Skip to content

Commit c09fcd2

Browse files
authored
upgrade sdk-for-js to address CVE-2022-1650 (#1973)
Signed-off-by: Kent Rancourt <kent.rancourt@microsoft.com>
1 parent 15e6b7e commit c09fcd2

File tree

3 files changed

+20
-74
lines changed

3 files changed

+20
-74
lines changed

v2/brigadier-polyfill/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@
3030
"ts-node": "^10.2.1"
3131
},
3232
"dependencies": {
33-
"@brigadecore/brigade-sdk": "^v2.4.0",
33+
"@brigadecore/brigade-sdk": "^v2.4.1",
3434
"@brigadecore/brigadier": "../brigadier",
3535
"@types/node": "^16.10.3",
3636
"typescript": "4.4.3",

v2/brigadier-polyfill/yarn.lock

Lines changed: 9 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -23,14 +23,14 @@
2323
chalk "^2.0.0"
2424
js-tokens "^4.0.0"
2525

26-
"@brigadecore/brigade-sdk@^v2.4.0":
27-
version "2.4.0"
28-
resolved "https://registry.yarnpkg.com/@brigadecore/brigade-sdk/-/brigade-sdk-2.4.0.tgz#743995c67bdcf746e6a93282c5fb1f78e0718f23"
29-
integrity sha512-1S7SXYvWV3uS0b2toJrD4sjk9WTXeFV5LOz3USsBSrZ0R/JENqaoBnT0J4j60saXCBGTZQk/A5IsLnu8QRs7BQ==
26+
"@brigadecore/brigade-sdk@^v2.4.1":
27+
version "2.4.1"
28+
resolved "https://registry.yarnpkg.com/@brigadecore/brigade-sdk/-/brigade-sdk-2.4.1.tgz#c6a592e750573966e3b86c475d5b4e90e8144abe"
29+
integrity sha512-229e7FgHf/NcVMFRrbp7Pg5TOuHpSdKXKEuc5OsqezCj/Nz6JXPq+cgsyTbXu5az4ysEN1jqOaM2il9P8uRG4Q==
3030
dependencies:
3131
axios "^0.21.2"
3232
event-source-polyfill "^1.0.22"
33-
eventsource "^1.1.0"
33+
eventsource "^2.0.2"
3434
js-base64 "^3.6.0"
3535
querystring "^0.2.0"
3636

@@ -731,12 +731,10 @@ event-source-polyfill@^1.0.22:
731731
resolved "https://registry.yarnpkg.com/event-source-polyfill/-/event-source-polyfill-1.0.26.tgz#86c04d088ef078279168eefa028f928fec5059a4"
732732
integrity sha512-IwDLs9fUTcGAyacHBeS53T8wcEkDyDn0UP4tfQqJ4wQP8AyH0mszuQf2ULTylnpI0sMquzJ4usrNV7+uztwI9A==
733733

734-
eventsource@^1.1.0:
735-
version "1.1.0"
736-
resolved "https://registry.yarnpkg.com/eventsource/-/eventsource-1.1.0.tgz#00e8ca7c92109e94b0ddf32dac677d841028cfaf"
737-
integrity sha512-VSJjT5oCNrFvCS6igjzPAt5hBzQ2qPBFIbJ03zLI9SE0mxwZpMw6BfJrbFHm1a141AavMEB8JHmBhWAd66PfCg==
738-
dependencies:
739-
original "^1.0.0"
734+
eventsource@^2.0.2:
735+
version "2.0.2"
736+
resolved "https://registry.yarnpkg.com/eventsource/-/eventsource-2.0.2.tgz#76dfcc02930fb2ff339520b6d290da573a9e8508"
737+
integrity sha512-IzUmBGPR3+oUG9dUeXynyNmf91/3zUSJg1lCktzKw47OXuhco54U3r9B7O4XX+Rb1Itm9OZ2b0RkTs10bICOxA==
740738

741739
fast-deep-equal@^3.1.1, fast-deep-equal@^3.1.3:
742740
version "3.1.3"
@@ -1215,13 +1213,6 @@ optionator@^0.9.1:
12151213
type-check "^0.4.0"
12161214
word-wrap "^1.2.3"
12171215

1218-
original@^1.0.0:
1219-
version "1.0.2"
1220-
resolved "https://registry.yarnpkg.com/original/-/original-1.0.2.tgz#e442a61cffe1c5fd20a65f3261c26663b303f25f"
1221-
integrity sha512-hyBVl6iqqUOJ8FqRe+l/gS8H+kKYjrEndd5Pm1MfBtsEKA038HkkdbAl/72EAXGyonD/PFsvmVG+EvcIpliMBg==
1222-
dependencies:
1223-
url-parse "^1.4.3"
1224-
12251216
p-limit@^3.0.2:
12261217
version "3.1.0"
12271218
resolved "https://registry.yarnpkg.com/p-limit/-/p-limit-3.1.0.tgz#e1daccbe78d0d1388ca18c64fea38e3e57e3706b"
@@ -1298,11 +1289,6 @@ querystring@^0.2.0:
12981289
resolved "https://registry.yarnpkg.com/querystring/-/querystring-0.2.1.tgz#40d77615bb09d16902a85c3e38aa8b5ed761c2dd"
12991290
integrity sha512-wkvS7mL/JMugcup3/rMitHmd9ecIGd2lhFhK9N3UUQ450h66d1r3Y9nvXzQAW1Lq+wyx61k/1pfKS5KuKiyEbg==
13001291

1301-
querystringify@^2.1.1:
1302-
version "2.2.0"
1303-
resolved "https://registry.yarnpkg.com/querystringify/-/querystringify-2.2.0.tgz#3345941b4153cb9d082d8eee4cda2016a9aef7f6"
1304-
integrity sha512-FIqgj2EUvTa7R50u0rGsyTftzjYmv/a3hO345bZNrqabNqjtgiDMgmo4mkUjd+nzU5oF3dClKqFIPUKybUyqoQ==
1305-
13061292
queue-microtask@^1.2.2:
13071293
version "1.2.3"
13081294
resolved "https://registry.yarnpkg.com/queue-microtask/-/queue-microtask-1.2.3.tgz#4929228bbc724dfac43e0efb058caf7b6cfb6243"
@@ -1346,11 +1332,6 @@ require-from-string@^2.0.2:
13461332
resolved "https://registry.yarnpkg.com/require-from-string/-/require-from-string-2.0.2.tgz#89a7fdd938261267318eafe14f9c32e598c36909"
13471333
integrity sha512-Xf0nWe6RseziFMu+Ap9biiUbmplq6S9/p+7w7YXP/JBHhrUDDUhwa+vANyubuqfZWTveU//DYVGsDG7RKL/vEw==
13481334

1349-
requires-port@^1.0.0:
1350-
version "1.0.0"
1351-
resolved "https://registry.yarnpkg.com/requires-port/-/requires-port-1.0.0.tgz#925d2601d39ac485e091cf0da5c6e694dc3dcaff"
1352-
integrity sha1-kl0mAdOaxIXgkc8NpcbmlNw9yv8=
1353-
13541335
resolve-from@^4.0.0:
13551336
version "4.0.0"
13561337
resolved "https://registry.yarnpkg.com/resolve-from/-/resolve-from-4.0.0.tgz#4abcd852ad32dd7baabfe9b40e00a36db5f392e6"
@@ -1584,14 +1565,6 @@ uri-js@^4.2.2:
15841565
dependencies:
15851566
punycode "^2.1.0"
15861567

1587-
url-parse@^1.4.3:
1588-
version "1.5.10"
1589-
resolved "https://registry.yarnpkg.com/url-parse/-/url-parse-1.5.10.tgz#9d3c2f736c1d75dd3bd2be507dcc111f1e2ea9c1"
1590-
integrity sha512-WypcfiRhfeUP9vvF0j6rw0J3hrWrw6iZv3+22h6iRMJ/8z1Tj6XfLP4DsUix5MhMPnXpiHDoKyoZ/bdCkwBCiQ==
1591-
dependencies:
1592-
querystringify "^2.1.1"
1593-
requires-port "^1.0.0"
1594-
15951568
util-deprecate@^1.0.1:
15961569
version "1.0.2"
15971570
resolved "https://registry.yarnpkg.com/util-deprecate/-/util-deprecate-1.0.2.tgz#450d4dc9fa70de732762fbd2d4a28981419a0ccf"

v2/worker/yarn.lock

Lines changed: 10 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -23,21 +23,21 @@
2323
chalk "^2.0.0"
2424
js-tokens "^4.0.0"
2525

26-
"@brigadecore/brigade-sdk@^v2.4.0":
27-
version "2.4.0"
28-
resolved "https://registry.yarnpkg.com/@brigadecore/brigade-sdk/-/brigade-sdk-2.4.0.tgz#743995c67bdcf746e6a93282c5fb1f78e0718f23"
29-
integrity sha512-1S7SXYvWV3uS0b2toJrD4sjk9WTXeFV5LOz3USsBSrZ0R/JENqaoBnT0J4j60saXCBGTZQk/A5IsLnu8QRs7BQ==
26+
"@brigadecore/brigade-sdk@^v2.4.1":
27+
version "2.4.1"
28+
resolved "https://registry.yarnpkg.com/@brigadecore/brigade-sdk/-/brigade-sdk-2.4.1.tgz#c6a592e750573966e3b86c475d5b4e90e8144abe"
29+
integrity sha512-229e7FgHf/NcVMFRrbp7Pg5TOuHpSdKXKEuc5OsqezCj/Nz6JXPq+cgsyTbXu5az4ysEN1jqOaM2il9P8uRG4Q==
3030
dependencies:
3131
axios "^0.21.2"
3232
event-source-polyfill "^1.0.22"
33-
eventsource "^1.1.0"
33+
eventsource "^2.0.2"
3434
js-base64 "^3.6.0"
3535
querystring "^0.2.0"
3636

3737
"@brigadecore/brigadier-polyfill@../brigadier-polyfill":
3838
version "0.0.1-placeholder"
3939
dependencies:
40-
"@brigadecore/brigade-sdk" "^v2.4.0"
40+
"@brigadecore/brigade-sdk" "^v2.4.1"
4141
"@brigadecore/brigadier" "../brigadier"
4242
"@types/node" "^16.10.3"
4343
typescript "4.4.3"
@@ -1149,12 +1149,10 @@ event-source-polyfill@^1.0.22:
11491149
resolved "https://registry.yarnpkg.com/event-source-polyfill/-/event-source-polyfill-1.0.26.tgz#86c04d088ef078279168eefa028f928fec5059a4"
11501150
integrity sha512-IwDLs9fUTcGAyacHBeS53T8wcEkDyDn0UP4tfQqJ4wQP8AyH0mszuQf2ULTylnpI0sMquzJ4usrNV7+uztwI9A==
11511151

1152-
eventsource@^1.1.0:
1153-
version "1.1.0"
1154-
resolved "https://registry.yarnpkg.com/eventsource/-/eventsource-1.1.0.tgz#00e8ca7c92109e94b0ddf32dac677d841028cfaf"
1155-
integrity sha512-VSJjT5oCNrFvCS6igjzPAt5hBzQ2qPBFIbJ03zLI9SE0mxwZpMw6BfJrbFHm1a141AavMEB8JHmBhWAd66PfCg==
1156-
dependencies:
1157-
original "^1.0.0"
1152+
eventsource@^2.0.2:
1153+
version "2.0.2"
1154+
resolved "https://registry.yarnpkg.com/eventsource/-/eventsource-2.0.2.tgz#76dfcc02930fb2ff339520b6d290da573a9e8508"
1155+
integrity sha512-IzUmBGPR3+oUG9dUeXynyNmf91/3zUSJg1lCktzKw47OXuhco54U3r9B7O4XX+Rb1Itm9OZ2b0RkTs10bICOxA==
11581156

11591157
fast-deep-equal@^3.1.1, fast-deep-equal@^3.1.3:
11601158
version "3.1.3"
@@ -2264,13 +2262,6 @@ optionator@^0.9.1:
22642262
type-check "^0.4.0"
22652263
word-wrap "^1.2.3"
22662264

2267-
original@^1.0.0:
2268-
version "1.0.2"
2269-
resolved "https://registry.yarnpkg.com/original/-/original-1.0.2.tgz#e442a61cffe1c5fd20a65f3261c26663b303f25f"
2270-
integrity sha512-hyBVl6iqqUOJ8FqRe+l/gS8H+kKYjrEndd5Pm1MfBtsEKA038HkkdbAl/72EAXGyonD/PFsvmVG+EvcIpliMBg==
2271-
dependencies:
2272-
url-parse "^1.4.3"
2273-
22742265
p-limit@^3.0.2:
22752266
version "3.1.0"
22762267
resolved "https://registry.yarnpkg.com/p-limit/-/p-limit-3.1.0.tgz#e1daccbe78d0d1388ca18c64fea38e3e57e3706b"
@@ -2430,11 +2421,6 @@ querystring@^0.2.0:
24302421
resolved "https://registry.yarnpkg.com/querystring/-/querystring-0.2.1.tgz#40d77615bb09d16902a85c3e38aa8b5ed761c2dd"
24312422
integrity sha512-wkvS7mL/JMugcup3/rMitHmd9ecIGd2lhFhK9N3UUQ450h66d1r3Y9nvXzQAW1Lq+wyx61k/1pfKS5KuKiyEbg==
24322423

2433-
querystringify@^2.1.1:
2434-
version "2.2.0"
2435-
resolved "https://registry.yarnpkg.com/querystringify/-/querystringify-2.2.0.tgz#3345941b4153cb9d082d8eee4cda2016a9aef7f6"
2436-
integrity sha512-FIqgj2EUvTa7R50u0rGsyTftzjYmv/a3hO345bZNrqabNqjtgiDMgmo4mkUjd+nzU5oF3dClKqFIPUKybUyqoQ==
2437-
24382424
queue-microtask@^1.2.2:
24392425
version "1.2.3"
24402426
resolved "https://registry.yarnpkg.com/queue-microtask/-/queue-microtask-1.2.3.tgz#4929228bbc724dfac43e0efb058caf7b6cfb6243"
@@ -2518,11 +2504,6 @@ require-from-string@^2.0.2:
25182504
resolved "https://registry.yarnpkg.com/require-from-string/-/require-from-string-2.0.2.tgz#89a7fdd938261267318eafe14f9c32e598c36909"
25192505
integrity sha512-Xf0nWe6RseziFMu+Ap9biiUbmplq6S9/p+7w7YXP/JBHhrUDDUhwa+vANyubuqfZWTveU//DYVGsDG7RKL/vEw==
25202506

2521-
requires-port@^1.0.0:
2522-
version "1.0.0"
2523-
resolved "https://registry.yarnpkg.com/requires-port/-/requires-port-1.0.0.tgz#925d2601d39ac485e091cf0da5c6e694dc3dcaff"
2524-
integrity sha1-kl0mAdOaxIXgkc8NpcbmlNw9yv8=
2525-
25262507
resolve-from@^4.0.0:
25272508
version "4.0.0"
25282509
resolved "https://registry.yarnpkg.com/resolve-from/-/resolve-from-4.0.0.tgz#4abcd852ad32dd7baabfe9b40e00a36db5f392e6"
@@ -2884,14 +2865,6 @@ uri-js@^4.2.2:
28842865
dependencies:
28852866
punycode "^2.1.0"
28862867

2887-
url-parse@^1.4.3:
2888-
version "1.5.10"
2889-
resolved "https://registry.yarnpkg.com/url-parse/-/url-parse-1.5.10.tgz#9d3c2f736c1d75dd3bd2be507dcc111f1e2ea9c1"
2890-
integrity sha512-WypcfiRhfeUP9vvF0j6rw0J3hrWrw6iZv3+22h6iRMJ/8z1Tj6XfLP4DsUix5MhMPnXpiHDoKyoZ/bdCkwBCiQ==
2891-
dependencies:
2892-
querystringify "^2.1.1"
2893-
requires-port "^1.0.0"
2894-
28952868
util-deprecate@^1.0.1:
28962869
version "1.0.2"
28972870
resolved "https://registry.yarnpkg.com/util-deprecate/-/util-deprecate-1.0.2.tgz#450d4dc9fa70de732762fbd2d4a28981419a0ccf"

0 commit comments

Comments
 (0)