Skip to content

Commit 96416c4

Browse files
authored
security: use yarn resolutions to close broken dependabot PRs (#5442)
1 parent 2a75128 commit 96416c4

File tree

2 files changed

+50
-30
lines changed

2 files changed

+50
-30
lines changed

package.json

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -67,16 +67,19 @@
6767
"typescript": "5.4.3"
6868
},
6969
"resolutions": {
70-
"decode-uri-component": "0.2.2",
7170
"@types/react": "18.2.73",
7271
"**/recursive-readdir/minimatch": "6.2.0",
72+
"decode-uri-component": "0.2.2",
73+
"express": "4.19.2",
7374
"fastify": "3.29.5",
75+
"follow-redirects": "1.15.6",
7476
"json5": "2.2.3",
7577
"loader-utils": "2.0.4",
7678
"postcss": "^8.4.31",
7779
"terser": "5.30.0",
7880
"trim-newlines": "3.0.1",
79-
"trim": "1.0.1"
81+
"trim": "1.0.1",
82+
"undici": "5.28.4"
8083
},
8184
"packageManager": "[email protected]"
8285
}

yarn.lock

Lines changed: 45 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -6478,21 +6478,21 @@ bluebird@~3.4.1:
64786478
resolved "https://registry.yarnpkg.com/bluebird/-/bluebird-3.4.7.tgz#f72d760be09b7f76d08ed8fae98b289a8d05fab3"
64796479
integrity sha512-iD3898SR7sWVRHbiQv+sHUtHnMvC1o3nW5rAcqnq3uOn07DSAppZYUkIGslDz6gXC7HfunPe7YVBgoEJASPcHA==
64806480

6481-
6482-
version "1.20.0"
6483-
resolved "https://registry.yarnpkg.com/body-parser/-/body-parser-1.20.0.tgz#3de69bd89011c11573d7bfee6a64f11b6bd27cc5"
6484-
integrity sha512-DfJ+q6EPcGKZD1QWUjSpqp+Q7bDQTsQIF4zfUAtZ6qk+H/3/QRhg9CEp39ss+/T2vw0+HaidC0ecJj/DRLIaKg==
6481+
6482+
version "1.20.2"
6483+
resolved "https://registry.yarnpkg.com/body-parser/-/body-parser-1.20.2.tgz#6feb0e21c4724d06de7ff38da36dad4f57a747fd"
6484+
integrity sha512-ml9pReCu3M61kGlqoTm2umSXTlRTuGTx0bfYj+uIUKKYycG5NtSbeetV3faSU6R7ajOPw0g/J1PvK4qNy7s5bA==
64856485
dependencies:
64866486
bytes "3.1.2"
6487-
content-type "~1.0.4"
6487+
content-type "~1.0.5"
64886488
debug "2.6.9"
64896489
depd "2.0.0"
64906490
destroy "1.2.0"
64916491
http-errors "2.0.0"
64926492
iconv-lite "0.4.24"
64936493
on-finished "2.4.1"
6494-
qs "6.10.3"
6495-
raw-body "2.5.1"
6494+
qs "6.11.0"
6495+
raw-body "2.5.2"
64966496
type-is "~1.6.18"
64976497
unpipe "1.0.0"
64986498

@@ -7345,6 +7345,11 @@ content-type@~1.0.4:
73457345
resolved "https://registry.yarnpkg.com/content-type/-/content-type-1.0.4.tgz#e138cc75e040c727b1966fe5e5f8c9aee256fe3b"
73467346
integrity sha512-hIP3EEPs8tB9AT1L+NUqtwOAps4mk2Zob89MWXMHjHWg9milF/j4osnnQLXBCBFBk/tvIG/tUc9mOUJiPBhPXA==
73477347

7348+
content-type@~1.0.5:
7349+
version "1.0.5"
7350+
resolved "https://registry.yarnpkg.com/content-type/-/content-type-1.0.5.tgz#8b773162656d1d1086784c8f23a54ce6d73d7918"
7351+
integrity sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==
7352+
73487353
continuation-local-storage@^3.2.1:
73497354
version "3.2.1"
73507355
resolved "https://registry.yarnpkg.com/continuation-local-storage/-/continuation-local-storage-3.2.1.tgz#11f613f74e914fe9b34c92ad2d28fe6ae1db7ffb"
@@ -7370,7 +7375,12 @@ [email protected]:
73707375
resolved "https://registry.yarnpkg.com/cookie-signature/-/cookie-signature-1.0.6.tgz#e303a882b342cc3ee8ca513a79999734dab3ae2c"
73717376
integrity sha1-4wOogrNCzD7oylE6eZmXNNqzriw=
73727377

7373-
[email protected], cookie@^0.5.0:
7378+
7379+
version "0.6.0"
7380+
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.6.0.tgz#2798b04b071b0ecbff0dbb62a505a8efa4e19051"
7381+
integrity sha512-U71cyTamuh1CRNCfpGY6to28lxvNwPG4Guz/EVjgf3Jmzv0vlDp1atT9eS5dDjMYHucpHbWns6Lwf3BKz6svdw==
7382+
7383+
cookie@^0.5.0:
73747384
version "0.5.0"
73757385
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.5.0.tgz#d1f5d71adec6558c58f389987c366aa47e994f8b"
73767386
integrity sha512-YZ3GUyn/o8gfKJlnlX7g7xq4gyO6OSuhGPKaaGssGB2qgDUS0gPgtTvoyZLTt9Ab6dC4hfc9dV5arkvc/OCmrw==
@@ -9317,17 +9327,17 @@ expect@^29.7.0:
93179327
jest-message-util "^29.7.0"
93189328
jest-util "^29.7.0"
93199329

9320-
express@^4.17.3:
9321-
version "4.18.1"
9322-
resolved "https://registry.yarnpkg.com/express/-/express-4.18.1.tgz#7797de8b9c72c857b9cd0e14a5eea80666267caf"
9323-
integrity sha512-zZBcOX9TfehHQhtupq57OF8lFZ3UZi08Y97dwFCkD8p9d/d2Y3M+ykKcwaMDEL+4qyUolgBDX6AblpR3fL212Q==
9330+
express@4.19.2, express@^4.17.3:
9331+
version "4.19.2"
9332+
resolved "https://registry.yarnpkg.com/express/-/express-4.19.2.tgz#e25437827a3aa7f2a827bc8171bbbb664a356465"
9333+
integrity sha512-5T6nhjsT+EOMzuck8JjBHARTHfMht0POzlA60WV2pMD3gyXw2LZnZ+ueGdNxG+0calOJcWKbpFcuzLZ91YWq9Q==
93249334
dependencies:
93259335
accepts "~1.3.8"
93269336
array-flatten "1.1.1"
9327-
body-parser "1.20.0"
9337+
body-parser "1.20.2"
93289338
content-disposition "0.5.4"
93299339
content-type "~1.0.4"
9330-
cookie "0.5.0"
9340+
cookie "0.6.0"
93319341
cookie-signature "1.0.6"
93329342
debug "2.6.9"
93339343
depd "2.0.0"
@@ -9343,7 +9353,7 @@ express@^4.17.3:
93439353
parseurl "~1.3.3"
93449354
path-to-regexp "0.1.7"
93459355
proxy-addr "~2.0.7"
9346-
qs "6.10.3"
9356+
qs "6.11.0"
93479357
range-parser "~1.2.1"
93489358
safe-buffer "5.2.1"
93499359
send "0.18.0"
@@ -9788,10 +9798,10 @@ flow-parser@0.*:
97889798
resolved "https://registry.yarnpkg.com/flow-parser/-/flow-parser-0.204.0.tgz#48515c3d289557d465b409c60ebdf4e783af491e"
97899799
integrity sha512-cQhNPLOk5NFyDXBC8WE8dy2Gls+YqKI3FNqQbJ7UrbFyd30IdEX3t27u3VsnoVK22I872+PWeb1KhHxDgu7kAg==
97909800

9791-
follow-redirects@^1.0.0:
9792-
version "1.15.4"
9793-
resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.15.4.tgz#cdc7d308bf6493126b17ea2191ea0ccf3e535adf"
9794-
integrity sha512-Cr4D/5wlrb0z9dgERpUL3LrmPKVDsETIJhaCMeDfuFYcqa5bldGV6wBsAN6X/vxlXQtFBMrXdXxdL8CbDTGniw==
9801+
follow-redirects@1.15.6, follow-redirects@^1.0.0:
9802+
version "1.15.6"
9803+
resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.15.6.tgz#7f815c0cda4249c74ff09e95ef97c23b5fd0399b"
9804+
integrity sha512-wWN62YITEaOpSK584EZXJafH1AGpO8RVgElfkuXbTOrPX4fIfOyEpW/CsiNd8JdYrAoOvafRTOEnvsO++qCqFA==
97959805

97969806
for-each@^0.3.3:
97979807
version "0.3.3"
@@ -14548,7 +14558,14 @@ pure-rand@^6.0.0:
1454814558
resolved "https://registry.yarnpkg.com/pure-rand/-/pure-rand-6.0.1.tgz#31207dddd15d43f299fdcdb2f572df65030c19af"
1454914559
integrity sha512-t+x1zEHDjBwkDGY5v5ApnZ/utcd4XYDiJsaQQoptTXgUXX95sDg1elCdJghzicm7n2mbCBJ3uYWr6M22SO19rg==
1455014560

14551-
[email protected], qs@^6.10.0, qs@^6.9.1:
14561+
14562+
version "6.11.0"
14563+
resolved "https://registry.yarnpkg.com/qs/-/qs-6.11.0.tgz#fd0d963446f7a65e1367e01abd85429453f0c37a"
14564+
integrity sha512-MvjoMCJwEarSbUYk5O+nmoSzSutSsTwF85zcHPQ9OrlFoZOYIjaqBAJIqIXjptyD5vThxGq52Xu/MaJzRkIk4Q==
14565+
dependencies:
14566+
side-channel "^1.0.4"
14567+
14568+
qs@^6.10.0, qs@^6.9.1:
1455214569
version "6.10.3"
1455314570
resolved "https://registry.yarnpkg.com/qs/-/qs-6.10.3.tgz#d6cde1b2ffca87b5aa57889816c5f81535e22e8e"
1455414571
integrity sha512-wr7M2E0OFRfIfJZjKGieI8lBKb7fRCH4Fv5KNPEs7gJ8jadvotdsS08PzOKR7opXhZ/Xkjtt3WF9g38drmyRqQ==
@@ -14621,10 +14638,10 @@ range-parser@^1.2.1, range-parser@~1.2.1:
1462114638
resolved "https://registry.yarnpkg.com/range-parser/-/range-parser-1.2.1.tgz#3cf37023d199e1c24d1a55b84800c2f3e6468031"
1462214639
integrity sha512-Hrgsx+orqoygnmhFbKaHE6c296J+HTAQXoxEF6gNupROmmGJRoyzfG3ccAveqCBrwr/2yxQ5BVd/GTl5agOwSg==
1462314640

14624-
14625-
version "2.5.1"
14626-
resolved "https://registry.yarnpkg.com/raw-body/-/raw-body-2.5.1.tgz#fe1b1628b181b700215e5fd42389f98b71392857"
14627-
integrity sha512-qqJBtEyVgS0ZmPGdCFPWJ3FreoqvG4MVQln/kCgF7Olq95IbOp0/BWyMwbdtn4VTvkM8Y7khCQ2Xgk/tcrCXig==
14641+
14642+
version "2.5.2"
14643+
resolved "https://registry.yarnpkg.com/raw-body/-/raw-body-2.5.2.tgz#99febd83b90e08975087e8f1f9419a149366b68a"
14644+
integrity sha512-8zGqypfENjCIqGhgXToC8aB2r7YrBX+AQAfIPs/Mlk+BtPTztOvTS01NRW/3Eh60J+a48lt8qsCzirQ6loCVfA==
1462814645
dependencies:
1462914646
bytes "3.1.2"
1463014647
http-errors "2.0.0"
@@ -17039,10 +17056,10 @@ undici-types@~5.26.4:
1703917056
resolved "https://registry.yarnpkg.com/undici-types/-/undici-types-5.26.5.tgz#bcd539893d00b56e964fd2657a4866b221a65617"
1704017057
integrity sha512-JlCMO+ehdEIKqlFxk6IfVoAUVmgz7cU7zD/h9XZ0qzeosSHmUJVOzSQvvYSYWXkFXC+IfLKSIffhv0sVZup6pA==
1704117058

17042-
undici@^5.28.3:
17043-
version "5.28.3"
17044-
resolved "https://registry.yarnpkg.com/undici/-/undici-5.28.3.tgz#a731e0eff2c3fcfd41c1169a869062be222d1e5b"
17045-
integrity sha512-3ItfzbrhDlINjaP0duwnNsKpDQk3acHI3gVJ1z4fmwMK31k5G9OVIAMLSIaP6w4FaGkaAkN6zaQO9LUvZ1t7VA==
17059+
undici@5.28.4, undici@^5.28.3:
17060+
version "5.28.4"
17061+
resolved "https://registry.yarnpkg.com/undici/-/undici-5.28.4.tgz#6b280408edb6a1a604a9b20340f45b422e373068"
17062+
integrity sha512-72RFADWFqKmUb2hmmvNODKL3p9hcB6Gt2DOQMis1SEBaV6a4MH8soBvzg+95CYhCKPFedut2JY9bMfrDl9D23g==
1704617063
dependencies:
1704717064
"@fastify/busboy" "^2.0.0"
1704817065

0 commit comments

Comments
 (0)