Skip to content

Commit 25803bc

Browse files
committed
chore: resolve path-to-regexp cve
We had transitive dependencies on two vulnerable versions of path-to regexp: The dependency via sinon was a compatible upgrade so could be fixed via `yarn up -R path-to-regexp`. The dependency via storybook was resolved by auto upgrading storybook via the storybook upgrade tool.
1 parent ddafa04 commit 25803bc

File tree

2 files changed

+545
-4653
lines changed

2 files changed

+545
-4653
lines changed

package.json

Lines changed: 12 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -90,17 +90,19 @@
9090
"@babel/preset-env": "^7.24.7",
9191
"@babel/preset-react": "^7.24.7",
9292
"@babel/preset-typescript": "^7.24.7",
93-
"@chromatic-com/storybook": "^1.5.0",
93+
"@chromatic-com/storybook": "^3.2.3",
9494
"@jest/types": "^29.6.3",
95-
"@storybook/addon-a11y": "^8.1.5",
96-
"@storybook/addon-actions": "^8.1.5",
97-
"@storybook/addon-controls": "^8.1.5",
98-
"@storybook/addon-essentials": "^8.1.5",
99-
"@storybook/addon-links": "^8.1.5",
100-
"@storybook/addon-viewport": "^8.1.5",
95+
"@storybook/addon-a11y": "^8.4.7",
96+
"@storybook/addon-actions": "^8.4.7",
97+
"@storybook/addon-controls": "^8.4.7",
98+
"@storybook/addon-essentials": "^8.4.7",
99+
"@storybook/addon-links": "^8.4.7",
100+
"@storybook/addon-viewport": "^8.4.7",
101101
"@storybook/addon-webpack5-compiler-babel": "^3.0.3",
102-
"@storybook/react": "^8.1.5",
103-
"@storybook/react-webpack5": "^8.1.6",
102+
"@storybook/manager-api": "^8.4.7",
103+
"@storybook/react": "^8.4.7",
104+
"@storybook/react-webpack5": "^8.4.7",
105+
"@storybook/theming": "^8.4.7",
104106
"@testing-library/dom": "^8.13.0",
105107
"@testing-library/jest-dom": "^6.4.6",
106108
"@testing-library/react": "^11.2.6",
@@ -151,7 +153,7 @@
151153
"react-dom": "^16.14.0",
152154
"regenerator-runtime": "^0.13.7",
153155
"sinon": "^9.2.1",
154-
"storybook": "^8.1.5",
156+
"storybook": "^8.4.7",
155157
"storybook-source-link": "^4.0.1",
156158
"ts-node": "^10.7.0",
157159
"typescript": "^4.6.3",

0 commit comments

Comments
 (0)