Skip to content

Bump asn1js from 3.0.7 to 3.0.10#29

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/asn1js-3.0.10
Open

Bump asn1js from 3.0.7 to 3.0.10#29
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/asn1js-3.0.10

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 21, 2026

Bumps asn1js from 3.0.7 to 3.0.10.

Release notes

Sourced from asn1js's releases.

Release v3.0.10

What's Changed

  • Added parser limits to asn1js.fromBER() to prevent unbounded BER parsing.
  • Optimized long-form ASN.1 tag parsing to avoid quadratic buffer growth.

Full Changelog: PeculiarVentures/ASN1.js@v3.0.9...v3.0.10

Commits
  • 0722d02 3.0.10
  • 59666e5 chore: update permissions in publish workflow and restore GitHub release step
  • aa62c50 chore: update Node.js version in publish workflow and fix repository URL form...
  • 6afa618 chore: update permissions in publish workflow and comment out GitHub release ...
  • 0f3cd19 chore: fix repository URL case sensitivity in package.json and update publish...
  • 6162ac3 chore: update repository URL format in package.json
  • 3eec918 chore: update repository URL format in package.json
  • ce8d309 ci(publish): update publish workflow to use simplified tag pattern and remove...
  • 6be3d0d chore: update repository URL format in package.json
  • b900d32 ci(publish): use npm Trusted Publisher
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for asn1js since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [asn1js](https://github.com/PeculiarVentures/ASN1.js) from 3.0.7 to 3.0.10.
- [Release notes](https://github.com/PeculiarVentures/ASN1.js/releases)
- [Commits](PeculiarVentures/ASN1.js@v3.0.7...v3.0.10)

---
updated-dependencies:
- dependency-name: asn1js
  dependency-version: 3.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants