Skip to content

chore(deps): bump @simplewebauthn/server from 13.3.3 to 14.0.3 - #362

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/simplewebauthn/server-14.0.3
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/simplewebauthn/server-14.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @simplewebauthn/server from 13.3.3 to 14.0.3.

Release notes

Sourced from @鈥媠implewebauthn/server's releases.

v14.0.3

Changes:

  • [server] PQC support is now lazily evaluated. This delays Node from emitting its PQC warnings from when the Node process starts to when a method is called that checks for PQC support (#809)

v14.0.2

This update fixes a CVSS v3 Moderate (5.4) security vulnerability identified in @鈥媠implewebauthn/server. See the security advisory linked below for more information.

Changes:

  • [server] Revamped certificate revocation logic to only cryptographically verify and process CRLs from certificates that chained back to an RP-chosen trust anchor (GHSA-2g3p-m8c9-hhwh)

v14.0.1

  • [server] Attestation statements using PQC algorithms can now be verified (#800)

v14.0.0 - The one after they go quantum

The headlining feature of this release is @鈥媠implewebauthn/server gaining support for passkeys using the ML-DSA-44, ML-DSA-65, and ML-DSA-87 PQC algorithms in supported runtimes. And in those same supported runtimes, SimpleWebAuthn will automatically encourage registration of ML-DSA-44 passkeys to future-proof Relying Parties as PQC-capable FIDO2 authenticators and credential managers start coming to market. See https://simplewebauthn.dev/docs/advanced/server/pqc-ml-dsa-support for more info 馃殌

Setting our sites on the browser, @鈥媠implewebauthn/browser picks up a new sendSignal() method as a single method to call all of the WebAuthn Signal APIs. See https://simplewebauthn.dev/docs/packages/browser#sendsignal for more info 馃洔

As for breaking changes, the minimum supported version of Node has been raised to Node LTS 22.x and higher, and Deno v2.4.x and higher. Going forward, SimpleWebAuthn will more formally aim to support Node LTS releases through their Active and Maintenance windows as tracked on the Node.js Releases page, and aim to support Deno minor releases for up to one year after their release

That's not all, though. Continue reading for the full list of changes in this release! 馃帀

Changes:

Breaking Changes

  • [browser] [server] The minimum supported runtime versions have been increased to Node LTS 22.x and higher, and Deno v2.4.x and higher (#763)
Changelog

Sourced from @鈥媠implewebauthn/server's changelog.

v14.0.3

Changes:

  • [server] PQC support is now lazily evaluated. This delays Node from emitting its PQC warnings from when the Node process starts to when a method is called that checks for PQC support (#809)

v14.0.2

This update fixes a CVSS v3 Moderate (5.4 / 10) and a CVSS v3 Moderate (6.3 / 10) security vulnerabilities identified in @鈥媠implewebauthn/server. See the security advisory linked below for more information.

Changes:

  • [server] Revamped certificate revocation logic to only cryptographically verify and process CRLs from certificates that chained back to an RP-chosen trust anchor (GHSA-2g3p-m8c9-hhwh, GHSA-j3h4-m3m2-7p7j)

v14.0.1

Changes:

  • [server] Attestation statements using PQC algorithms can now be verified (#800)

v14.0.0 - The one after they go quantum

The headlining feature of this release is @鈥媠implewebauthn/server gaining support for passkeys using the ML-DSA-44, ML-DSA-65, and ML-DSA-87 PQC algorithms in supported runtimes. And in those same supported runtimes, SimpleWebAuthn will automatically encourage registration of ML-DSA-44 passkeys to future-proof Relying Parties as PQC-capable FIDO2 authenticators and credential managers start coming to market. See https://simplewebauthn.dev/docs/advanced/server/pqc-ml-dsa-support for more info 馃殌

Setting our sites on the browser, @鈥媠implewebauthn/browser picks up a new sendSignal() method as a single method to call all of the WebAuthn Signal APIs. See https://simplewebauthn.dev/docs/packages/browser#sendsignal for more info 馃洔

As for breaking changes, the minimum supported version of Node has been raised to Node LTS 22.x and higher, and Deno v2.4.x and higher. Going forward, SimpleWebAuthn will more formally aim to support Node LTS releases through their Active and Maintenance windows as tracked on the Node.js Releases page, and aim to support Deno minor releases for up to one year after their release

That's not all, though. Continue reading for the full list of changes in this release! 馃帀

... (truncated)

Commits
  • 084e601 Update server version to v14.0.3
  • cd402cc Lazily evaluate PQC support to prevent Node warnings on startup (#809)
  • 7e3c4c4 Kinda makes more sense to do the AKI check first
  • 21f99a2 Update server version to v14.0.2
  • f03758a Merge commit from fork
  • 0bfdc3b Update server version to v14.0.1
  • 4831ce2 Fix X.509 parsing to support PQC use in attestation statements (#800)
  • 3e2dc0c Update version to v14.0.0
  • 618c0e9 Merge v14.0.0 milestone to master (#792)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@simplewebauthn/server](https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server) from 13.3.3 to 14.0.3.
- [Release notes](https://github.com/MasterKale/SimpleWebAuthn/releases)
- [Changelog](https://github.com/MasterKale/SimpleWebAuthn/blob/master/CHANGELOG.md)
- [Commits](https://github.com/MasterKale/SimpleWebAuthn/commits/v14.0.3/packages/server)

---
updated-dependencies:
- dependency-name: "@simplewebauthn/server"
  dependency-version: 14.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants