Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps) Updated packages for security vulnerabilities #387

Open
wants to merge 17 commits into
base: develop
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
80ece5c
build(deps): bump yaml from 2.2.1 to 2.2.2 in /server/node-service
dependabot[bot] May 19, 2023
badc16c
Create renovate.json
sarvex May 19, 2023
b5388fd
build(deps): bump http-cache-semantics in /server/node-service
dependabot[bot] May 19, 2023
6ee3425
build(deps): bump vm2 from 3.9.14 to 3.9.19 in /server/node-service
dependabot[bot] May 19, 2023
aa56cdc
Merge pull request #4 from sarvex/dependabot/npm_and_yarn/server/node…
sarvex May 19, 2023
44d85cb
build(deps): bump json from 20200518 to 20230227 in /server/api-service
dependabot[bot] May 19, 2023
d798918
Merge pull request #7 from sarvex/dependabot/maven/server/api-service…
sarvex May 19, 2023
606be06
Merge pull request #6 from sarvex/dependabot/npm_and_yarn/server/node…
sarvex May 19, 2023
0b38824
Merge pull request #5 from sarvex/dependabot/npm_and_yarn/server/node…
sarvex May 19, 2023
e5d1334
build(deps): bump snowflake-jdbc
dependabot[bot] May 19, 2023
4d70946
build(deps-dev): bump spring-boot-starter-webflux
dependabot[bot] May 19, 2023
62f6803
Merge pull request #9 from sarvex/dependabot/maven/server/api-service…
sarvex May 19, 2023
9584eea
chore(deps): bump vm2 from 3.9.11 to 3.9.19 in /client
dependabot[bot] May 19, 2023
7575f53
Merge pull request #8 from sarvex/dependabot/maven/server/api-service…
sarvex May 19, 2023
81363dc
Merge pull request #3 from sarvex/dependabot/npm_and_yarn/client/vm2-…
sarvex May 19, 2023
696d4de
chore(deps): bump ua-parser-js from 1.0.2 to 1.0.33 in /client
dependabot[bot] May 19, 2023
dae0938
Merge pull request #10 from sarvex/dependabot/npm_and_yarn/client/ua-…
sarvex May 19, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion client/packages/openblocks/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -94,7 +94,7 @@
"tern": "^0.24.3",
"toposort": "^2.0.2",
"typescript-collections": "^1.3.3",
"ua-parser-js": "^1.0.2",
"ua-parser-js": "^1.0.33",
"uuid": "^9.0.0",
"web-vitals": "^2.1.0",
"weixin-js-sdk": "^1.6.0",
Expand Down
16 changes: 8 additions & 8 deletions client/yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -14546,7 +14546,7 @@ __metadata:
toposort: ^2.0.2
typescript: ^4.8.4
typescript-collections: ^1.3.3
ua-parser-js: ^1.0.2
ua-parser-js: ^1.0.33
uuid: ^9.0.0
vite: ^3.2.4
vite-plugin-checker: ^0.5.1
Expand Down Expand Up @@ -18909,10 +18909,10 @@ __metadata:
languageName: node
linkType: hard

"ua-parser-js@npm:^1.0.2":
version: 1.0.2
resolution: "ua-parser-js@npm:1.0.2"
checksum: ff7f6d79a9c1a38aa85a0e751040fc7e17a0b621bda876838d14ebe55aca4e50e68da0350f181e58801c2d8a35e7db4e12473776e558910c4b7cabcec96aa3bf
"ua-parser-js@npm:^1.0.33":
version: 1.0.35
resolution: "ua-parser-js@npm:1.0.35"
checksum: 02370d38a0c8b586f2503d1c3bbba5cbc0b97d407282f9023201a99e4c03eae4357a2800fdf50cf80d73ec25c0b0cc5bfbaa03975b0add4043d6e4c86712c9c1
languageName: node
linkType: hard

Expand Down Expand Up @@ -19535,14 +19535,14 @@ __metadata:
linkType: hard

"vm2@npm:^3.9.8":
version: 3.9.11
resolution: "vm2@npm:3.9.11"
version: 3.9.19
resolution: "vm2@npm:3.9.19"
dependencies:
acorn: ^8.7.0
acorn-walk: ^8.2.0
bin:
vm2: bin/vm2
checksum: aab39e6e4b59146d24abacd79f490e854a6e058a8b23d93d2be5aca7720778e2605d2cc028ccc4a5f50d3d91b0c38be9a6247a80d2da1a6de09425cc437770b4
checksum: fc6cf553134145cd7bb5246985bf242b056e3fb5ea71e2eef6710b2a5d6c6119cc6bc960435ff62480ee82efb43369be8f4db07b6690916ae7d3b2e714f395d8
languageName: node
linkType: hard

Expand Down
3 changes: 3 additions & 0 deletions renovate.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"extends": ["github>sarvex/renovate-configs:js-app"]
}
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-webflux</artifactId>
<version>2.5.5</version>
<version>2.5.12</version>
<scope>test</scope>
</dependency>
<dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@
<dependency>
<groupId>net.snowflake</groupId>
<artifactId>snowflake-jdbc</artifactId>
<version>3.13.27</version>
<version>3.13.29</version>
</dependency>
<dependency>
<groupId>com.openblocks</groupId>
Expand Down
2 changes: 1 addition & 1 deletion server/api-service/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,7 @@
<dependency>
<groupId>org.json</groupId>
<artifactId>json</artifactId>
<version>20200518</version>
<version>20230227</version>
</dependency>

<dependency>
Expand Down
2 changes: 1 addition & 1 deletion server/node-service/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@
"stylis": "^4.1.3",
"swagger-client": "^3.18.5",
"typescript": "^4.9.3",
"yaml": "^2.2.1"
"yaml": "^2.2.2"
},
"resolutions": {
"@apidevtools/json-schema-ref-parser": "9.0.7"
Expand Down
22 changes: 11 additions & 11 deletions server/node-service/yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -7272,9 +7272,9 @@ __metadata:
linkType: hard

"http-cache-semantics@npm:^4.1.0":
version: 4.1.0
resolution: "http-cache-semantics@npm:4.1.0::__archiveUrl=https%3A%2F%2Fregistry.npmjs.org%2Fhttp-cache-semantics%2F-%2Fhttp-cache-semantics-4.1.0.tgz"
checksum: 974de94a81c5474be07f269f9fd8383e92ebb5a448208223bfb39e172a9dbc26feff250192ecc23b9593b3f92098e010406b0f24bd4d588d631f80214648ed42
version: 4.1.1
resolution: "http-cache-semantics@npm:4.1.1"
checksum: 83ac0bc60b17a3a36f9953e7be55e5c8f41acc61b22583060e8dedc9dd5e3607c823a88d0926f9150e571f90946835c7fe150732801010845c72cd8bbff1a236
languageName: node
linkType: hard

Expand Down Expand Up @@ -10444,7 +10444,7 @@ __metadata:
ts-jest: ^29.0.3
ts-node: ^10.9.1
typescript: ^4.9.3
yaml: ^2.2.1
yaml: ^2.2.2
languageName: unknown
linkType: soft

Expand Down Expand Up @@ -10951,14 +10951,14 @@ __metadata:
linkType: hard

"vm2@npm:^3.9.8":
version: 3.9.14
resolution: "vm2@npm:3.9.14"
version: 3.9.19
resolution: "vm2@npm:3.9.19"
dependencies:
acorn: ^8.7.0
acorn-walk: ^8.2.0
bin:
vm2: bin/vm2
checksum: 1ed7481e07ce8e03055101b382bfbf0d725a5c9b9bbe8bf75f71501cb43a6bd22f6a0a151975ff7cea8cad136d47e66d64f0a3248913f6d3ca3c405db12bacc0
checksum: fc6cf553134145cd7bb5246985bf242b056e3fb5ea71e2eef6710b2a5d6c6119cc6bc960435ff62480ee82efb43369be8f4db07b6690916ae7d3b2e714f395d8
languageName: node
linkType: hard

Expand Down Expand Up @@ -11138,10 +11138,10 @@ __metadata:
languageName: node
linkType: hard

"yaml@npm:^2.2.1":
version: 2.2.1
resolution: "yaml@npm:2.2.1::__archiveUrl=https%3A%2F%2Fregistry.npmjs.org%2Fyaml%2F-%2Fyaml-2.2.1.tgz"
checksum: 84f68cbe462d5da4e7ded4a8bded949ffa912bc264472e5a684c3d45b22d8f73a3019963a32164023bdf3d83cfb6f5b58ff7b2b10ef5b717c630f40bd6369a23
"yaml@npm:^2.2.2":
version: 2.2.2
resolution: "yaml@npm:2.2.2"
checksum: d90c235e099e30094dcff61ba3350437aef53325db4a6bcd04ca96e1bfe7e348b191f6a7a52b5211e2dbc4eeedb22a00b291527da030de7c189728ef3f2b4eb3
languageName: node
linkType: hard

Expand Down