Skip to content

Bump auth0-js to v10#2797

Open
OWConnoi wants to merge 1 commit into
auth0:masterfrom
OWConnoi:codex/bump-auth0-js-10
Open

Bump auth0-js to v10#2797
OWConnoi wants to merge 1 commit into
auth0:masterfrom
OWConnoi:codex/bump-auth0-js-10

Conversation

@OWConnoi
Copy link
Copy Markdown

What

This bumps the production auth0-js dependency from ^9.29.0 to ^10.0.0.

Why

The current range resolves to auth0-js@9.32.0, which is covered by the public high-severity advisory GHSA-8qjv-jj2q-x832 / CWE-863. Updating to v10 clears the production dependency advisory for Lock.

Tests

  • npm audit --omit=dev --json
  • npm test -- src/__tests__/core/web_api/p2_api.test.js src/__tests__/core/web_api.test.js src/__tests__/core/actions.test.js

Note: Full npm audit still reports dev dependency vulnerabilities; the production-only audit is clean.

@OWConnoi OWConnoi requested a review from a team as a code owner May 11, 2026 22:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant