Skip to content

Commit bbb6e7b

Browse files
fix: force request to use @cypress/[email protected] to address security vulnerability
Updates package.json resolutions to use @cypress/[email protected] instead of the deprecated request package. This addresses the security vulnerability GHSA-p8p7-x288-28g6 TICKET: DX-1558
1 parent a5a0db2 commit bbb6e7b

File tree

2 files changed

+14
-77
lines changed

2 files changed

+14
-77
lines changed

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,7 @@
9999
"**/swarm-js/**/ws": "5.2.4",
100100
"serialize-javascript": "^6.0.2",
101101
"@grpc/grpc-js": "^1.12.6",
102+
"request": "npm:@cypress/[email protected]",
102103
"**/avalanche/store2": "2.14.4"
103104
},
104105
"workspaces": [

yarn.lock

Lines changed: 13 additions & 77 deletions
Original file line numberDiff line numberDiff line change
@@ -7016,7 +7016,7 @@ ajv-keywords@^5.1.0:
70167016
dependencies:
70177017
fast-deep-equal "^3.1.3"
70187018

7019-
ajv@^6.10.0, ajv@^6.12.3, ajv@^6.12.4, ajv@^6.12.5:
7019+
ajv@^6.10.0, ajv@^6.12.4, ajv@^6.12.5:
70207020
version "6.12.6"
70217021
resolved "https://registry.npmjs.org/ajv/-/ajv-6.12.6.tgz"
70227022
integrity sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g==
@@ -11803,7 +11803,7 @@ [email protected]:
1180311803
resolved "https://registry.npmjs.org/forge-light/-/forge-light-1.1.4.tgz#765da0d54e19c6644f37e7e5b873e1305ce78d1e"
1180411804
integrity sha512-Nr0xdu93LJawgBZVU/tC+A+4pbKqigdY5PRBz8CXNm4e5saAZIqU2Qe9+nVFtVO5TWCHSgvI0LaZZuatgE5J1g==
1180511805

11806-
form-data@^2.3.1, form-data@^4.0.0, form-data@^4.0.4, form-data@~2.3.2, form-data@~4.0.4:
11806+
form-data@^2.3.1, form-data@^4.0.0, form-data@^4.0.4, form-data@~4.0.4:
1180711807
version "4.0.4"
1180811808
resolved "https://registry.npmjs.org/form-data/-/form-data-4.0.4.tgz"
1180911809
integrity sha512-KrGhL9Q4zjj0kiUt5OO4Mr/A/jlI2jDYs5eHBpYHPcBEVSiipAvn2Ko2HnPe20rmcuuvMHNdZFp+4IlGTMF0Ow==
@@ -12417,19 +12417,6 @@ handlebars@^4.7.7:
1241712417
optionalDependencies:
1241812418
uglify-js "^3.1.4"
1241912419

12420-
har-schema@^2.0.0:
12421-
version "2.0.0"
12422-
resolved "https://registry.npmjs.org/har-schema/-/har-schema-2.0.0.tgz"
12423-
integrity sha512-Oqluz6zhGX8cyRaTQlFMPw80bSJVG2x/cFb8ZPhUILGgHka9SsokCCOQgpveePerqidZOrT14ipqfJb7ILcW5Q==
12424-
12425-
har-validator@~5.1.3:
12426-
version "5.1.5"
12427-
resolved "https://registry.npmjs.org/har-validator/-/har-validator-5.1.5.tgz"
12428-
integrity sha512-nmT2T0lljbxdQZfspsno9hgrG3Uir6Ks5afism62poxqBM6sDnMEuPmzTq8XN0OEwqKLLdh1jQI3qyE66Nzb3w==
12429-
dependencies:
12430-
ajv "^6.12.3"
12431-
har-schema "^2.0.0"
12432-
1243312420
hard-rejection@^2.1.0:
1243412421
version "2.1.0"
1243512422
resolved "https://registry.npmjs.org/hard-rejection/-/hard-rejection-2.1.0.tgz"
@@ -12825,15 +12812,6 @@ http-proxy@^1.18.1:
1282512812
follow-redirects "^1.0.0"
1282612813
requires-port "^1.0.0"
1282712814

12828-
http-signature@~1.2.0:
12829-
version "1.2.0"
12830-
resolved "https://registry.npmjs.org/http-signature/-/http-signature-1.2.0.tgz"
12831-
integrity sha512-CAbnr6Rz4CYQkLYUtSNXxQPUH2gK8f3iWexVlsnMeD+GjlsQ0Xsy1cOX+mN3dtxYomRy21CiOzU8Uhw6OwncEQ==
12832-
dependencies:
12833-
assert-plus "^1.0.0"
12834-
jsprim "^1.2.2"
12835-
sshpk "^1.7.0"
12836-
1283712815
http-signature@~1.4.0:
1283812816
version "1.4.0"
1283912817
resolved "https://registry.npmjs.org/http-signature/-/http-signature-1.4.0.tgz"
@@ -14083,16 +14061,6 @@ jspdf@^3.0.2:
1408314061
dompurify "^3.2.4"
1408414062
html2canvas "^1.0.0-rc.5"
1408514063

14086-
jsprim@^1.2.2:
14087-
version "1.4.2"
14088-
resolved "https://registry.npmjs.org/jsprim/-/jsprim-1.4.2.tgz"
14089-
integrity sha512-P2bSOMAc/ciLz6DzgjVlGJP9+BrJWu5UDGK70C2iweC5QBIeFf0ZXRvGjEj2uYgrY2MkAAhsSWHDWlFtEroZWw==
14090-
dependencies:
14091-
assert-plus "1.0.0"
14092-
extsprintf "1.3.0"
14093-
json-schema "0.4.0"
14094-
verror "1.10.0"
14095-
1409614064
jsprim@^2.0.2:
1409714065
version "2.0.2"
1409814066
resolved "https://registry.npmjs.org/jsprim/-/jsprim-2.0.2.tgz"
@@ -16054,11 +16022,6 @@ nyc@^15.0.0, nyc@^15.1.0:
1605416022
test-exclude "^6.0.0"
1605516023
yargs "^15.0.2"
1605616024

16057-
oauth-sign@~0.9.0:
16058-
version "0.9.0"
16059-
resolved "https://registry.npmjs.org/oauth-sign/-/oauth-sign-0.9.0.tgz"
16060-
integrity sha512-fexhUFFPTGV8ybAtSIGbV6gOkSv8UtRbDBnAyLQw4QPKkgNlsH2ByPGtMUqdWkos6YCRmAqViwgZrJc/mRDzZQ==
16061-
1606216025
object-assign@^4, object-assign@^4.0.1, object-assign@^4.1.0, object-assign@^4.1.1:
1606316026
version "4.1.1"
1606416027
resolved "https://registry.npmjs.org/object-assign/-/object-assign-4.1.1.tgz"
@@ -17464,13 +17427,6 @@ proxyquire@^2.1.3:
1746417427
module-not-found-error "^1.0.1"
1746517428
resolve "^1.11.1"
1746617429

17467-
psl@^1.1.28:
17468-
version "1.15.0"
17469-
resolved "https://registry.npmjs.org/psl/-/psl-1.15.0.tgz"
17470-
integrity sha512-JZd3gMVBAVQkSs6HdNZo9Sdo0LNcQeMNP3CozBJb3JYC/QUYZTnKxP+f8oWRX4rHP5EurWxqAHTSwUCjlNKa1w==
17471-
dependencies:
17472-
punycode "^2.3.1"
17473-
1747417430
public-encrypt@^4.0.0, public-encrypt@^4.0.3:
1747517431
version "4.0.3"
1747617432
resolved "https://registry.npmjs.org/public-encrypt/-/public-encrypt-4.0.3.tgz"
@@ -17511,7 +17467,7 @@ punycode@^1.3.2, punycode@^1.4.1:
1751117467
resolved "https://registry.npmjs.org/punycode/-/punycode-1.4.1.tgz"
1751217468
integrity sha512-jmYNElW7yvO7TV33CjSmvSiE2yco3bV2czu/OzDKdMNVZQWfxCblURLhf+47syQRBntjfLdd/H0egrzIG+oaFQ==
1751317469

17514-
punycode@^2.1.0, punycode@^2.1.1, punycode@^2.3.1:
17470+
punycode@^2.1.0, punycode@^2.1.1:
1751517471
version "2.3.1"
1751617472
resolved "https://registry.npmjs.org/punycode/-/punycode-2.3.1.tgz"
1751717473
integrity sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==
@@ -17582,11 +17538,6 @@ [email protected], qs@^6.11.0, qs@^6.11.2, qs@^6.12.3, qs@^6.5.1:
1758217538
dependencies:
1758317539
side-channel "^1.1.0"
1758417540

17585-
qs@~6.5.2:
17586-
version "6.5.3"
17587-
resolved "https://registry.npmjs.org/qs/-/qs-6.5.3.tgz"
17588-
integrity sha512-qxXIEh4pCGfHICj1mAJQ2/2XVZkjCDTcEgfoSQxc/fYivUZxTkk7L3bDBJSoNrEzXI17oUO5Dp07ktqE5KzczA==
17589-
1759017541
query-string@^5.0.1:
1759117542
version "5.1.1"
1759217543
resolved "https://registry.npmjs.org/query-string/-/query-string-5.1.1.tgz"
@@ -18057,31 +18008,29 @@ request-progress@^3.0.0:
1805718008
dependencies:
1805818009
throttleit "^1.0.0"
1805918010

18060-
request@^2.79.0:
18061-
version "2.88.2"
18062-
resolved "https://registry.npmjs.org/request/-/request-2.88.2.tgz"
18063-
integrity sha512-MsvtOrfG9ZcrOwAW+Qi+F6HbD0CWXEh9ou77uOb7FM2WPhwT7smM833PzanhJLsgXjN89Ir6V2PczXNnMpwKhw==
18011+
request@^2.79.0, "request@npm:@cypress/[email protected]":
18012+
version "3.0.9"
18013+
resolved "https://registry.npmjs.org/@cypress/request/-/request-3.0.9.tgz#8ed6e08fea0c62998b5552301023af7268f11625"
18014+
integrity sha512-I3l7FdGRXluAS44/0NguwWlO83J18p0vlr2FYHrJkWdNYhgVoiYo61IXPqaOsL+vNxU1ZqMACzItGK3/KKDsdw==
1806418015
dependencies:
1806518016
aws-sign2 "~0.7.0"
1806618017
aws4 "^1.8.0"
1806718018
caseless "~0.12.0"
1806818019
combined-stream "~1.0.6"
1806918020
extend "~3.0.2"
1807018021
forever-agent "~0.6.1"
18071-
form-data "~2.3.2"
18072-
har-validator "~5.1.3"
18073-
http-signature "~1.2.0"
18022+
form-data "~4.0.4"
18023+
http-signature "~1.4.0"
1807418024
is-typedarray "~1.0.0"
1807518025
isstream "~0.1.2"
1807618026
json-stringify-safe "~5.0.1"
1807718027
mime-types "~2.1.19"
18078-
oauth-sign "~0.9.0"
1807918028
performance-now "^2.1.0"
18080-
qs "~6.5.2"
18029+
qs "6.14.0"
1808118030
safe-buffer "^5.1.2"
18082-
tough-cookie "~2.5.0"
18031+
tough-cookie "^5.0.0"
1808318032
tunnel-agent "^0.6.0"
18084-
uuid "^3.3.2"
18033+
uuid "^8.3.2"
1808518034

1808618035
require-directory@^2.1.1:
1808718036
version "2.1.1"
@@ -19157,7 +19106,7 @@ sprintf-js@~1.0.2:
1915719106
resolved "https://registry.npmjs.org/sprintf-js/-/sprintf-js-1.0.3.tgz"
1915819107
integrity sha512-D9cPgkvLlV3t3IzL0D0YLvGA9Ahk4PcvVwUbN0dSGr1aP0Nrt4AEnTUbuGvquEC0mA64Gqt1fzirlRs5ibXx8g==
1915919108

19160-
sshpk@^1.18.0, sshpk@^1.7.0:
19109+
sshpk@^1.18.0:
1916119110
version "1.18.0"
1916219111
resolved "https://registry.npmjs.org/sshpk/-/sshpk-1.18.0.tgz"
1916319112
integrity sha512-2p2KJZTSqQ/I3+HX42EpYOa2l3f8Erv8MWKsy2I9uf4wA7yFIkXRffYdsx86y6z4vHtV8u7g+pPlr8/4ouAxsQ==
@@ -19999,14 +19948,6 @@ tough-cookie@^5.0.0:
1999919948
dependencies:
2000019949
tldts "^6.1.32"
2000119950

20002-
tough-cookie@~2.5.0:
20003-
version "2.5.0"
20004-
resolved "https://registry.npmjs.org/tough-cookie/-/tough-cookie-2.5.0.tgz"
20005-
integrity sha512-nlLsUzgm1kfLXSXfRZMc1KLAugd4hqJHDTvc2hDIwS3mZAfMEuMbc03SujMF+GEcpaX/qboeycw6iO8JwVv2+g==
20006-
dependencies:
20007-
psl "^1.1.28"
20008-
punycode "^2.1.1"
20009-
2001019951
tr46@~0.0.3:
2001119952
version "0.0.3"
2001219953
resolved "https://registry.npmjs.org/tr46/-/tr46-0.0.3.tgz"
@@ -20616,11 +20557,6 @@ [email protected]:
2061620557
resolved "https://registry.npmjs.org/uuid/-/uuid-8.0.0.tgz"
2061720558
integrity sha512-jOXGuXZAWdsTH7eZLtyXMqUb9EcWMGZNbL9YcGBJl4MH4nrxHmZJhEHvyLFrkxo+28uLb/NYRcStH48fnD0Vzw==
2061820559

20619-
uuid@^3.3.2:
20620-
version "3.4.0"
20621-
resolved "https://registry.npmjs.org/uuid/-/uuid-3.4.0.tgz"
20622-
integrity sha512-HjSDRw6gZE5JMggctHBcjVak08+KEVhSIiDzFnT9S9aegmp85S/bReBVTb4QTFaRNptJ9kuYaNhnbNEOkbKb/A==
20623-
2062420560
uuid@^8.3.2:
2062520561
version "8.3.2"
2062620562
resolved "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz"

0 commit comments

Comments
 (0)