Skip to content

feat!: add @itwin/service-authorization as a peer dependency of @itwin/oidc-signin-tool#345

Draft
ben-polinsky wants to merge 5 commits into
mainfrom
peers
Draft

feat!: add @itwin/service-authorization as a peer dependency of @itwin/oidc-signin-tool#345
ben-polinsky wants to merge 5 commits into
mainfrom
peers

Conversation

@ben-polinsky

Copy link
Copy Markdown
Collaborator

Consumers of @itwin/oidc-signin-tool should be able to use whichever version of @itwin/service-authorization they please. Thus, service-authorization is now a peer dep of signin tool.

@aruniverse

Copy link
Copy Markdown
Member

@paulius-valiunas @saskliutas can you guys review?

Comment thread packages/oidc-signin-tool/package.json
ben-polinsky and others added 3 commits April 17, 2026 14:30
- Update sinon from 15.x to 21.x (fixes path-to-regexp + diff transitives)
- Update @itwin/build-tools to 5.8.2 (lodash fixed once api-extractor catches up)
- Update vite from 6.4.1 to ^6.4.2 (fixes arbitrary file read + path traversal)
- Deep-update follow-redirects to 1.16.0 (fixes auth header leak)
- Override lodash >=4.18.0 (api-extractor pins ~4.17.23, can't reach in)
- Override diff >=8.0.3 (mocha pins ^7.0.0, can't reach in)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@anmolshres98

Copy link
Copy Markdown
Contributor

Relates to #344

@saskliutas saskliutas left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ben-polinsky ben-polinsky marked this pull request as draft April 23, 2026 15:52
@ben-polinsky

Copy link
Copy Markdown
Collaborator Author

We're not sure this is the correct fix or necessary. See #344

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants