
Closed

deps: update cookie-signature from 1.0.6 to ~1.2.2#169
Offwhite-Del wants to merge 1 commit into
expressjs:masterfrom
Offwhite-Del:upgrade-cookie-signature-to-v1.2.2

Conversation

@Offwhite-Del

Copy link
Copy Markdown

Summary

Upgrade cookie-signature runtime dependency from 1.0.6 to ~1.2.2.

Motivation

cookie-signature v1.2.x brings minor improvements and bug fixes over v1.0.6. The signing/unsigning API is fully backward-compatible within the v1 major range.

Testing

  • npm install succeeds
  • npm test passes: 32/32
  • No source code changes required

Changes

  • package.json: "cookie-signature": "1.0.6""cookie-signature": "~1.2.2"

🤖 Generated with Claude Code

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​cookie-signature@​1.0.6 ⏵ 1.2.210010070 -683100

View full report

@Offwhite-Del

Copy link
Copy Markdown
Author

Closing after re-review. This is an unsolicited runtime dependency update with no linked bug or security advisory. The test run shows compatibility, but not a concrete reason for maintainers to take the change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant