Skip to content

chore(deps): update dependency @simplewebauthn/server to v14 - #257

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/simplewebauthn-server-14.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/simplewebauthn-server-14.x

Conversation

@renovate

@renovate renovate Bot commented Sep 3, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@simplewebauthn/server (source) ^13.3.3 → ^14.0.3 age confidence

Release Notes

MasterKale/SimpleWebAuthn (@​simplewebauthn/server)

v14.0.3

Compare Source

Changes:

  • [server] PQC support is now lazily evaluated. This delays Node from emitting its PQC warnings
    from when the Node process starts to when a method is called that checks for PQC support
    (#​809)

v14.0.2

Compare Source

This update fixes a CVSS v3 Moderate (5.4 / 10) and a CVSS v3 Moderate (6.3 / 10) security
vulnerabilities identified in @​simplewebauthn/server. See the security advisory linked below for
more information.

Changes:

  • [server] Revamped certificate revocation logic to only cryptographically verify and process
    CRLs from certificates that chained back to an RP-chosen trust anchor
    (GHSA-2g3p-m8c9-hhwh,
    GHSA-j3h4-m3m2-7p7j)

v14.0.1

Compare Source

Changes:

  • [server] Attestation statements using PQC algorithms can now be verified
    (#​800)

v14.0.0

Compare Source

The headlining feature of this release is @​simplewebauthn/server gaining support for passkeys
using the ML-DSA-44, ML-DSA-65, and ML-DSA-87 PQC algorithms in supported runtimes. And in those
same supported runtimes, SimpleWebAuthn will automatically encourage registration of ML-DSA-44
passkeys to future-proof Relying Parties as PQC-capable FIDO2 authenticators and credential managers
start coming to market. See https://simplewebauthn.dev/docs/advanced/server/pqc-ml-dsa-support for
more info 🚀

Setting our sites on the browser, @​simplewebauthn/browser picks up a new sendSignal() method
as a single method to call all of the
WebAuthn Signal APIs. See
https://simplewebauthn.dev/docs/packages/browser#sendsignal for more info 🛜

As for breaking changes, the minimum supported version of Node has been raised to Node LTS 22.x
and higher
, and Deno v2.4.x and higher. Going forward, SimpleWebAuthn will more formally aim
to support Node LTS releases through their Active and Maintenance windows as tracked on
the Node.js Releases page, and aim to support Deno
minor releases for up to one year after their release

That's not all, though. Continue reading for the full list of changes in this release! 🎉

Changes:

Breaking Changes
  • [browser] [server] The minimum supported runtime versions have been increased to Node LTS 22.x
    and higher, and Deno v2.4.x and higher
    (#​763)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/simplewebauthn-server-14.x branch 3 times, most recently from 11690ac to f108da3 Compare September 10, 2026 05:29
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ea90ea01-4c37-4489-bf9f-4d0b1c1b931d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/simplewebauthn-server-14.x branch from f108da3 to 462e35f Compare September 14, 2026 06:00
@renovate
renovate Bot force-pushed the renovate/simplewebauthn-server-14.x branch 4 times, most recently from 87452f6 to 1e2fbe4 Compare October 1, 2026 03:41
@renovate
renovate Bot force-pushed the renovate/simplewebauthn-server-14.x branch from 1e2fbe4 to 9b1e6e7 Compare October 7, 2026 07:47

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants