Skip to content

Commit ac08b27

Browse files
deps: Bump nano to 10.1.3 to avoid axios <1.6.0 (#13328)
axios 1.6.0 fixes CVE-2023-45857 (https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459). Contributed by STMicroelectronics Signed-off-by: Torbjörn SVENSSON <[email protected]>
1 parent 120a822 commit ac08b27

File tree

2 files changed

+27
-35
lines changed

2 files changed

+27
-35
lines changed

dev-packages/application-package/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636
"deepmerge": "^4.2.2",
3737
"fs-extra": "^4.0.2",
3838
"is-electron": "^2.1.0",
39-
"nano": "^9.0.5",
39+
"nano": "^10.1.3",
4040
"resolve-package-path": "^4.0.3",
4141
"semver": "^7.5.4",
4242
"write-json-file": "^2.2.0"

yarn.lock

Lines changed: 26 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -2288,7 +2288,7 @@
22882288
dependencies:
22892289
"@types/node" "*"
22902290

2291-
"@types/tough-cookie@*", "@types/tough-cookie@^4.0.0":
2291+
"@types/tough-cookie@*":
22922292
version "4.0.5"
22932293
resolved "https://registry.yarnpkg.com/@types/tough-cookie/-/tough-cookie-4.0.5.tgz#cb6e2a691b70cb177c6e3ae9c1d2e8b2ea8cd304"
22942294
integrity sha512-/Ad8+nIOV7Rl++6f1BdKxFSMgmoqEoYbHRpPcx3JEfv8VRsQe9Z4mCXeJBzxs7mbHY/XOZZuXlRNfhpVPbs6ZA==
@@ -3245,21 +3245,6 @@ available-typed-arrays@^1.0.5:
32453245
resolved "https://registry.yarnpkg.com/available-typed-arrays/-/available-typed-arrays-1.0.5.tgz#92f95616501069d07d10edb2fc37d3e1c65123b7"
32463246
integrity sha512-DMD0KiN46eipeziST1LPP/STfDU0sufISXmjSgvVsoU2tqxctQeASejWcfNtxYKqETM1UxQ8sp2OrSBWpHY6sw==
32473247

3248-
axios-cookiejar-support@^1.0.1:
3249-
version "1.0.1"
3250-
resolved "https://registry.yarnpkg.com/axios-cookiejar-support/-/axios-cookiejar-support-1.0.1.tgz#7b32af7d932508546c68b1fc5ba8f562884162e1"
3251-
integrity sha512-IZJxnAJ99XxiLqNeMOqrPbfR7fRyIfaoSLdPUf4AMQEGkH8URs0ghJK/xtqBsD+KsSr3pKl4DEQjCn834pHMig==
3252-
dependencies:
3253-
is-redirect "^1.0.0"
3254-
pify "^5.0.0"
3255-
3256-
axios@^0.21.1:
3257-
version "0.21.4"
3258-
resolved "https://registry.yarnpkg.com/axios/-/axios-0.21.4.tgz#c67b90dc0568e5c1cf2b0b858c43ba28e2eda575"
3259-
integrity sha512-ut5vewkiu8jjGBdqpM44XxjuCjq9LAKeHVmoVfHVzy8eHgxxq8SbAVQNovDA8mVi05kP0Ea/n/UzcSHcTJQfNg==
3260-
dependencies:
3261-
follow-redirects "^1.14.0"
3262-
32633248
axios@^1.0.0:
32643249
version "1.6.6"
32653250
resolved "https://registry.yarnpkg.com/axios/-/axios-1.6.6.tgz#878db45401d91fe9e53aed8ac962ed93bde8dd1c"
@@ -3269,6 +3254,15 @@ axios@^1.0.0:
32693254
form-data "^4.0.0"
32703255
proxy-from-env "^1.1.0"
32713256

3257+
axios@^1.6.2:
3258+
version "1.6.7"
3259+
resolved "https://registry.yarnpkg.com/axios/-/axios-1.6.7.tgz#7b48c2e27c96f9c68a2f8f31e2ab19f59b06b0a7"
3260+
integrity sha512-/hDJGff6/c7u0hDkvkGxR/oy6CbCs8ziCsC7SqmhjfozqiJGc8Z11wrv9z9lYfY4K8l+H9TpjcMDX0xOZmx+RA==
3261+
dependencies:
3262+
follow-redirects "^1.15.4"
3263+
form-data "^4.0.0"
3264+
proxy-from-env "^1.1.0"
3265+
32723266
azure-devops-node-api@^11.0.1:
32733267
version "11.2.0"
32743268
resolved "https://registry.yarnpkg.com/azure-devops-node-api/-/azure-devops-node-api-11.2.0.tgz#bf04edbef60313117a0507415eed4790a420ad6b"
@@ -5776,7 +5770,7 @@ flatted@^3.2.9:
57765770
resolved "https://registry.yarnpkg.com/flatted/-/flatted-3.2.9.tgz#7eb4c67ca1ba34232ca9d2d93e9886e611ad7daf"
57775771
integrity sha512-36yxDn5H7OFZQla0/jFJmbIKTdZAQHngCedGxiMmpNfEZM0sdEeT+WczLQrjK6D7o2aiyLYDnkw0R3JK0Qv1RQ==
57785772

5779-
follow-redirects@^1.0.0, follow-redirects@^1.14.0, follow-redirects@^1.15.4:
5773+
follow-redirects@^1.0.0, follow-redirects@^1.15.4:
57805774
version "1.15.5"
57815775
resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.15.5.tgz#54d4d6d062c0fa7d9d17feb008461550e3ba8020"
57825776
integrity sha512-vSFWUON1B+yAw1VN4xMfxgn5fTUiaOzAJCKBwIIgT/+7CuGy9+r+5gITvP62j3RmaD5Ph65UaERdOSRGUzZtgw==
@@ -6925,11 +6919,6 @@ is-potential-custom-element-name@^1.0.1:
69256919
resolved "https://registry.yarnpkg.com/is-potential-custom-element-name/-/is-potential-custom-element-name-1.0.1.tgz#171ed6f19e3ac554394edf78caa05784a45bebb5"
69266920
integrity sha512-bCYeRA2rVibKZd+s2625gGnGF/t7DSqDs4dP7CrLA1m7jKWz6pps0LpYLJN8Q64HtmPKJ1hrN3nzPNKFEKOUiQ==
69276921

6928-
is-redirect@^1.0.0:
6929-
version "1.0.0"
6930-
resolved "https://registry.yarnpkg.com/is-redirect/-/is-redirect-1.0.0.tgz#1d03dded53bd8db0f30c26e4f95d36fc7c87dc24"
6931-
integrity sha512-cr/SlUEe5zOGmzvj9bUyC4LVvkNVAXu4GytXLNMr1pny+a65MpQ9IJzFHD5vi7FyJgb4qt27+eS3TuQnqB+RQw==
6932-
69336922
is-regex@^1.1.4:
69346923
version "1.1.4"
69356924
resolved "https://registry.yarnpkg.com/is-regex/-/is-regex-1.1.4.tgz#eef5663cd59fa4c0ae339505323df6854bb15958"
@@ -8370,16 +8359,14 @@ nan@^2.14.0, nan@^2.17.0, nan@^2.18.0:
83708359
resolved "https://registry.yarnpkg.com/nan/-/nan-2.18.0.tgz#26a6faae7ffbeb293a39660e88a76b82e30b7554"
83718360
integrity sha512-W7tfG7vMOGtD30sHoZSSc/JVYiyDPEyQVso/Zz+/uQd0B0L46gtC+pHha5FFMRpil6fm/AoEcRWyOVi4+E/f8w==
83728361

8373-
nano@^9.0.5:
8374-
version "9.0.5"
8375-
resolved "https://registry.yarnpkg.com/nano/-/nano-9.0.5.tgz#2b767819f612907a3ac09b21f2929d4097407262"
8376-
integrity sha512-fEAhwAdXh4hDDnC8cYJtW6D8ivOmpvFAqT90+zEuQREpRkzA/mJPcI4EKv15JUdajaqiLTXNoKK6PaRF+/06DQ==
8362+
nano@^10.1.3:
8363+
version "10.1.3"
8364+
resolved "https://registry.yarnpkg.com/nano/-/nano-10.1.3.tgz#5cb1ad14add4c9c82d53a79159848dafa84e7a13"
8365+
integrity sha512-q/hKQJJH3FhkkuJ3ojbgDph2StlSXFBPNkpZBZlsvZDbuYfxKJ4VtunEeilthcZtuIplIk1zVX5o2RgKTUTO+Q==
83778366
dependencies:
8378-
"@types/tough-cookie" "^4.0.0"
8379-
axios "^0.21.1"
8380-
axios-cookiejar-support "^1.0.1"
8381-
qs "^6.9.4"
8382-
tough-cookie "^4.0.0"
8367+
axios "^1.6.2"
8368+
node-abort-controller "^3.0.1"
8369+
qs "^6.11.0"
83838370

83848371
83858372
version "3.3.1"
@@ -8451,6 +8438,11 @@ node-abi@^2.21.0, node-abi@^2.7.0:
84518438
dependencies:
84528439
semver "^5.4.1"
84538440

8441+
node-abort-controller@^3.0.1:
8442+
version "3.1.1"
8443+
resolved "https://registry.yarnpkg.com/node-abort-controller/-/node-abort-controller-3.1.1.tgz#a94377e964a9a37ac3976d848cb5c765833b8548"
8444+
integrity sha512-AGK2yQKIjRuqnc6VkX2Xj5d+QW8xZ87pa1UK6yA6ouUyuxfHuMP6umE5QK7UmTeOAymo+Zx1Fxiuw9rVx8taHQ==
8445+
84548446
node-addon-api@^3.0.0, node-addon-api@^3.0.2, node-addon-api@^3.1.0, node-addon-api@^3.2.1:
84558447
version "3.2.1"
84568448
resolved "https://registry.yarnpkg.com/node-addon-api/-/node-addon-api-3.2.1.tgz#81325e0a2117789c0128dab65e7e38f07ceba161"
@@ -9364,7 +9356,7 @@ picomatch@^2.0.4, picomatch@^2.2.1, picomatch@^2.3.1:
93649356
resolved "https://registry.yarnpkg.com/picomatch/-/picomatch-2.3.1.tgz#3ba3833733646d9d3e4995946c1365a67fb07a42"
93659357
integrity sha512-JU3teHTNjmE2VCGFzuY8EXzCDVwEqB2a8fsIvwaStHhAWJEeVd1o1QD80CU6+ZdEXXSLbSsuLwJjkCBWqRQUVA==
93669358

9367-
[email protected], pify@^5.0.0:
9359+
93689360
version "5.0.0"
93699361
resolved "https://registry.yarnpkg.com/pify/-/pify-5.0.0.tgz#1f5eca3f5e87ebec28cc6d54a0e4aaf00acc127f"
93709362
integrity sha512-eW/gHNMlxdSP6dmG6uJip6FXN0EQBwm2clYYd8Wul42Cwu/DK8HEftzsapcNdYe2MfLiIwZqsDk2RDEsTE79hA==
@@ -9729,7 +9721,7 @@ [email protected]:
97299721
dependencies:
97309722
side-channel "^1.0.4"
97319723

9732-
qs@^6.4.0, qs@^6.9.1, qs@^6.9.4:
9724+
qs@^6.11.0, qs@^6.4.0, qs@^6.9.1:
97339725
version "6.11.2"
97349726
resolved "https://registry.yarnpkg.com/qs/-/qs-6.11.2.tgz#64bea51f12c1f5da1bc01496f48ffcff7c69d7d9"
97359727
integrity sha512-tDNIz22aBzCDxLtVH++VnTfzxlfeK5CbqohpSqpJgj1Wg/cQbStNAz3NuqCs5vV+pjBsK4x4pN9HlVh7rcYRiA==
@@ -11277,7 +11269,7 @@ [email protected]:
1127711269
resolved "https://registry.yarnpkg.com/toidentifier/-/toidentifier-1.0.1.tgz#3be34321a88a820ed1bd80dfaa33e479fbb8dd35"
1127811270
integrity sha512-o5sSPKEkg/DIQNmH43V0/uerLrpzVedkUh8tGNvaeXpfpuwjKenlSox/2O/BTlZUtEe+JG7s5YhEz608PlAHRA==
1127911271

11280-
tough-cookie@^4.0.0, tough-cookie@^4.1.2:
11272+
tough-cookie@^4.1.2:
1128111273
version "4.1.3"
1128211274
resolved "https://registry.yarnpkg.com/tough-cookie/-/tough-cookie-4.1.3.tgz#97b9adb0728b42280aa3d814b6b999b2ff0318bf"
1128311275
integrity sha512-aX/y5pVRkfRnfmuX+OdbSdXvPe6ieKX/G2s7e98f4poJHnqH3281gDPm/metm6E/WRamfx7WC4HUqkWHfQHprw==

0 commit comments

Comments
 (0)