From 0de634a084a01974ed5a75b01133bba2d2123508 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Mon, 19 Jan 2026 07:54:30 +0000 Subject: [PATCH] fix(deps): update dependency vm2 to v3.10.0 [security] --- apps/core/package.json | 2 +- pnpm-lock.yaml | 12 ++++++------ 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/apps/core/package.json b/apps/core/package.json index e599c982ee2..03144826c42 100644 --- a/apps/core/package.json +++ b/apps/core/package.json @@ -128,7 +128,7 @@ "snakecase-keys": "6.0.0", "source-map-support": "^0.5.21", "ua-parser-js": "2.0.7", - "vm2": "3.9.19", + "vm2": "3.10.0", "wildcard-match": "5.1.4", "xss": "1.0.15", "zx-cjs": "7.0.7-0" diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 460903d629e..8ac9911756b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -319,8 +319,8 @@ importers: specifier: 2.0.7 version: 2.0.7 vm2: - specifier: 3.9.19 - version: 3.9.19 + specifier: 3.10.0 + version: 3.10.0 wildcard-match: specifier: 5.1.4 version: 5.1.4 @@ -6075,6 +6075,7 @@ packages: tar@6.2.1: resolution: {integrity: sha512-DZ4yORTwrbTj/7MZYq2w+/ZFdI6OZ/f9SFHR+71gIVUZhOQPHzVCLpvRnPgyaMpfWxxk/4ONva3GQSyNIKRv6A==} engines: {node: '>=10'} + deprecated: Old versions of tar are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exhorbitant rates) by contacting i@izs.me terser-webpack-plugin@5.3.16: resolution: {integrity: sha512-h9oBFCWrq78NyWWVcSwZarJkZ01c2AyGrzs1crmHZO3QUg9D61Wu4NPjBy69n7JqylFF5y+CsUZYmYEIZ3mR+Q==} @@ -6565,10 +6566,9 @@ packages: jsdom: optional: true - vm2@3.9.19: - resolution: {integrity: sha512-J637XF0DHDMV57R6JyVsTak7nIL8gy5KH4r1HiwWLf/4GBbb5MKL5y7LpmF4A8E2nR6XmzpmMFQ7V7ppPTmUQg==} + vm2@3.10.0: + resolution: {integrity: sha512-3ggF4Bs0cw4M7Rxn19/Cv3nJi04xrgHwt4uLto+zkcZocaKwP/nKP9wPx6ggN2X0DSXxOOIc63BV1jvES19wXQ==} engines: {node: '>=6.0'} - deprecated: The library contains critical security issues and should not be used for production! The maintenance of the project has been discontinued. Consider migrating your code to isolated-vm. hasBin: true vue-eslint-parser@10.2.0: @@ -13578,7 +13578,7 @@ snapshots: - supports-color - terser - vm2@3.9.19: + vm2@3.10.0: dependencies: acorn: 8.15.0 acorn-walk: 8.3.4