Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency googleapis to v39 [SECURITY] #636

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 28, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
googleapis 34.0.0 -> 39.1.0 age adoption passing confidence

GitHub Vulnerability Alerts

GHSA-7543-mr7h-6v86

Versions of googleapis prior to 39.1.0 are vulnerable to Improper Authorization. Setting credentials to one client may apply to all clients which may cause requests to be sent with the incorrect credentials.

Recommendation

Upgrade to version 39.1.0.


Release Notes

googleapis/google-api-nodejs-client (googleapis)

v39.1.0

Compare Source

03-28-2019 16:17 PDT

This release has security fixes.. Versions 36.0.0 => 39.0.0 have a potential vulnerability where the scope of auth objects may be shared across different clients. This was addressed in #​1660, and is part of this minor release. All clients should be updated to the latest version.

Bug Fixes
  • fix: move context from namespace to class scope (#​1660)
New Features
Internal / Testing Changes
  • fix: README should not be generated (#​1657)

v39.0.0

Compare Source

03-26-2019 22:05 PDT

This release had breaking changes. There have been a variety of TypeScript type changes. There have also been a variety of changes to the Google Plus API, and the OAuth2 API. Please take care!

There are also some sweet new APIs:

  • cloudasset_v1
  • cloudtasks_v2
  • factchecktools_v1alpha1
  • servicenetworking_v1
  • websecurityscanner_v1beta
New Features
Documentation
  • docs: remove the plus samples (#​1654)
  • docs: Update typo in README.md (#​1640)
  • docs: fix typos in README files (#​1642)
Internal / Testing Changes
  • chore(deps): update dependency tmp to ^0.1.0 (#​1652)
  • chore: publish to npm using wombat (#​1645)
  • build: update npm token (#​1641)
  • chore(deps): update dependency hard-rejection to v2 (#​1643)
  • build: use per-repo publish token (#​1638)

v38.0.0

Compare Source

03-12-2019 14:00 PDT

Greetings y'all! This release has some new APIs, says goodbye to a few older ones, and fixes a bunch of doc issues. Enjoy!

BREAKING CHANGES: The following APIs have been deleted:

  • appengine_v1beta4
  • appengine_v1beta5

The following APIs have been added:

  • accesscontextmanager_v1
  • bigtableadmin_v1
  • cloudprivatecatalog_v1beta1
  • cloudprivatecatalogproducer_v1beta1
  • healthcare_v1alpha2
  • videointelligence_v1p3beta1
New Features
Bug Fixes
Documentation
  • docs: fix npm install cmd in readme (#​1635)
  • docs: update contributing guide (#​1615)
  • docs: Remove "releasing" ToC from CONTRIBUTING.md (#​1607)
  • docs: update CONTRIBUTING link (#​1603)
  • docs: update links in contrib guide (#​1599)
  • docs: Use people API instead of plus API
  • docs: move CONTRIBUTING.md to root (#​1583)
Internal / Testing Changes

v37.2.0

Compare Source

02-07-2019 14:55 PST

New Features

This pulls in a few new APIs:

  • dfareporting_v3_3
  • healthcare_v1alpha
  • videointelligence_v1p2beta1
Bug fixes
  • fix: respect . in api versions (fix adsense API) (#​1573)
Documentation
  • docs: add lint/fix example to contributing guide (#​1581)
  • docs(samples): Talent API Sample Revision & Test (#​1546)

v37.1.0

Compare Source

01-29-2019 13:33 PST

This release includes a new API for working with Google Docs. Enjoy!

v37.0.0

Compare Source

01-28-2019 10:29 PST

This release has breaking changes. But it's also got a lot of good stuff too. Keep reading!

google-auth-library 3.0

The google-auth-library module has been upgrade to 3.0. This comes with it's own breaking changes, which are covered here.

gaxios upgrade

Previous versions of this library used the axios library as an underlying HTTP transport. In an effort to fix a variety of problems, this has been swapped out for an API compatible library: gaxios. While we've tried really hard to ensure compatibility with axios, it's entirely possible there are subtle differences. If you run into trouble - just let us know!

Removed APIs

The replicapoolupdater_v1beta1 API has been removed.

New features
Webpack support

This library is now webpack-able! Samples and docs are still coming, but you should be able to bundle for the browser now.

New APIs

The following APIs have been introduced:

  • file_v1
  • bigtableadmin_v2
  • cloudbuild_v1alpha1
  • cloudidentity_v1
  • cloudidentity_v1beta1
  • containeranalysis_v1alpha1
  • containeranalysis_v1beta1
  • content_v2_1
  • iap_v1
  • libraryagent_v1
  • remotebuildexecution_v1
  • remotebuildexecution_v1alpha
  • remotebuildexecution_v2
Changes

It includes the following changes:

  • feat: run the generator (#​1564)
  • feat: run the generator (#​1541)
  • feat: webpack support for all APIs (#​1554)
  • feat: generating webpackable packages (#​1547)
Documentation
  • docs: specify gaxios over axios (#​1558)
  • docs(samples): add people samples for get & create contacts (#​1543)
  • docs: fix typo in README.md (#​1549)
  • docs: improve the compute sample in the README (#​1537)
  • docs(samples): rework the compute list vms sample (#​1534)
  • docs: correct the README (#​1522)
  • docs: use blogger to demonstrate key authentication (#​1519)
  • docs: fix the doc generator (#​1489)
Dependencies
  • fix(deps): update dependency googleapis-common to ^0.7.0 (#​1560)
  • fix(deps): update googleapis-common and google-auth-library (#​1556)
Bug fixes
  • fix(generator): convert method names to camelCase (#​1552)
  • fix(test): fix the revoke token test (#​1532)

v36.0.0

Compare Source

12-06-2018 17:35 PST

New APIs
  • cloudscheduler_v1beta1
  • driveactivity_v2
  • pagespeedonline_v5
  • speech_v1p1beta1
Removed APIs
  • dfareporting_v3_0
  • partners_v2
  • speech_v1beta1
Features
  • feat: run the generator (#​1474)
  • feat: Add support for repeated fields (#​1451)
Bug fixes
Documentation
  • docs: be more explicit about supported version of nodejs for docs (#​1473)
  • docs: add note about minimum Node.js version required (#​1464)
  • fix(samples): fix url parsing in sampleClient (#​1462)
  • docs: Added information to run the quickstart sample (#​1460)
Internal / Testing Changes
  • chore: always nyc report before calling codecov (#​1482)
  • chore: nyc ignore build/test by default (#​1481)
  • refactor: remove weird root binding (#​1476)
  • refactor: add dev dependencies to APIs (#​1475)
  • chore(deps): update dependency typescript to ~3.2.0 (#​1465)
  • fix(build): fix system key decryption (#​1467)
  • chore(deps): update dependency @​types/p-queue to v3 (#​1449)
  • chore: try to fix codecov (#​1439)
  • chore(deps): update dependency gts to ^0.9.0 (#​1440)
  • chore: update eslintignore config (#​1438)

v35.0.0

Compare Source

This release has breaking changes. Please take care with your upgrade!

Breaking changes

The following APIs have been deprecated and removed:

  • content_v2sandbox
  • dfareporting_v2_8
  • serviceuser_v1
New APIs

The following new APIs have been added since the last release:

  • accesscontextmanager_v1beta
  • alertcenter_v1beta1
  • cloudasset_v1beta1
  • cloudsearch_v1
  • firebasehosting_v1beta1
  • servicenetworking_v1beta
Generator runs (adds and removes APIs above)
Bug fixes
  • fix: generator missing standard parameters (#​1390)
  • Don't publish sourcemaps (#​1364)
Dependencies
  • fix(deps): update dependency googleapis-common to ^0.4.0 (#​1426)
  • fix: update gsuite admin samples (#​1361)
Samples
  • fix: use URL constructor in the samples (#​1424)
Internal / Testing Changes
  • chore: drop contributors from multiple places (#​1428)
  • fix: failing system test (#​1429)
  • chore: use latest npm on Windows (#​1427)
  • chore: update CircleCI config (#​1423)
  • chore: include build in eslintignore (#​1420)
  • chore(deps): update dependency eslint-plugin-node to v8 (#​1415)
  • chore: update issue templates (#​1413)
  • chore: remove old issue template (#​1411)
  • build: run tests on node11 (#​1410)
  • chore(deps): update dependency typescript to ~3.1.0 (#​1403)
  • chore(deps): update dependency eslint-plugin-prettier to v3 (#​1404)
  • chore(deps): update dependency nock to v10 (#​1405)
  • chores(build): do not collect sponge.xml from windows builds (#​1406)
  • chores(build): run codecov on continuous builds (#​1401)
  • chore: update new issue template (#​1398)
  • feat: Allow use of --discovery-url parameter (#​1377)
  • build: fix codecov uploading on Kokoro (#​1389)
  • Update kokoro config (#​1372)
  • Update CI config (#​1368)
  • Fix Windows Kokoro builds (#​1365)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title Update dependency googleapis to v39 [SECURITY] Update dependency googleapis to v39 [SECURITY] - autoclosed Apr 3, 2024
@renovate renovate bot closed this Apr 3, 2024
@renovate renovate bot deleted the renovate/npm-googleapis-vulnerability branch April 3, 2024 13:26
@renovate renovate bot changed the title Update dependency googleapis to v39 [SECURITY] - autoclosed Update dependency googleapis to v39 [SECURITY] Apr 3, 2024
@renovate renovate bot reopened this Apr 3, 2024
@renovate renovate bot restored the renovate/npm-googleapis-vulnerability branch April 3, 2024 17:15
@renovate renovate bot force-pushed the renovate/npm-googleapis-vulnerability branch from df175c8 to 0bb382b Compare April 3, 2024 17:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants