Skip to content

Commit 9f137f8

Browse files
Merge pull request #30 from EvgeneOskin/fix-CVE-2020-15168
Update isomorphic-fetch and nock
2 parents d107707 + af8a187 commit 9f137f8

File tree

2 files changed

+46
-71
lines changed

2 files changed

+46
-71
lines changed

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,12 +36,12 @@
3636
"eslint": "^3.10.1",
3737
"eslint-config-airbnb-base": "^10.0.1",
3838
"eslint-plugin-import": "^2.2.0",
39-
"nock": "^9.0.2",
39+
"nock": "^13.0.7",
4040
"nyc": "^9.0.1"
4141
},
4242
"dependencies": {
4343
"es6-error": "^4.0.0",
44-
"isomorphic-fetch": "^2.2.1",
44+
"isomorphic-fetch": "^3.0.0",
4545
"qs": "^6.3.0"
4646
},
4747
"ava": {

yarn.lock

Lines changed: 44 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -139,10 +139,6 @@ assert-plus@^1.0.0:
139139
version "1.0.0"
140140
resolved "https://registry.yarnpkg.com/assert-plus/-/assert-plus-1.0.0.tgz#f12e0f3c5d77b0b1cdd9146942e4e96c1e4dd525"
141141

142-
assertion-error@^1.0.1:
143-
version "1.0.2"
144-
resolved "https://registry.yarnpkg.com/assertion-error/-/assertion-error-1.0.2.tgz#13ca515d86206da0bac66e834dd397d87581094c"
145-
146142
async-each@^1.0.0:
147143
version "1.0.1"
148144
resolved "https://registry.yarnpkg.com/async-each/-/async-each-1.0.1.tgz#19d386a1d9edc6e7c1c85d388aedbcc56d33602d"
@@ -1037,14 +1033,6 @@ caseless@~0.11.0:
10371033
version "0.11.0"
10381034
resolved "https://registry.yarnpkg.com/caseless/-/caseless-0.11.0.tgz#715b96ea9841593cc33067923f5ec60ebda4f7d7"
10391035

1040-
"chai@>=1.9.2 <4.0.0":
1041-
version "3.5.0"
1042-
resolved "https://registry.yarnpkg.com/chai/-/chai-3.5.0.tgz#4d02637b067fe958bdbfdd3a40ec56fef7373247"
1043-
dependencies:
1044-
assertion-error "^1.0.1"
1045-
deep-eql "^0.1.3"
1046-
type-detect "^1.0.0"
1047-
10481036
chalk@^0.4.0:
10491037
version "0.4.0"
10501038
resolved "https://registry.yarnpkg.com/chalk/-/chalk-0.4.0.tgz#5199a3ddcd0c1efe23bc08c1b027b06176e0c64f"
@@ -1263,16 +1251,17 @@ debug@^2.1.1, debug@^2.2.0:
12631251
dependencies:
12641252
ms "0.7.2"
12651253

1254+
debug@^4.1.0:
1255+
version "4.3.1"
1256+
resolved "https://registry.yarnpkg.com/debug/-/debug-4.3.1.tgz#f0d229c505e0c6d8c49ac553d1b13dc183f6b2ee"
1257+
integrity sha512-doEwdvm4PCeK4K3RQN2ZC2BYUBaxwLARCqZmMjtF8a51J2Rb0xpVloFRnCODwqjpwnAoao4pelN8l3RJdv3gRQ==
1258+
dependencies:
1259+
ms "2.1.2"
1260+
12661261
decamelize@^1.1.1, decamelize@^1.1.2:
12671262
version "1.2.0"
12681263
resolved "https://registry.yarnpkg.com/decamelize/-/decamelize-1.2.0.tgz#f6534d15148269b20352e7bee26f501f9a191290"
12691264

1270-
deep-eql@^0.1.3:
1271-
version "0.1.3"
1272-
resolved "https://registry.yarnpkg.com/deep-eql/-/deep-eql-0.1.3.tgz#ef558acab8de25206cd713906d74e56930eb69f2"
1273-
dependencies:
1274-
type-detect "0.1.1"
1275-
12761265
deep-equal@^1.0.0:
12771266
version "1.0.1"
12781267
resolved "https://registry.yarnpkg.com/deep-equal/-/deep-equal-1.0.1.tgz#f5d260292b660e084eff4cdbc9f08ad3247448b5"
@@ -1354,12 +1343,6 @@ empower-core@^0.6.1:
13541343
call-signature "0.0.2"
13551344
core-js "^2.0.0"
13561345

1357-
encoding@^0.1.11:
1358-
version "0.1.12"
1359-
resolved "https://registry.yarnpkg.com/encoding/-/encoding-0.1.12.tgz#538b66f3ee62cd1ab51ec323829d1f9480c74beb"
1360-
dependencies:
1361-
iconv-lite "~0.4.13"
1362-
13631346
error-ex@^1.2.0:
13641347
version "1.3.0"
13651348
resolved "https://registry.yarnpkg.com/error-ex/-/error-ex-1.3.0.tgz#e67b43f3e82c96ea3a584ffee0b9fc3325d802d9"
@@ -1916,10 +1899,6 @@ http-signature@~1.1.0:
19161899
jsprim "^1.2.2"
19171900
sshpk "^1.7.0"
19181901

1919-
iconv-lite@~0.4.13:
1920-
version "0.4.15"
1921-
resolved "https://registry.yarnpkg.com/iconv-lite/-/iconv-lite-0.4.15.tgz#fe265a218ac6a57cfe854927e9d04c19825eddeb"
1922-
19231902
ignore-by-default@^1.0.0, ignore-by-default@^1.0.1:
19241903
version "1.0.1"
19251904
resolved "https://registry.yarnpkg.com/ignore-by-default/-/ignore-by-default-1.0.1.tgz#48ca6d72f6c6a3af00a9ad4ae6876be3889e2b09"
@@ -2147,7 +2126,7 @@ is-retry-allowed@^1.0.0:
21472126
version "1.1.0"
21482127
resolved "https://registry.yarnpkg.com/is-retry-allowed/-/is-retry-allowed-1.1.0.tgz#11a060568b67339444033d0125a61a20d564fb34"
21492128

2150-
is-stream@^1.0.0, is-stream@^1.0.1:
2129+
is-stream@^1.0.0:
21512130
version "1.1.0"
21522131
resolved "https://registry.yarnpkg.com/is-stream/-/is-stream-1.1.0.tgz#12d4a3dd4e68e0b79ceb8dbc84173ae80d91ca44"
21532132

@@ -2177,12 +2156,13 @@ isobject@^2.0.0:
21772156
dependencies:
21782157
isarray "1.0.0"
21792158

2180-
isomorphic-fetch@^2.2.1:
2181-
version "2.2.1"
2182-
resolved "https://registry.yarnpkg.com/isomorphic-fetch/-/isomorphic-fetch-2.2.1.tgz#611ae1acf14f5e81f729507472819fe9733558a9"
2159+
isomorphic-fetch@^3.0.0:
2160+
version "3.0.0"
2161+
resolved "https://registry.yarnpkg.com/isomorphic-fetch/-/isomorphic-fetch-3.0.0.tgz#0267b005049046d2421207215d45d6a262b8b8b4"
2162+
integrity sha512-qvUtwJ3j6qwsF3jLxkZ72qCgjMysPzDfeV240JHiGZsANBYd+EEuu35v7dfrJ9Up0Ak07D7GGSkGhCHTqg/5wA==
21832163
dependencies:
2184-
node-fetch "^1.0.1"
2185-
whatwg-fetch ">=0.10.0"
2164+
node-fetch "^2.6.1"
2165+
whatwg-fetch "^3.4.1"
21862166

21872167
isstream@~0.1.2:
21882168
version "0.1.2"
@@ -2354,14 +2334,15 @@ lodash.pickby@^4.6.0:
23542334
version "4.6.0"
23552335
resolved "https://registry.yarnpkg.com/lodash.pickby/-/lodash.pickby-4.6.0.tgz#7dea21d8c18d7703a27c704c15d3b84a67e33aff"
23562336

2337+
lodash.set@^4.3.2:
2338+
version "4.3.2"
2339+
resolved "https://registry.yarnpkg.com/lodash.set/-/lodash.set-4.3.2.tgz#d8757b1da807dde24816b0d6a84bea1a76230b23"
2340+
integrity sha1-2HV7HagH3eJIFrDWqEvqGnYjCyM=
2341+
23572342
lodash@^4.0.0, lodash@^4.2.0, lodash@^4.3.0:
23582343
version "4.17.2"
23592344
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.2.tgz#34a3055babe04ce42467b607d700072c7ff6bf42"
23602345

2361-
lodash@~4.9.0:
2362-
version "4.9.0"
2363-
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.9.0.tgz#4c20d742f03ce85dc700e0dd7ab9bcab85e6fc14"
2364-
23652346
loose-envify@^1.0.0:
23662347
version "1.3.0"
23672348
resolved "https://registry.yarnpkg.com/loose-envify/-/loose-envify-1.3.0.tgz#6b26248c42f6d4fa4b0d8542f78edfcde35642a8"
@@ -2487,6 +2468,11 @@ [email protected], ms@^0.7.1:
24872468
version "0.7.2"
24882469
resolved "https://registry.yarnpkg.com/ms/-/ms-0.7.2.tgz#ae25cf2512b3885a1d95d7f037868d8431124765"
24892470

2471+
2472+
version "2.1.2"
2473+
resolved "https://registry.yarnpkg.com/ms/-/ms-2.1.2.tgz#d09d1f357b443f493382a8eb3ccd183872ae6009"
2474+
integrity sha512-sGkPx+VjMtmA6MX27oA4FBFELFCZZ4S4XqeGOXCv68tT+jb3vk/RyaKWP0PTKyWtmLSM0b+adUTEvbs1PEaH2w==
2475+
24902476
multimatch@^2.1.0:
24912477
version "2.1.0"
24922478
resolved "https://registry.yarnpkg.com/multimatch/-/multimatch-2.1.0.tgz#9c7906a22fb4c02919e2f5f75161b4cdbd4b2a2b"
@@ -2512,25 +2498,20 @@ neo-async@^2.6.0:
25122498
version "2.6.2"
25132499
resolved "https://registry.yarnpkg.com/neo-async/-/neo-async-2.6.2.tgz#b4aafb93e3aeb2d8174ca53cf163ab7d7308305f"
25142500

2515-
nock@^9.0.2:
2516-
version "9.0.2"
2517-
resolved "https://registry.yarnpkg.com/nock/-/nock-9.0.2.tgz#f6a5f4a8d560d61f48b5ad428ccff8dc9b62701e"
2501+
nock@^13.0.7:
2502+
version "13.0.7"
2503+
resolved "https://registry.yarnpkg.com/nock/-/nock-13.0.7.tgz#9bc718c66bd0862dfa14601a9ba678a406127910"
2504+
integrity sha512-WBz73VYIjdbO6BwmXODRQLtn7B5tldA9pNpWJe5QTtTEscQlY5KXU4srnGzBOK2fWakkXj69gfTnXGzmrsaRWw==
25182505
dependencies:
2519-
chai ">=1.9.2 <4.0.0"
2520-
debug "^2.2.0"
2521-
deep-equal "^1.0.0"
2506+
debug "^4.1.0"
25222507
json-stringify-safe "^5.0.1"
2523-
lodash "~4.9.0"
2524-
mkdirp "^0.5.0"
2525-
propagate "0.4.0"
2526-
qs "^6.0.2"
2508+
lodash.set "^4.3.2"
2509+
propagate "^2.0.0"
25272510

2528-
node-fetch@^1.0.1:
2529-
version "1.6.3"
2530-
resolved "https://registry.yarnpkg.com/node-fetch/-/node-fetch-1.6.3.tgz#dc234edd6489982d58e8f0db4f695029abcd8c04"
2531-
dependencies:
2532-
encoding "^0.1.11"
2533-
is-stream "^1.0.1"
2511+
node-fetch@^2.6.1:
2512+
version "2.6.1"
2513+
resolved "https://registry.yarnpkg.com/node-fetch/-/node-fetch-2.6.1.tgz#045bd323631f76ed2e2b55573394416b639a0052"
2514+
integrity sha512-V4aYg89jEoVRxRb2fJdAg8FHvI7cEyYdVAh94HH0UIK8oJxUfkjlDQN9RbMx+bEjP7+ggMiFRprSti032Oipxw==
25342515

25352516
node-pre-gyp@^0.6.29:
25362517
version "0.6.31"
@@ -2915,9 +2896,10 @@ progress@^1.1.8:
29152896
version "1.1.8"
29162897
resolved "https://registry.yarnpkg.com/progress/-/progress-1.1.8.tgz#e260c78f6161cdd9b0e56cc3e0a85de17c7a57be"
29172898

2918-
2919-
version "0.4.0"
2920-
resolved "https://registry.yarnpkg.com/propagate/-/propagate-0.4.0.tgz#f3fcca0a6fe06736a7ba572966069617c130b481"
2899+
propagate@^2.0.0:
2900+
version "2.0.1"
2901+
resolved "https://registry.yarnpkg.com/propagate/-/propagate-2.0.1.tgz#40cdedab18085c792334e64f0ac17256d38f9a45"
2902+
integrity sha512-vGrhOavPSTz4QVNuBNdcNXePNdNMaO1xj9yBeH1ScQPjk/rhg9sSlCXPhMkFuaNNW/syTvYqsnbIJxMBfRbbag==
29212903

29222904
pseudomap@^1.0.1:
29232905
version "1.0.2"
@@ -2927,7 +2909,7 @@ punycode@^1.4.1:
29272909
version "1.4.1"
29282910
resolved "https://registry.yarnpkg.com/punycode/-/punycode-1.4.1.tgz#c0d5a63b2718800ad8e1eb0fa5269c84dd41845e"
29292911

2930-
qs@^6.0.2, qs@^6.3.0, qs@~6.3.0:
2912+
qs@^6.3.0, qs@~6.3.0:
29312913
version "6.3.2"
29322914
resolved "https://registry.yarnpkg.com/qs/-/qs-6.3.2.tgz#e75bd5f6e268122a2a0e0bda630b2550c166502c"
29332915

@@ -3478,14 +3460,6 @@ type-check@~0.3.2:
34783460
dependencies:
34793461
prelude-ls "~1.1.2"
34803462

3481-
3482-
version "0.1.1"
3483-
resolved "https://registry.yarnpkg.com/type-detect/-/type-detect-0.1.1.tgz#0ba5ec2a885640e470ea4e8505971900dac58822"
3484-
3485-
type-detect@^1.0.0:
3486-
version "1.0.0"
3487-
resolved "https://registry.yarnpkg.com/type-detect/-/type-detect-1.0.0.tgz#762217cc06db258ec48908a1298e8b95121e8ea2"
3488-
34893463
type-name@^2.0.1:
34903464
version "2.0.2"
34913465
resolved "https://registry.yarnpkg.com/type-name/-/type-name-2.0.2.tgz#efe7d4123d8ac52afff7f40c7e4dec5266008fb4"
@@ -3574,9 +3548,10 @@ [email protected]:
35743548
dependencies:
35753549
extsprintf "1.0.2"
35763550

3577-
whatwg-fetch@>=0.10.0:
3578-
version "2.0.1"
3579-
resolved "https://registry.yarnpkg.com/whatwg-fetch/-/whatwg-fetch-2.0.1.tgz#078b9461bbe91cea73cbce8bb122a05f9e92b772"
3551+
whatwg-fetch@^3.4.1:
3552+
version "3.5.0"
3553+
resolved "https://registry.yarnpkg.com/whatwg-fetch/-/whatwg-fetch-3.5.0.tgz#605a2cd0a7146e5db141e29d1c62ab84c0c4c868"
3554+
integrity sha512-jXkLtsR42xhXg7akoDKvKWE40eJeI+2KZqcp2h3NsOrRnDvtWX36KcKl30dy+hxECivdk2BVUHVNrPtoMBUx6A==
35803555

35813556
which-module@^1.0.0:
35823557
version "1.0.0"

0 commit comments

Comments
 (0)