From 03484df80a92a53742ea4a76ae7cd80d5ffcbc0b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 5 Jan 2024 17:20:48 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AXIOS-6144788 --- package.json | 2 +- yarn.lock | 24 +++++++++++++++++------- 2 files changed, 18 insertions(+), 8 deletions(-) diff --git a/package.json b/package.json index 6e5c18d1c3..5bde6f3c47 100644 --- a/package.json +++ b/package.json @@ -33,7 +33,7 @@ "@vuelidate/core": "^2.0.3", "@vuelidate/validators": "^2.0.4", "alpinejs": "^3.12.3", - "axios": "^1.6.3", + "axios": "^1.6.4", "blueimp-file-upload": "^10.32.0", "blueimp-load-image": "^5.16.0", "bootstrap-daterangepicker": "^3.1.0", diff --git a/yarn.lock b/yarn.lock index 57fa27fae5..8bda1e0ccb 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3217,14 +3217,14 @@ __metadata: languageName: node linkType: hard -"axios@npm:^1.6.3": - version: 1.6.3 - resolution: "axios@npm:1.6.3" +"axios@npm:^1.6.4": + version: 1.6.4 + resolution: "axios@npm:1.6.4" dependencies: - follow-redirects: ^1.15.0 + follow-redirects: ^1.15.4 form-data: ^4.0.0 proxy-from-env: ^1.1.0 - checksum: 07ef3bb83fc2dacc1ae2c97f2bbd04ef7701f5655f9037789d79ee78b698ffa50eaa8465c2017d4d3e9ce7d94cb779f730acaab32ce9036d0a4933c1e89df4da + checksum: 48d8af8488ac7402fae312437c0189b3b609a472fca2f7fc796129c804d98520589b6317096eba8509711d49f855a3f620b6a24ff23acd73ac26433d0383b8f9 languageName: node linkType: hard @@ -3644,7 +3644,7 @@ __metadata: "@vuelidate/validators": ^2.0.4 alpinejs: ^3.12.3 autoprefixer: ^10.4.16 - axios: ^1.6.3 + axios: ^1.6.4 blueimp-file-upload: ^10.32.0 blueimp-load-image: ^5.16.0 bootstrap-daterangepicker: ^3.1.0 @@ -5316,7 +5316,7 @@ __metadata: languageName: node linkType: hard -"follow-redirects@npm:^1.0.0, follow-redirects@npm:^1.15.0": +"follow-redirects@npm:^1.0.0": version: 1.15.3 resolution: "follow-redirects@npm:1.15.3" peerDependenciesMeta: @@ -5326,6 +5326,16 @@ __metadata: languageName: node linkType: hard +"follow-redirects@npm:^1.15.4": + version: 1.15.4 + resolution: "follow-redirects@npm:1.15.4" + peerDependenciesMeta: + debug: + optional: true + checksum: e178d1deff8b23d5d24ec3f7a94cde6e47d74d0dc649c35fc9857041267c12ec5d44650a0c5597ef83056ada9ea6ca0c30e7c4f97dbf07d035086be9e6a5b7b6 + languageName: node + linkType: hard + "foreground-child@npm:^3.1.0": version: 3.1.1 resolution: "foreground-child@npm:3.1.1"