Skip to content

Bump jsrsasign from 11.1.0 to 11.1.1 - #6122

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/jsrsasign-11.1.1
Open

Bump jsrsasign from 11.1.0 to 11.1.1#6122
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/jsrsasign-11.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps jsrsasign from 11.1.0 to 11.1.1.

Changelog

Sourced from jsrsasign's changelog.

ChangeLog for jsrsasign

  • Changes from 11.1.2 to 11.1.3 (2026-Apr-18)

    • base64x.js
      • timingSafeEqual and timingSafeEqualImpl added
    • jws.js
      • modified to use timingSafeEqual for HS* signature verification
    • Security fixes:
    • bugfix
      • jws.js
        • wrong thumbprint calculation for symmetric key (KJUR.jws.JWS.getJWKthumbprint) reported in issue #656 by @​e3stpavel.
  • Changes from 11.1.1 to 11.1.2 (2026-Apr-12)

    • Security fixes:
      • HIGH: wrong random for for Node.JS >= 19 and modern browsers (ext/rng.js SecureRandom) reported by Bronson Yen of Calif.io and @​Kr0emer #655.
      • HIGH: ASN.1 Parser Infinite Loop (asn1hex.js) getChildIdx fix to avoid infinite loop reported by Koda Reef.
      • HIGH: DSA Universal Signature Forgery (dsa.js) FIPS 186-4 section 4.7 wrong boundary checking in verifyWithMessageHash reported by Koda Reef, Nicholas Carlini and @​Kr0emer.
      • ASN1HEX.getChildIdx DoS (asn1hex.js) getChildIdx may raise DoS because of lacking value length check reported by Yt(yutengsun) and Franciny S Roj.
      • missing JWS crit header parameter validation (jws.js) as reported by Franciny S Roj. Thank you indeed for those vulnerability reports and/or patches.
  • Changes from 11.1.0 to 11.1.1 (2026-Feb-20)

restore KJUR.crypto.Cipher class without RSA/RSAOAEP support

  • Changes from 11.0.0 to 11.1.0 (2024-Feb-01)
    • src/crypto.js
      • restore KJUR.crypto.Cipher class without RSA and RSAOAEP encryption/decryption support

remove RSA and RSAOAEP encryption for Marvin attack

  • Changes from 10.9.0 to 11.0.0 (2024-Jan-16)
    • Major Changes:
      • Stop to support Internet Explorer.
      • Stop to support bower.
      • Modern ECMA functions will be introduced such as Promise, let, Array methods or class.
      • API document generator will be changed from Jsdoc Toolkit to JSDoc3.
      • Module bandler will be used such as browserify or webpack.

... (truncated)

Commits
  • e2b136e 11.1.1 release
  • e2e417e Merge pull request #641 from njg7194/add-security-policy
  • 77f1776 Merge pull request #651 from Kr0emer/fix/bug-007-isprobableprime-negative
  • 5ea1c32 Merge pull request #650 from Kr0emer/fix/bug-006-modpow-negative-exponent
  • ee4b013 Merge pull request #647 from Kr0emer/fix/bug-003-dsa-nonce-compareto
  • 37b4c06 Merge pull request #646 from Kr0emer/fix/bug-002-dsa-domain-params-validation
  • d89f0ec fix(crypto): correct compareTo checks in BigInteger RNG helpers
  • 02fa75d fix(jsbn2): reject non-positive values in primality checks
  • f508ddd Merge branch 'master' into fix/bug-002-dsa-domain-params-validation
  • ca5b027 Merge pull request #648 from Kr0emer/fix/bug-004-modinverse-dos
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 27, 2026
@socket-security

socket-security Bot commented Jul 27, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedjsrsasign@​11.1.0 ⏵ 11.1.1100 +1100 +75100 +182100

View full report

Bumps [jsrsasign](https://github.com/kjur/jsrsasign) from 11.1.0 to 11.1.1.
- [Release notes](https://github.com/kjur/jsrsasign/releases)
- [Changelog](https://github.com/kjur/jsrsasign/blob/master/ChangeLog.txt)
- [Commits](kjur/jsrsasign@11.1.0...11.1.1)

---
updated-dependencies:
- dependency-name: jsrsasign
  dependency-version: 11.1.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/jsrsasign-11.1.1 branch from 8eb10cb to 5061c32 Compare August 2, 2026 17:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants