From cd2b5bb81408cdbe5a30f4b74dc92eabe9e95fea Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 2 Nov 2024 11:03:04 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-UNDICI-3323844 - https://snyk.io/vuln/SNYK-JS-UNDICI-3323845 - https://snyk.io/vuln/SNYK-JS-UNDICI-5962466 - https://snyk.io/vuln/SNYK-JS-UNDICI-6252336 - https://snyk.io/vuln/SNYK-JS-UNDICI-6564963 - https://snyk.io/vuln/SNYK-JS-UNDICI-6564964 --- package-lock.json | 22 ++++++++++++++++------ package.json | 2 +- 2 files changed, 17 insertions(+), 7 deletions(-) diff --git a/package-lock.json b/package-lock.json index 4ad5d468..fd496fce 100644 --- a/package-lock.json +++ b/package-lock.json @@ -58,7 +58,7 @@ "rxjs": "^7.8.0", "tslib": "^2.3.0", "ua-parser-js": "^1.0.38", - "undici": "^5.14.0", + "undici": "^5.28.4", "zod": "^3.23.8" }, "devDependencies": { @@ -5998,6 +5998,15 @@ "node": "^12.22.0 || ^14.17.0 || >=16.0.0" } }, + "node_modules/@fastify/busboy": { + "version": "2.1.1", + "resolved": "https://registry.npmjs.org/@fastify/busboy/-/busboy-2.1.1.tgz", + "integrity": "sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA==", + "license": "MIT", + "engines": { + "node": ">=14" + } + }, "node_modules/@hapi/hoek": { "version": "9.3.0", "resolved": "https://registry.npmjs.org/@hapi/hoek/-/hoek-9.3.0.tgz", @@ -28345,14 +28354,15 @@ "integrity": "sha512-IevTus0SbGwQzYh3+fRsAMTVVPOoIVufzacXcHPmdlle1jUpq7BRL+mw3dgeLanvGZdwwbWhRV6XrcFNdBmjWA==" }, "node_modules/undici": { - "version": "5.14.0", - "resolved": "https://registry.npmjs.org/undici/-/undici-5.14.0.tgz", - "integrity": "sha512-yJlHYw6yXPPsuOH0x2Ib1Km61vu4hLiRRQoafs+WUgX1vO64vgnxiCEN9dpIrhZyHFsai3F0AEj4P9zy19enEQ==", + "version": "5.28.4", + "resolved": "https://registry.npmjs.org/undici/-/undici-5.28.4.tgz", + "integrity": "sha512-72RFADWFqKmUb2hmmvNODKL3p9hcB6Gt2DOQMis1SEBaV6a4MH8soBvzg+95CYhCKPFedut2JY9bMfrDl9D23g==", + "license": "MIT", "dependencies": { - "busboy": "^1.6.0" + "@fastify/busboy": "^2.0.0" }, "engines": { - "node": ">=12.18" + "node": ">=14.0" } }, "node_modules/unherit": { diff --git a/package.json b/package.json index 03620383..48d705f1 100644 --- a/package.json +++ b/package.json @@ -112,7 +112,7 @@ "rxjs": "^7.8.0", "tslib": "^2.3.0", "ua-parser-js": "^1.0.38", - "undici": "^5.14.0", + "undici": "^5.28.4", "zod": "^3.23.8" } }