Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Package update #705

Merged
merged 9 commits into from May 13, 2024
Merged

Conversation

Zathiel
Copy link
Collaborator

@Zathiel Zathiel commented May 8, 2024

Hello @prafull-opensignlabs

New PR for security issues

[WeaknessCWE-1321] (https://cwe.mitre.org/data/definitions/1321.html) [MODERATE]
[WeaknessCWE-400] (https://cwe.mitre.org/data/definitions/400.html) [MODERATE]
[WeaknessCWE-22] (https://cwe.mitre.org/data/definitions/22.html) [HIGH]
[WeaknessCWE-79] (https://cwe.mitre.org/data/definitions/79.html) [HIGH]

Regards

dependabot bot and others added 8 commits May 7, 2024 02:24
Bumps [ejs](https://github.com/mde/ejs) from 3.1.9 to 3.1.10.
- [Release notes](https://github.com/mde/ejs/releases)
- [Commits](mde/ejs@v3.1.9...v3.1.10)

---
updated-dependencies:
- dependency-name: ejs
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/isaacs/node-tar) from 6.2.0 to 6.2.1.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v6.2.0...v6.2.1)

---
updated-dependencies:
- dependency-name: tar
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [webpack-dev-middleware](https://github.com/webpack/webpack-dev-middleware) from 5.3.3 to 5.3.4.
- [Release notes](https://github.com/webpack/webpack-dev-middleware/releases)
- [Changelog](https://github.com/webpack/webpack-dev-middleware/blob/v5.3.4/CHANGELOG.md)
- [Commits](webpack/webpack-dev-middleware@v5.3.3...v5.3.4)

---
updated-dependencies:
- dependency-name: webpack-dev-middleware
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [react-pdf](https://github.com/wojtekmaj/react-pdf/tree/HEAD/packages/react-pdf) from 7.7.1 to 7.7.3.
- [Release notes](https://github.com/wojtekmaj/react-pdf/releases)
- [Commits](https://github.com/wojtekmaj/react-pdf/commits/v7.7.3/packages/react-pdf)

---
updated-dependencies:
- dependency-name: react-pdf
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…Sign/react-pdf-7.7.3

build(deps): bump react-pdf from 7.7.1 to 7.7.3 in /apps/OpenSign
…Sign/webpack-dev-middleware-5.3.4

build(deps): bump webpack-dev-middleware from 5.3.3 to 5.3.4 in /apps/OpenSign
…Sign/tar-6.2.1

build(deps): bump tar from 6.2.0 to 6.2.1 in /apps/OpenSign
…Sign/ejs-3.1.10

build(deps): bump ejs from 3.1.9 to 3.1.10 in /apps/OpenSign
Copy link

vercel bot commented May 8, 2024

@Zathiel is attempting to deploy a commit to the OpenSign's projects Team on Vercel.

A member of the Team first needs to authorize it.

@Zathiel Zathiel marked this pull request as ready for review May 8, 2024 21:40
@prafull-opensignlabs prafull-opensignlabs merged commit e15136c into OpenSignLabs:staging May 13, 2024
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants