From d42a313ce057217e564dcf76233214d09a0c67b7 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 10 Jan 2022 21:26:22 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-1018905 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724 - https://snyk.io/vuln/SNYK-JS-LODASH-450202 - https://snyk.io/vuln/SNYK-JS-LODASH-567746 - https://snyk.io/vuln/SNYK-JS-LODASH-590103 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASH-73638 - https://snyk.io/vuln/SNYK-JS-LODASH-73639 - https://snyk.io/vuln/npm:lodash:20180130 --- package-lock.json | 41 +++++++++++++++++++---------------------- package.json | 2 +- 2 files changed, 20 insertions(+), 23 deletions(-) diff --git a/package-lock.json b/package-lock.json index 1de0cde..3d2e705 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1356,41 +1356,38 @@ "dev": true }, "packity": { - "version": "0.3.2", - "resolved": "https://registry.npmjs.org/packity/-/packity-0.3.2.tgz", - "integrity": "sha1-IFZoYaPvJEKObVBfxULfRS5+kwM=", + "version": "0.3.3", + "resolved": "https://registry.npmjs.org/packity/-/packity-0.3.3.tgz", + "integrity": "sha512-qeUVup8CV0noEm+yzykI8IhKukb1mVy+/DffYFAgYsThI76LJ+V6F/y7WuSYy69kscNBWaKp9L90JDUiJ1+Hsw==", "dev": true, "requires": { - "async": "^1.4.2", - "colors": "^1.1.2", + "async": "^2.1.4", + "colors": "1.4.0", "commander": "^2.9.0", - "lodash": "^3.10.1", + "lodash": "^4.17.2", "readdir": "^0.0.13", "semver": "^5.0.3" }, "dependencies": { "async": { - "version": "1.5.2", - "resolved": "https://registry.npmjs.org/async/-/async-1.5.2.tgz", - "integrity": "sha1-7GphrlZIDAw8skHJVhjiCJL5Zyo=", - "dev": true + "version": "2.6.3", + "resolved": "https://registry.npmjs.org/async/-/async-2.6.3.tgz", + "integrity": "sha512-zflvls11DCy+dQWzTW2dzuilv8Z5X/pjfmZOWba6TNIVDm+2UDaJmXSOXlasHKfNBs8oo3M0aT50fDEWfKZjXg==", + "dev": true, + "requires": { + "lodash": "^4.17.14" + } }, "commander": { - "version": "2.20.0", - "resolved": "https://registry.npmjs.org/commander/-/commander-2.20.0.tgz", - "integrity": "sha512-7j2y+40w61zy6YC2iRNpUe/NwhNyoXrYpHMrSunaMG64nRnaf96zO/KMQR4OyN/UnE5KLyEBnKHd4aG3rskjpQ==", - "dev": true - }, - "lodash": { - "version": "3.10.1", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-3.10.1.tgz", - "integrity": "sha1-W/Rejkm6QYnhfUgnid/RW9FAt7Y=", + "version": "2.20.3", + "resolved": "https://registry.npmjs.org/commander/-/commander-2.20.3.tgz", + "integrity": "sha512-GpVkmM8vF2vQUkj2LvZmD35JxeJOLCwJ9cUkugyk2nuhbv3+mJvpLYYt+0+USMxE+oj+ey/lJEnhZw75x/OMcQ==", "dev": true }, "semver": { - "version": "5.7.0", - "resolved": "https://registry.npmjs.org/semver/-/semver-5.7.0.tgz", - "integrity": "sha512-Ya52jSX2u7QKghxeoFGpLwCtGlt7j0oY9DYb5apt9nPlJ42ID+ulTXESnt/qAQcoSERyZ5sl3LDIOw0nAn/5DA==", + "version": "5.7.1", + "resolved": "https://registry.npmjs.org/semver/-/semver-5.7.1.tgz", + "integrity": "sha512-sauaDf/PZdVgrLTNYHRtpXa1iRiKcaebiKQ1BJdpQlWH2lCvexQdX55snPFyK7QzpudqbCI0qXFfOasHdyNDGQ==", "dev": true } } diff --git a/package.json b/package.json index 4790ffb..f140a86 100644 --- a/package.json +++ b/package.json @@ -49,7 +49,7 @@ "eslint-plugin-security": "1.4.0", "js-yaml": "3.14.0", "mocha": "8.1.3", - "packity": "0.3.2", + "packity": "0.3.3", "parse-gitignore": "1.0.1", "pretty-ms": "7.0.0", "recursive-readdir": "2.2.2",