Skip to content

chore(deps)(deps): bump @simplewebauthn/server from 13.3.3 to 14.0.3 - #271

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/simplewebauthn/server-14.0.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/simplewebauthn/server-14.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @simplewebauthn/server from 13.3.3 to 14.0.3.

Release notes

Sourced from @​simplewebauthn/server's releases.

v14.0.3

Changes:

  • [server] PQC support is now lazily evaluated. This delays Node from emitting its PQC warnings from when the Node process starts to when a method is called that checks for PQC support (#809)

v14.0.2

This update fixes a CVSS v3 Moderate (5.4) security vulnerability identified in @​simplewebauthn/server. See the security advisory linked below for more information.

Changes:

  • [server] Revamped certificate revocation logic to only cryptographically verify and process CRLs from certificates that chained back to an RP-chosen trust anchor (GHSA-2g3p-m8c9-hhwh)

v14.0.1

  • [server] Attestation statements using PQC algorithms can now be verified (#800)

v14.0.0 - The one after they go quantum

The headlining feature of this release is @​simplewebauthn/server gaining support for passkeys using the ML-DSA-44, ML-DSA-65, and ML-DSA-87 PQC algorithms in supported runtimes. And in those same supported runtimes, SimpleWebAuthn will automatically encourage registration of ML-DSA-44 passkeys to future-proof Relying Parties as PQC-capable FIDO2 authenticators and credential managers start coming to market. See https://simplewebauthn.dev/docs/advanced/server/pqc-ml-dsa-support for more info 🚀

Setting our sites on the browser, @​simplewebauthn/browser picks up a new sendSignal() method as a single method to call all of the WebAuthn Signal APIs. See https://simplewebauthn.dev/docs/packages/browser#sendsignal for more info 🛜

As for breaking changes, the minimum supported version of Node has been raised to Node LTS 22.x and higher, and Deno v2.4.x and higher. Going forward, SimpleWebAuthn will more formally aim to support Node LTS releases through their Active and Maintenance windows as tracked on the Node.js Releases page, and aim to support Deno minor releases for up to one year after their release

That's not all, though. Continue reading for the full list of changes in this release! 🎉

Changes:

Breaking Changes

  • [browser] [server] The minimum supported runtime versions have been increased to Node LTS 22.x and higher, and Deno v2.4.x and higher (#763)
Changelog

Sourced from @​simplewebauthn/server's changelog.

v14.0.3

Changes:

  • [server] PQC support is now lazily evaluated. This delays Node from emitting its PQC warnings from when the Node process starts to when a method is called that checks for PQC support (#809)

v14.0.2

This update fixes a CVSS v3 Moderate (5.4 / 10) and a CVSS v3 Moderate (6.3 / 10) security vulnerabilities identified in @​simplewebauthn/server. See the security advisory linked below for more information.

Changes:

  • [server] Revamped certificate revocation logic to only cryptographically verify and process CRLs from certificates that chained back to an RP-chosen trust anchor (GHSA-2g3p-m8c9-hhwh, GHSA-j3h4-m3m2-7p7j)

v14.0.1

Changes:

  • [server] Attestation statements using PQC algorithms can now be verified (#800)

v14.0.0 - The one after they go quantum

The headlining feature of this release is @​simplewebauthn/server gaining support for passkeys using the ML-DSA-44, ML-DSA-65, and ML-DSA-87 PQC algorithms in supported runtimes. And in those same supported runtimes, SimpleWebAuthn will automatically encourage registration of ML-DSA-44 passkeys to future-proof Relying Parties as PQC-capable FIDO2 authenticators and credential managers start coming to market. See https://simplewebauthn.dev/docs/advanced/server/pqc-ml-dsa-support for more info 🚀

Setting our sites on the browser, @​simplewebauthn/browser picks up a new sendSignal() method as a single method to call all of the WebAuthn Signal APIs. See https://simplewebauthn.dev/docs/packages/browser#sendsignal for more info 🛜

As for breaking changes, the minimum supported version of Node has been raised to Node LTS 22.x and higher, and Deno v2.4.x and higher. Going forward, SimpleWebAuthn will more formally aim to support Node LTS releases through their Active and Maintenance windows as tracked on the Node.js Releases page, and aim to support Deno minor releases for up to one year after their release

That's not all, though. Continue reading for the full list of changes in this release! 🎉

... (truncated)

Commits
  • 084e601 Update server version to v14.0.3
  • cd402cc Lazily evaluate PQC support to prevent Node warnings on startup (#809)
  • 7e3c4c4 Kinda makes more sense to do the AKI check first
  • 21f99a2 Update server version to v14.0.2
  • f03758a Merge commit from fork
  • 0bfdc3b Update server version to v14.0.1
  • 4831ce2 Fix X.509 parsing to support PQC use in attestation statements (#800)
  • 3e2dc0c Update version to v14.0.0
  • 618c0e9 Merge v14.0.0 milestone to master (#792)
  • See full diff in compare view

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: backend, frontend. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🔒 Supply Chain Security Review

Check Status
Socket.dev malware scan ✅ success
Vulnerability audit ✅ success
Lockfile diff review ✅ success
OSSF Scorecard ✅ success

This review was automatically generated by the Supply Chain Review workflow.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/simplewebauthn/server-14.0.2 branch from c79f1e0 to 7236260 Compare September 28, 2026 16:17
@github-actions

Copy link
Copy Markdown
Contributor

🔒 Supply Chain Security Review

Check Status
Socket.dev malware scan ✅ success
Vulnerability audit ✅ success
Lockfile diff review ✅ success
OSSF Scorecard ✅ success

This review was automatically generated by the Supply Chain Review workflow.

Bumps [@simplewebauthn/server](https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server) from 13.3.3 to 14.0.3.
- [Release notes](https://github.com/MasterKale/SimpleWebAuthn/releases)
- [Changelog](https://github.com/MasterKale/SimpleWebAuthn/blob/master/CHANGELOG.md)
- [Commits](https://github.com/MasterKale/SimpleWebAuthn/commits/v14.0.3/packages/server)

---
updated-dependencies:
- dependency-name: "@simplewebauthn/server"
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps)(deps): bump @simplewebauthn/server from 13.3.3 to 14.0.2 chore(deps)(deps): bump @simplewebauthn/server from 13.3.3 to 14.0.3 Oct 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/simplewebauthn/server-14.0.2 branch from 7236260 to 4ab8321 Compare October 9, 2026 18:30
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🔒 Supply Chain Security Review

Check Status
Socket.dev malware scan ✅ success
Vulnerability audit ✅ success
Lockfile diff review ✅ success
OSSF Scorecard ✅ success

This review was automatically generated by the Supply Chain Review workflow.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants