Skip to content

Commit 0305e87

Browse files
committed
fix: force request to use @cypress/[email protected] to address security vulnerability
Updates package.json resolutions to use @cypress/[email protected] instead of the deprecated request package. This addresses the security vulnerability GHSA-p8p7-x288-28g6 TICKET: DX-1558
1 parent 1a34ab8 commit 0305e87

File tree

2 files changed

+15
-78
lines changed

2 files changed

+15
-78
lines changed

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -100,7 +100,8 @@
100100
"**/ethers/**/ws": "7.5.10",
101101
"**/swarm-js/**/ws": "5.2.4",
102102
"serialize-javascript": "^6.0.2",
103-
"@grpc/grpc-js": "^1.12.6"
103+
"@grpc/grpc-js": "^1.12.6",
104+
"request": "npm:@cypress/[email protected]"
104105
},
105106
"workspaces": [
106107
"modules/*"

yarn.lock

Lines changed: 13 additions & 77 deletions
Original file line numberDiff line numberDiff line change
@@ -7028,7 +7028,7 @@ ajv-keywords@^5.1.0:
70287028
dependencies:
70297029
fast-deep-equal "^3.1.3"
70307030

7031-
ajv@^6.10.0, ajv@^6.12.3, ajv@^6.12.4, ajv@^6.12.5:
7031+
ajv@^6.10.0, ajv@^6.12.4, ajv@^6.12.5:
70327032
version "6.12.6"
70337033
resolved "https://registry.npmjs.org/ajv/-/ajv-6.12.6.tgz"
70347034
integrity sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g==
@@ -11829,7 +11829,7 @@ [email protected]:
1182911829
resolved "https://registry.npmjs.org/forge-light/-/forge-light-1.1.4.tgz#765da0d54e19c6644f37e7e5b873e1305ce78d1e"
1183011830
integrity sha512-Nr0xdu93LJawgBZVU/tC+A+4pbKqigdY5PRBz8CXNm4e5saAZIqU2Qe9+nVFtVO5TWCHSgvI0LaZZuatgE5J1g==
1183111831

11832-
form-data@^2.3.1, form-data@^4.0.0, form-data@^4.0.4, form-data@~2.3.2, form-data@~4.0.4:
11832+
form-data@^2.3.1, form-data@^4.0.0, form-data@^4.0.4, form-data@~4.0.4:
1183311833
version "4.0.4"
1183411834
resolved "https://registry.npmjs.org/form-data/-/form-data-4.0.4.tgz"
1183511835
integrity sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==
@@ -12443,19 +12443,6 @@ handlebars@^4.7.7:
1244312443
optionalDependencies:
1244412444
uglify-js "^3.1.4"
1244512445

12446-
har-schema@^2.0.0:
12447-
version "2.0.0"
12448-
resolved "https://registry.npmjs.org/har-schema/-/har-schema-2.0.0.tgz"
12449-
integrity sha512-Oqluz6zhGX8cyRaTQlFMPw80bSJVG2x/cFb8ZPhUILGgHka9SsokCCOQgpveePerqidZOrT14ipqfJb7ILcW5Q==
12450-
12451-
har-validator@~5.1.3:
12452-
version "5.1.5"
12453-
resolved "https://registry.npmjs.org/har-validator/-/har-validator-5.1.5.tgz"
12454-
integrity sha512-nmT2T0lljbxdQZfspsno9hgrG3Uir6Ks5afism62poxqBM6sDnMEuPmzTq8XN0OEwqKLLdh1jQI3qyE66Nzb3w==
12455-
dependencies:
12456-
ajv "^6.12.3"
12457-
har-schema "^2.0.0"
12458-
1245912446
hard-rejection@^2.1.0:
1246012447
version "2.1.0"
1246112448
resolved "https://registry.npmjs.org/hard-rejection/-/hard-rejection-2.1.0.tgz"
@@ -12851,15 +12838,6 @@ http-proxy@^1.18.1:
1285112838
follow-redirects "^1.0.0"
1285212839
requires-port "^1.0.0"
1285312840

12854-
http-signature@~1.2.0:
12855-
version "1.2.0"
12856-
resolved "https://registry.npmjs.org/http-signature/-/http-signature-1.2.0.tgz"
12857-
integrity sha512-CAbnr6Rz4CYQkLYUtSNXxQPUH2gK8f3iWexVlsnMeD+GjlsQ0Xsy1cOX+mN3dtxYomRy21CiOzU8Uhw6OwncEQ==
12858-
dependencies:
12859-
assert-plus "^1.0.0"
12860-
jsprim "^1.2.2"
12861-
sshpk "^1.7.0"
12862-
1286312841
http-signature@~1.4.0:
1286412842
version "1.4.0"
1286512843
resolved "https://registry.npmjs.org/http-signature/-/http-signature-1.4.0.tgz"
@@ -14109,16 +14087,6 @@ jspdf@^3.0.2:
1410914087
dompurify "^3.2.4"
1411014088
html2canvas "^1.0.0-rc.5"
1411114089

14112-
jsprim@^1.2.2:
14113-
version "1.4.2"
14114-
resolved "https://registry.npmjs.org/jsprim/-/jsprim-1.4.2.tgz"
14115-
integrity sha512-P2bSOMAc/ciLz6DzgjVlGJP9+BrJWu5UDGK70C2iweC5QBIeFf0ZXRvGjEj2uYgrY2MkAAhsSWHDWlFtEroZWw==
14116-
dependencies:
14117-
assert-plus "1.0.0"
14118-
extsprintf "1.3.0"
14119-
json-schema "0.4.0"
14120-
verror "1.10.0"
14121-
1412214090
jsprim@^2.0.2:
1412314091
version "2.0.2"
1412414092
resolved "https://registry.npmjs.org/jsprim/-/jsprim-2.0.2.tgz"
@@ -16085,11 +16053,6 @@ nyc@^15.0.0, nyc@^15.1.0:
1608516053
test-exclude "^6.0.0"
1608616054
yargs "^15.0.2"
1608716055

16088-
oauth-sign@~0.9.0:
16089-
version "0.9.0"
16090-
resolved "https://registry.npmjs.org/oauth-sign/-/oauth-sign-0.9.0.tgz"
16091-
integrity sha512-fexhUFFPTGV8ybAtSIGbV6gOkSv8UtRbDBnAyLQw4QPKkgNlsH2ByPGtMUqdWkos6YCRmAqViwgZrJc/mRDzZQ==
16092-
1609316056
object-assign@^4, object-assign@^4.0.1, object-assign@^4.1.0, object-assign@^4.1.1:
1609416057
version "4.1.1"
1609516058
resolved "https://registry.npmjs.org/object-assign/-/object-assign-4.1.1.tgz"
@@ -17495,13 +17458,6 @@ proxyquire@^2.1.3:
1749517458
module-not-found-error "^1.0.1"
1749617459
resolve "^1.11.1"
1749717460

17498-
psl@^1.1.28:
17499-
version "1.15.0"
17500-
resolved "https://registry.npmjs.org/psl/-/psl-1.15.0.tgz"
17501-
integrity sha512-JZd3gMVBAVQkSs6HdNZo9Sdo0LNcQeMNP3CozBJb3JYC/QUYZTnKxP+f8oWRX4rHP5EurWxqAHTSwUCjlNKa1w==
17502-
dependencies:
17503-
punycode "^2.3.1"
17504-
1750517461
public-encrypt@^4.0.0, public-encrypt@^4.0.3:
1750617462
version "4.0.3"
1750717463
resolved "https://registry.npmjs.org/public-encrypt/-/public-encrypt-4.0.3.tgz"
@@ -17542,7 +17498,7 @@ punycode@^1.3.2, punycode@^1.4.1:
1754217498
resolved "https://registry.npmjs.org/punycode/-/punycode-1.4.1.tgz"
1754317499
integrity sha512-jmYNElW7yvO7TV33CjSmvSiE2yco3bV2czu/OzDKdMNVZQWfxCblURLhf+47syQRBntjfLdd/H0egrzIG+oaFQ==
1754417500

17545-
punycode@^2.1.0, punycode@^2.1.1, punycode@^2.3.1:
17501+
punycode@^2.1.0, punycode@^2.1.1:
1754617502
version "2.3.1"
1754717503
resolved "https://registry.npmjs.org/punycode/-/punycode-2.3.1.tgz"
1754817504
integrity sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==
@@ -17613,11 +17569,6 @@ [email protected], qs@^6.11.0, qs@^6.11.2, qs@^6.12.3, qs@^6.5.1:
1761317569
dependencies:
1761417570
side-channel "^1.1.0"
1761517571

17616-
qs@~6.5.2:
17617-
version "6.5.3"
17618-
resolved "https://registry.npmjs.org/qs/-/qs-6.5.3.tgz"
17619-
integrity sha512-qxXIEh4pCGfHICj1mAJQ2/2XVZkjCDTcEgfoSQxc/fYivUZxTkk7L3bDBJSoNrEzXI17oUO5Dp07ktqE5KzczA==
17620-
1762117572
query-string@^5.0.1:
1762217573
version "5.1.1"
1762317574
resolved "https://registry.npmjs.org/query-string/-/query-string-5.1.1.tgz"
@@ -18088,31 +18039,29 @@ request-progress@^3.0.0:
1808818039
dependencies:
1808918040
throttleit "^1.0.0"
1809018041

18091-
request@^2.79.0:
18092-
version "2.88.2"
18093-
resolved "https://registry.npmjs.org/request/-/request-2.88.2.tgz"
18094-
integrity sha512-MsvtOrfG9ZcrOwAW+Qi+F6HbD0CWXEh9ou77uOb7FM2WPhwT7smM833PzanhJLsgXjN89Ir6V2PczXNnMpwKhw==
18042+
request@^2.79.0, "request@npm:@cypress/[email protected]":
18043+
version "3.0.9"
18044+
resolved "https://registry.npmjs.org/@cypress/request/-/request-3.0.9.tgz#8ed6e08fea0c62998b5552301023af7268f11625"
18045+
integrity sha512-I3l7FdGRXluAS44/0NguwWlO83J18p0vlr2FYHrJkWdNYhgVoiYo61IXPqaOsL+vNxU1ZqMACzItGK3/KKDsdw==
1809518046
dependencies:
1809618047
aws-sign2 "~0.7.0"
1809718048
aws4 "^1.8.0"
1809818049
caseless "~0.12.0"
1809918050
combined-stream "~1.0.6"
1810018051
extend "~3.0.2"
1810118052
forever-agent "~0.6.1"
18102-
form-data "~2.3.2"
18103-
har-validator "~5.1.3"
18104-
http-signature "~1.2.0"
18053+
form-data "~4.0.4"
18054+
http-signature "~1.4.0"
1810518055
is-typedarray "~1.0.0"
1810618056
isstream "~0.1.2"
1810718057
json-stringify-safe "~5.0.1"
1810818058
mime-types "~2.1.19"
18109-
oauth-sign "~0.9.0"
1811018059
performance-now "^2.1.0"
18111-
qs "~6.5.2"
18060+
qs "6.14.0"
1811218061
safe-buffer "^5.1.2"
18113-
tough-cookie "~2.5.0"
18062+
tough-cookie "^5.0.0"
1811418063
tunnel-agent "^0.6.0"
18115-
uuid "^3.3.2"
18064+
uuid "^8.3.2"
1811618065

1811718066
require-directory@^2.1.1:
1811818067
version "2.1.1"
@@ -19197,7 +19146,7 @@ sprintf-js@~1.0.2:
1919719146
resolved "https://registry.npmjs.org/sprintf-js/-/sprintf-js-1.0.3.tgz"
1919819147
integrity sha512-D9cPgkvLlV3t3IzL0D0YLvGA9Ahk4PcvVwUbN0dSGr1aP0Nrt4AEnTUbuGvquEC0mA64Gqt1fzirlRs5ibXx8g==
1919919148

19200-
sshpk@^1.18.0, sshpk@^1.7.0:
19149+
sshpk@^1.18.0:
1920119150
version "1.18.0"
1920219151
resolved "https://registry.npmjs.org/sshpk/-/sshpk-1.18.0.tgz"
1920319152
integrity sha512-2p2KJZTSqQ/I3+HX42EpYOa2l3f8Erv8MWKsy2I9uf4wA7yFIkXRffYdsx86y6z4vHtV8u7g+pPlr8/4ouAxsQ==
@@ -20039,14 +19988,6 @@ tough-cookie@^5.0.0:
2003919988
dependencies:
2004019989
tldts "^6.1.32"
2004119990

20042-
tough-cookie@~2.5.0:
20043-
version "2.5.0"
20044-
resolved "https://registry.npmjs.org/tough-cookie/-/tough-cookie-2.5.0.tgz"
20045-
integrity sha512-nlLsUzgm1kfLXSXfRZMc1KLAugd4hqJHDTvc2hDIwS3mZAfMEuMbc03SujMF+GEcpaX/qboeycw6iO8JwVv2+g==
20046-
dependencies:
20047-
psl "^1.1.28"
20048-
punycode "^2.1.1"
20049-
2005019991
tr46@~0.0.3:
2005119992
version "0.0.3"
2005219993
resolved "https://registry.npmjs.org/tr46/-/tr46-0.0.3.tgz"
@@ -20656,11 +20597,6 @@ [email protected]:
2065620597
resolved "https://registry.npmjs.org/uuid/-/uuid-8.0.0.tgz"
2065720598
integrity sha512-jOXGuXZAWdsTH7eZLtyXMqUb9EcWMGZNbL9YcGBJl4MH4nrxHmZJhEHvyLFrkxo+28uLb/NYRcStH48fnD0Vzw==
2065820599

20659-
uuid@^3.3.2:
20660-
version "3.4.0"
20661-
resolved "https://registry.npmjs.org/uuid/-/uuid-3.4.0.tgz"
20662-
integrity sha512-HjSDRw6gZE5JMggctHBcjVak08+KEVhSIiDzFnT9S9aegmp85S/bReBVTb4QTFaRNptJ9kuYaNhnbNEOkbKb/A==
20663-
2066420600
uuid@^8.3.2:
2066520601
version "8.3.2"
2066620602
resolved "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz"

0 commit comments

Comments
 (0)