Skip to content
This repository was archived by the owner on Apr 18, 2024. It is now read-only.

Commit 1bfd5b8

Browse files
Travis1282bmartel
andauthored
fix: LSDV-5249: Manual security updates (#1440)
* upgrade d3, svgr, loader-utils * resolve d3-color * fix resolution of d3-color 3.1.0 --------- Co-authored-by: Brandon Martel <[email protected]>
1 parent 9b1f3c7 commit 1bfd5b8

File tree

4 files changed

+1186
-599
lines changed

4 files changed

+1186
-599
lines changed

e2e/package.json

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,6 @@
2727
"@codeceptjs/ui": "^0.4.6",
2828
"@types/mkdirp": "^1.0.1",
2929
"@types/node": "^16.11.6",
30-
"@types/node-fetch": "^2.5.8",
3130
"@types/puppeteer": "^5.4.3",
3231
"@types/rimraf": "^3.0.0",
3332
"@typescript-eslint/eslint-plugin": "^5.6.0",
@@ -36,7 +35,6 @@
3635
"eslint": "^8.4.1",
3736
"eslint-plugin-codeceptjs": "^1.3.0",
3837
"mkdirp": "^1.0.4",
39-
"node-fetch": "^2.6.7",
4038
"nyc": "^15.1.0",
4139
"playwright": "^1.16.3",
4240
"puppeteer": "^10.0.0",

e2e/yarn.lock

Lines changed: 1 addition & 60 deletions
Original file line numberDiff line numberDiff line change
@@ -462,14 +462,6 @@
462462
dependencies:
463463
"@types/node" "*"
464464

465-
"@types/node-fetch@^2.5.8":
466-
version "2.5.12"
467-
resolved "https://registry.yarnpkg.com/@types/node-fetch/-/node-fetch-2.5.12.tgz#8a6f779b1d4e60b7a57fb6fd48d84fb545b9cc66"
468-
integrity sha512-MKgC4dlq4kKNa/mYrwpKfzQMB5X3ee5U6fSprkKpToBqBmX4nFZL9cW5jl6sWn+xpRJ7ypWh2yyqqr8UUCstSw==
469-
dependencies:
470-
"@types/node" "*"
471-
form-data "^3.0.0"
472-
473465
"@types/node@*", "@types/node@^16.11.6":
474466
version "16.11.12"
475467
resolved "https://registry.yarnpkg.com/@types/node/-/node-16.11.12.tgz#ac7fb693ac587ee182c3780c26eb65546a1a3c10"
@@ -759,11 +751,6 @@ assertion-error@^1.1.0:
759751
resolved "https://registry.yarnpkg.com/assertion-error/-/assertion-error-1.1.0.tgz#e60b6b0e8f301bd97e5375215bda406c85118c0b"
760752
integrity sha512-jgsaNduz+ndvGyFt3uSuWqvy4lCnIJiovtouQN5JZHOKCS2QuhEdbcQHFhVksz2N2U9hXJo8odG7ETyWlEeuDw==
761753

762-
asynckit@^0.4.0:
763-
version "0.4.0"
764-
resolved "https://registry.yarnpkg.com/asynckit/-/asynckit-0.4.0.tgz#c79ed97f7f34cb8f2ba1bc9790bcc366474b4b79"
765-
integrity sha1-x57Zf380y48robyXkLzDZkdLS3k=
766-
767754
axios@^0.21.1, axios@^0.21.4:
768755
version "0.21.4"
769756
resolved "https://registry.yarnpkg.com/axios/-/axios-0.21.4.tgz#c67b90dc0568e5c1cf2b0b858c43ba28e2eda575"
@@ -1171,13 +1158,6 @@ color-name@~1.1.4:
11711158
resolved "https://registry.yarnpkg.com/color-name/-/color-name-1.1.4.tgz#c2a09a87acbde69543de6f63fa3995c826c536a2"
11721159
integrity sha512-dOy+3AuW3a2wNbZHIuMZpTcgjGuLU/uBL/ubcZF9OXbDo8ff4O8yVp5Bf0efS8uEoYo5q4Fx7dY9OgQGXgAsQA==
11731160

1174-
combined-stream@^1.0.8:
1175-
version "1.0.8"
1176-
resolved "https://registry.yarnpkg.com/combined-stream/-/combined-stream-1.0.8.tgz#c3d45a8b34fd730631a110a8a2520682b31d5a7f"
1177-
integrity sha512-FQN4MRfuJeHf7cBbBMJFXhKSDq+2kAArBlmRBvcvFE5BB1HZKXtSFASDhdlz9zOYwxh8lDdnvmMOe/+5cdoEdg==
1178-
dependencies:
1179-
delayed-stream "~1.0.0"
1180-
11811161
commander@^2.19.0, commander@^2.20.3:
11821162
version "2.20.3"
11831163
resolved "https://registry.yarnpkg.com/commander/-/commander-2.20.3.tgz#fd485e84c03eb4881c20722ba48035e8531aeb33"
@@ -1424,11 +1404,6 @@ define-properties@^1.1.2, define-properties@^1.1.3, define-properties@^1.1.4:
14241404
has-property-descriptors "^1.0.0"
14251405
object-keys "^1.1.1"
14261406

1427-
delayed-stream@~1.0.0:
1428-
version "1.0.0"
1429-
resolved "https://registry.yarnpkg.com/delayed-stream/-/delayed-stream-1.0.0.tgz#df3ae199acadfb7d440aaae0b29e2272b24ec619"
1430-
integrity sha1-3zrhmayt+31ECqrgsp4icrJOxhk=
1431-
14321407
depd@~1.1.2:
14331408
version "1.1.2"
14341409
resolved "https://registry.yarnpkg.com/depd/-/depd-1.1.2.tgz#9bcd52e14c097763e749b274c4346ed2e560b5a9"
@@ -2067,15 +2042,6 @@ foreground-child@^2.0.0:
20672042
cross-spawn "^7.0.0"
20682043
signal-exit "^3.0.2"
20692044

2070-
form-data@^3.0.0:
2071-
version "3.0.1"
2072-
resolved "https://registry.yarnpkg.com/form-data/-/form-data-3.0.1.tgz#ebd53791b78356a99af9a300d4282c4d5eb9755f"
2073-
integrity sha512-RHkBKtLWUVwd7SqRIvCZMEvAMoGUp0XU+seQiZejj0COz3RI3hWP4sCv3gZWWLjJTd7rGwcsF5eKZGii0r/hbg==
2074-
dependencies:
2075-
asynckit "^0.4.0"
2076-
combined-stream "^1.0.8"
2077-
mime-types "^2.1.12"
2078-
20792045
20802046
version "0.2.0"
20812047
resolved "https://registry.yarnpkg.com/forwarded/-/forwarded-0.2.0.tgz#2269936428aad4c15c7ebe9779a84bf0b2a81811"
@@ -3083,7 +3049,7 @@ [email protected]:
30833049
resolved "https://registry.yarnpkg.com/mime-db/-/mime-db-1.51.0.tgz#d9ff62451859b18342d960850dc3cfb77e63fb0c"
30843050
integrity sha512-5y8A56jg7XVQx2mbv1lu49NR4dokRnhZYTtL+KGfaa27uq4pSTXkwQkFJl4pkRMyNFz/EtYDSkiiEHx3F7UN6g==
30853051

3086-
mime-types@^2.1.12, mime-types@~2.1.24:
3052+
mime-types@~2.1.24:
30873053
version "2.1.34"
30883054
resolved "https://registry.yarnpkg.com/mime-types/-/mime-types-2.1.34.tgz#5a712f9ec1503511a945803640fafe09d3793c24"
30893055
integrity sha512-6cP692WwGIs9XXdOO4++N+7qjqv0rqxxVvJ3VHPh/Sc9mVZcQP+ZGhkKiTvWMQRr2tbHkJP/Yn7Y0npb3ZBs4A==
@@ -3240,13 +3206,6 @@ [email protected]:
32403206
resolved "https://registry.yarnpkg.com/node-fetch/-/node-fetch-2.6.1.tgz#045bd323631f76ed2e2b55573394416b639a0052"
32413207
integrity sha512-V4aYg89jEoVRxRb2fJdAg8FHvI7cEyYdVAh94HH0UIK8oJxUfkjlDQN9RbMx+bEjP7+ggMiFRprSti032Oipxw==
32423208

3243-
node-fetch@^2.6.7:
3244-
version "2.6.7"
3245-
resolved "https://registry.yarnpkg.com/node-fetch/-/node-fetch-2.6.7.tgz#24de9fba827e3b4ae44dc8b20256a379160052ad"
3246-
integrity sha512-ZjMPFEfVx5j+y2yF35Kzx5sF7kDzxuDj6ziH4FFbOp87zKDZNx8yExJIb05OGF4Nlt9IHFIMBkRl41VdvcNdbQ==
3247-
dependencies:
3248-
whatwg-url "^5.0.0"
3249-
32503209
node-preload@^0.2.1:
32513210
version "0.2.1"
32523211
resolved "https://registry.yarnpkg.com/node-preload/-/node-preload-0.2.1.tgz#c03043bb327f417a18fee7ab7ee57b408a144301"
@@ -4386,11 +4345,6 @@ [email protected]:
43864345
resolved "https://registry.yarnpkg.com/toidentifier/-/toidentifier-1.0.0.tgz#7e1be3470f1e77948bc43d94a3c8f4d7752ba553"
43874346
integrity sha512-yaOH/Pk/VEhBWWTlhI+qXxDFXlejDGcQipMlyxda9nthulaxLZUNcUqFxokp0vcYnvteJln5FNQDRrxj3YcbVw==
43884347

4389-
tr46@~0.0.3:
4390-
version "0.0.3"
4391-
resolved "https://registry.yarnpkg.com/tr46/-/tr46-0.0.3.tgz#8184fd347dac9cdc185992f3a6622e14b9d9ab6a"
4392-
integrity sha1-gYT9NH2snNwYWZLzpmIuFLnZq2o=
4393-
43944348
ts-node@^10.0.0:
43954349
version "10.4.0"
43964350
resolved "https://registry.yarnpkg.com/ts-node/-/ts-node-10.4.0.tgz#680f88945885f4e6cf450e7f0d6223dd404895f7"
@@ -4564,19 +4518,6 @@ vary@~1.1.2:
45644518
resolved "https://registry.yarnpkg.com/vary/-/vary-1.1.2.tgz#2299f02c6ded30d4a5961b0b9f74524a18f634fc"
45654519
integrity sha1-IpnwLG3tMNSllhsLn3RSShj2NPw=
45664520

4567-
webidl-conversions@^3.0.0:
4568-
version "3.0.1"
4569-
resolved "https://registry.yarnpkg.com/webidl-conversions/-/webidl-conversions-3.0.1.tgz#24534275e2a7bc6be7bc86611cc16ae0a5654871"
4570-
integrity sha1-JFNCdeKnvGvnvIZhHMFq4KVlSHE=
4571-
4572-
whatwg-url@^5.0.0:
4573-
version "5.0.0"
4574-
resolved "https://registry.yarnpkg.com/whatwg-url/-/whatwg-url-5.0.0.tgz#966454e8765462e37644d3626f6742ce8b70965d"
4575-
integrity sha1-lmRU6HZUYuN2RNNib2dCzotwll0=
4576-
dependencies:
4577-
tr46 "~0.0.3"
4578-
webidl-conversions "^3.0.0"
4579-
45804521
which-boxed-primitive@^1.0.2:
45814522
version "1.0.2"
45824523
resolved "https://registry.yarnpkg.com/which-boxed-primitive/-/which-boxed-primitive-1.0.2.tgz#13757bc89b209b049fe5d86430e21cf40a89a8e6"

package.json

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -91,6 +91,8 @@
9191
"babel-plugin-istanbul": "^6.1.1",
9292
"babel-preset-react-app": "^9.1.1",
9393
"d3": "^5.16.0",
94+
"d3-color": "3.1.0",
95+
"loader-utils": "2.0.3",
9496
"magic-wand-js": "^1.0.0",
9597
"papaparse": "^5.3.1",
9698
"rc-tree": "^5.3.0",
@@ -113,7 +115,7 @@
113115
"@babel/preset-typescript": "7.18.6",
114116
"@babel/runtime": "7.18.6",
115117
"@heartexlabs/eslint-plugin-frontend": "https://github.com/heartexlabs/eslint-plugin-frontend.git",
116-
"@svgr/webpack": "^5.5.0",
118+
"@svgr/webpack": "^8.0.1",
117119
"@testing-library/react": "12.1.2",
118120
"@types/chroma-js": "^2.1.3",
119121
"@types/enzyme": "^3.10.12",
@@ -137,6 +139,7 @@
137139
"chroma-js": "^2.1.1",
138140
"css-loader": "^6.7.3",
139141
"css-minimizer-webpack-plugin": "^3.0.2",
142+
"d3": "^5.16.0",
140143
"date-fns": "^2.20.1",
141144
"dotenv-defaults": "^2.0.2",
142145
"dotenv-webpack": "^7.0.2",
@@ -197,9 +200,13 @@
197200
"webpack": "^5.79.0",
198201
"webpack-cli": "^5.0.1",
199202
"webpack-dev-server": "^4.13.3",
200-
"xml2js": "^0.4.23",
203+
"xml2js": "^0.6.0",
201204
"xpath-range": "^1.1.1"
202205
},
206+
"resolutions": {
207+
"d3-color": "3.1.0",
208+
"loader-utils": "2.0.3"
209+
},
203210
"nohoist": [
204211
"**/babel-preset-react-app/@babel/runtime"
205212
]

0 commit comments

Comments
 (0)