From ac9f18447b203a731cb51e2750cabbe60a0888b8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 5 Oct 2022 22:10:08 +0000 Subject: [PATCH] fix: bower_components/bootstrap-datepicker/package.json & bower_components/bootstrap-datepicker/yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JQUERY-565129 - https://snyk.io/vuln/SNYK-JS-JQUERY-567880 --- bower_components/bootstrap-datepicker/package.json | 2 +- bower_components/bootstrap-datepicker/yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/bower_components/bootstrap-datepicker/package.json b/bower_components/bootstrap-datepicker/package.json index 8605e6b87e4..8a48bcea72d 100644 --- a/bower_components/bootstrap-datepicker/package.json +++ b/bower_components/bootstrap-datepicker/package.json @@ -25,7 +25,7 @@ "url": "https://github.com/uxsolutions/bootstrap-datepicker.git" }, "dependencies": { - "jquery": ">=1.7.1 <4.0.0" + "jquery": ">=3.5.0" }, "devDependencies": { "grunt": "^1.0.4", diff --git a/bower_components/bootstrap-datepicker/yarn.lock b/bower_components/bootstrap-datepicker/yarn.lock index 8ca0bec2972..430014e2030 100644 --- a/bower_components/bootstrap-datepicker/yarn.lock +++ b/bower_components/bootstrap-datepicker/yarn.lock @@ -1414,10 +1414,10 @@ isstream@0.1.x, isstream@~0.1.2: resolved "https://registry.yarnpkg.com/isstream/-/isstream-0.1.2.tgz#47e63f7af55afa6f92e1500e690eb8b8529c099a" integrity sha1-R+Y/evVa+m+S4VAOaQ64uFKcCZo= -"jquery@>=1.7.1 <4.0.0": - version "3.4.1" - resolved "https://registry.yarnpkg.com/jquery/-/jquery-3.4.1.tgz#714f1f8d9dde4bdfa55764ba37ef214630d80ef2" - integrity sha512-36+AdBzCL+y6qjw5Tx7HgzeGCzC81MDDgaUP8ld2zhx58HdqXGoBd+tHdrBMiyjGQs0Hxs/MLZTu/eHNJJuWPw== +jquery@>=3.5.0: + version "3.6.1" + resolved "https://registry.yarnpkg.com/jquery/-/jquery-3.6.1.tgz#fab0408f8b45fc19f956205773b62b292c147a16" + integrity sha512-opJeO4nCucVnsjiXOE+/PcCgYw9Gwpvs/a6B1LL/lQhwWwpbVEVYDZ1FokFr8PRc7ghYlrFPuyHuiiDNTQxmcw== js-yaml@~3.13.0: version "3.13.1"