Skip to content

Commit d6dac1c

Browse files
deps: Bump nano to 10.1.3 to avoid axios <1.6.0
axios 1.6.0 fixes CVE-2023-45857 (https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459). Contributed by STMicroelectronics Signed-off-by: Torbjörn SVENSSON <[email protected]>
1 parent 69d7cd0 commit d6dac1c

File tree

2 files changed

+32
-35
lines changed

2 files changed

+32
-35
lines changed

dev-packages/application-package/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636
"deepmerge": "^4.2.2",
3737
"fs-extra": "^4.0.2",
3838
"is-electron": "^2.1.0",
39-
"nano": "^9.0.5",
39+
"nano": "^10.1.3",
4040
"resolve-package-path": "^4.0.3",
4141
"semver": "^7.5.4",
4242
"write-json-file": "^2.2.0"

yarn.lock

Lines changed: 31 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -2255,7 +2255,7 @@
22552255
dependencies:
22562256
"@types/node" "*"
22572257

2258-
"@types/tough-cookie@*", "@types/tough-cookie@^4.0.0":
2258+
"@types/tough-cookie@*":
22592259
version "4.0.3"
22602260
resolved "https://registry.yarnpkg.com/@types/tough-cookie/-/tough-cookie-4.0.3.tgz#3d06b6769518450871fbc40770b7586334bdfd90"
22612261
integrity sha512-THo502dA5PzG/sfQH+42Lw3fvmYkceefOspdCwpHRul8ik2Jv1K8I5OZz1AT3/rs46kwgMCe9bSBmDLYkkOMGg==
@@ -3204,21 +3204,6 @@ available-typed-arrays@^1.0.5:
32043204
resolved "https://registry.yarnpkg.com/available-typed-arrays/-/available-typed-arrays-1.0.5.tgz#92f95616501069d07d10edb2fc37d3e1c65123b7"
32053205
integrity sha512-DMD0KiN46eipeziST1LPP/STfDU0sufISXmjSgvVsoU2tqxctQeASejWcfNtxYKqETM1UxQ8sp2OrSBWpHY6sw==
32063206

3207-
axios-cookiejar-support@^1.0.1:
3208-
version "1.0.1"
3209-
resolved "https://registry.yarnpkg.com/axios-cookiejar-support/-/axios-cookiejar-support-1.0.1.tgz#7b32af7d932508546c68b1fc5ba8f562884162e1"
3210-
integrity sha512-IZJxnAJ99XxiLqNeMOqrPbfR7fRyIfaoSLdPUf4AMQEGkH8URs0ghJK/xtqBsD+KsSr3pKl4DEQjCn834pHMig==
3211-
dependencies:
3212-
is-redirect "^1.0.0"
3213-
pify "^5.0.0"
3214-
3215-
axios@^0.21.1:
3216-
version "0.21.4"
3217-
resolved "https://registry.yarnpkg.com/axios/-/axios-0.21.4.tgz#c67b90dc0568e5c1cf2b0b858c43ba28e2eda575"
3218-
integrity sha512-ut5vewkiu8jjGBdqpM44XxjuCjq9LAKeHVmoVfHVzy8eHgxxq8SbAVQNovDA8mVi05kP0Ea/n/UzcSHcTJQfNg==
3219-
dependencies:
3220-
follow-redirects "^1.14.0"
3221-
32223207
axios@^1.0.0:
32233208
version "1.5.1"
32243209
resolved "https://registry.yarnpkg.com/axios/-/axios-1.5.1.tgz#11fbaa11fc35f431193a9564109c88c1f27b585f"
@@ -3228,6 +3213,15 @@ axios@^1.0.0:
32283213
form-data "^4.0.0"
32293214
proxy-from-env "^1.1.0"
32303215

3216+
axios@^1.6.2:
3217+
version "1.6.7"
3218+
resolved "https://registry.yarnpkg.com/axios/-/axios-1.6.7.tgz#7b48c2e27c96f9c68a2f8f31e2ab19f59b06b0a7"
3219+
integrity sha512-/hDJGff6/c7u0hDkvkGxR/oy6CbCs8ziCsC7SqmhjfozqiJGc8Z11wrv9z9lYfY4K8l+H9TpjcMDX0xOZmx+RA==
3220+
dependencies:
3221+
follow-redirects "^1.15.4"
3222+
form-data "^4.0.0"
3223+
proxy-from-env "^1.1.0"
3224+
32313225
azure-devops-node-api@^11.0.1:
32323226
version "11.2.0"
32333227
resolved "https://registry.yarnpkg.com/azure-devops-node-api/-/azure-devops-node-api-11.2.0.tgz#bf04edbef60313117a0507415eed4790a420ad6b"
@@ -5697,11 +5691,16 @@ flatted@^3.2.9:
56975691
resolved "https://registry.yarnpkg.com/flatted/-/flatted-3.2.9.tgz#7eb4c67ca1ba34232ca9d2d93e9886e611ad7daf"
56985692
integrity sha512-36yxDn5H7OFZQla0/jFJmbIKTdZAQHngCedGxiMmpNfEZM0sdEeT+WczLQrjK6D7o2aiyLYDnkw0R3JK0Qv1RQ==
56995693

5700-
follow-redirects@^1.0.0, follow-redirects@^1.14.0, follow-redirects@^1.15.0:
5694+
follow-redirects@^1.0.0, follow-redirects@^1.15.0:
57015695
version "1.15.3"
57025696
resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.15.3.tgz#fe2f3ef2690afce7e82ed0b44db08165b207123a"
57035697
integrity sha512-1VzOtuEM8pC9SFU1E+8KfTjZyMztRsgEfwQl44z8A25uy13jSzTj6dyK2Df52iV0vgHCfBwLhDWevLn95w5v6Q==
57045698

5699+
follow-redirects@^1.15.4:
5700+
version "1.15.5"
5701+
resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.15.5.tgz#54d4d6d062c0fa7d9d17feb008461550e3ba8020"
5702+
integrity sha512-vSFWUON1B+yAw1VN4xMfxgn5fTUiaOzAJCKBwIIgT/+7CuGy9+r+5gITvP62j3RmaD5Ph65UaERdOSRGUzZtgw==
5703+
57055704
font-awesome@^4.7.0:
57065705
version "4.7.0"
57075706
resolved "https://registry.yarnpkg.com/font-awesome/-/font-awesome-4.7.0.tgz#8fa8cf0411a1a31afd07b06d2902bb9fc815a133"
@@ -6831,11 +6830,6 @@ is-potential-custom-element-name@^1.0.1:
68316830
resolved "https://registry.yarnpkg.com/is-potential-custom-element-name/-/is-potential-custom-element-name-1.0.1.tgz#171ed6f19e3ac554394edf78caa05784a45bebb5"
68326831
integrity sha512-bCYeRA2rVibKZd+s2625gGnGF/t7DSqDs4dP7CrLA1m7jKWz6pps0LpYLJN8Q64HtmPKJ1hrN3nzPNKFEKOUiQ==
68336832

6834-
is-redirect@^1.0.0:
6835-
version "1.0.0"
6836-
resolved "https://registry.yarnpkg.com/is-redirect/-/is-redirect-1.0.0.tgz#1d03dded53bd8db0f30c26e4f95d36fc7c87dc24"
6837-
integrity sha512-cr/SlUEe5zOGmzvj9bUyC4LVvkNVAXu4GytXLNMr1pny+a65MpQ9IJzFHD5vi7FyJgb4qt27+eS3TuQnqB+RQw==
6838-
68396833
is-regex@^1.1.4:
68406834
version "1.1.4"
68416835
resolved "https://registry.yarnpkg.com/is-regex/-/is-regex-1.1.4.tgz#eef5663cd59fa4c0ae339505323df6854bb15958"
@@ -8243,16 +8237,14 @@ nan@^2.14.0, nan@^2.17.0:
82438237
resolved "https://registry.yarnpkg.com/nan/-/nan-2.18.0.tgz#26a6faae7ffbeb293a39660e88a76b82e30b7554"
82448238
integrity sha512-W7tfG7vMOGtD30sHoZSSc/JVYiyDPEyQVso/Zz+/uQd0B0L46gtC+pHha5FFMRpil6fm/AoEcRWyOVi4+E/f8w==
82458239

8246-
nano@^9.0.5:
8247-
version "9.0.5"
8248-
resolved "https://registry.yarnpkg.com/nano/-/nano-9.0.5.tgz#2b767819f612907a3ac09b21f2929d4097407262"
8249-
integrity sha512-fEAhwAdXh4hDDnC8cYJtW6D8ivOmpvFAqT90+zEuQREpRkzA/mJPcI4EKv15JUdajaqiLTXNoKK6PaRF+/06DQ==
8240+
nano@^10.1.3:
8241+
version "10.1.3"
8242+
resolved "https://registry.yarnpkg.com/nano/-/nano-10.1.3.tgz#5cb1ad14add4c9c82d53a79159848dafa84e7a13"
8243+
integrity sha512-q/hKQJJH3FhkkuJ3ojbgDph2StlSXFBPNkpZBZlsvZDbuYfxKJ4VtunEeilthcZtuIplIk1zVX5o2RgKTUTO+Q==
82508244
dependencies:
8251-
"@types/tough-cookie" "^4.0.0"
8252-
axios "^0.21.1"
8253-
axios-cookiejar-support "^1.0.1"
8254-
qs "^6.9.4"
8255-
tough-cookie "^4.0.0"
8245+
axios "^1.6.2"
8246+
node-abort-controller "^3.0.1"
8247+
qs "^6.11.0"
82568248

82578249
82588250
version "3.3.1"
@@ -8324,6 +8316,11 @@ node-abi@^2.21.0, node-abi@^2.7.0:
83248316
dependencies:
83258317
semver "^5.4.1"
83268318

8319+
node-abort-controller@^3.0.1:
8320+
version "3.1.1"
8321+
resolved "https://registry.yarnpkg.com/node-abort-controller/-/node-abort-controller-3.1.1.tgz#a94377e964a9a37ac3976d848cb5c765833b8548"
8322+
integrity sha512-AGK2yQKIjRuqnc6VkX2Xj5d+QW8xZ87pa1UK6yA6ouUyuxfHuMP6umE5QK7UmTeOAymo+Zx1Fxiuw9rVx8taHQ==
8323+
83278324
node-addon-api@^3.0.0, node-addon-api@^3.0.2, node-addon-api@^3.1.0, node-addon-api@^3.2.1:
83288325
version "3.2.1"
83298326
resolved "https://registry.yarnpkg.com/node-addon-api/-/node-addon-api-3.2.1.tgz#81325e0a2117789c0128dab65e7e38f07ceba161"
@@ -9239,7 +9236,7 @@ picomatch@^2.0.4, picomatch@^2.2.1, picomatch@^2.3.1:
92399236
resolved "https://registry.yarnpkg.com/picomatch/-/picomatch-2.3.1.tgz#3ba3833733646d9d3e4995946c1365a67fb07a42"
92409237
integrity sha512-JU3teHTNjmE2VCGFzuY8EXzCDVwEqB2a8fsIvwaStHhAWJEeVd1o1QD80CU6+ZdEXXSLbSsuLwJjkCBWqRQUVA==
92419238

9242-
[email protected], pify@^5.0.0:
9239+
92439240
version "5.0.0"
92449241
resolved "https://registry.yarnpkg.com/pify/-/pify-5.0.0.tgz#1f5eca3f5e87ebec28cc6d54a0e4aaf00acc127f"
92459242
integrity sha512-eW/gHNMlxdSP6dmG6uJip6FXN0EQBwm2clYYd8Wul42Cwu/DK8HEftzsapcNdYe2MfLiIwZqsDk2RDEsTE79hA==
@@ -9604,7 +9601,7 @@ [email protected]:
96049601
dependencies:
96059602
side-channel "^1.0.4"
96069603

9607-
qs@^6.4.0, qs@^6.9.1, qs@^6.9.4:
9604+
qs@^6.11.0, qs@^6.4.0, qs@^6.9.1:
96089605
version "6.11.2"
96099606
resolved "https://registry.yarnpkg.com/qs/-/qs-6.11.2.tgz#64bea51f12c1f5da1bc01496f48ffcff7c69d7d9"
96109607
integrity sha512-tDNIz22aBzCDxLtVH++VnTfzxlfeK5CbqohpSqpJgj1Wg/cQbStNAz3NuqCs5vV+pjBsK4x4pN9HlVh7rcYRiA==
@@ -11141,7 +11138,7 @@ [email protected]:
1114111138
resolved "https://registry.yarnpkg.com/toidentifier/-/toidentifier-1.0.1.tgz#3be34321a88a820ed1bd80dfaa33e479fbb8dd35"
1114211139
integrity sha512-o5sSPKEkg/DIQNmH43V0/uerLrpzVedkUh8tGNvaeXpfpuwjKenlSox/2O/BTlZUtEe+JG7s5YhEz608PlAHRA==
1114311140

11144-
tough-cookie@^4.0.0, tough-cookie@^4.1.2:
11141+
tough-cookie@^4.1.2:
1114511142
version "4.1.3"
1114611143
resolved "https://registry.yarnpkg.com/tough-cookie/-/tough-cookie-4.1.3.tgz#97b9adb0728b42280aa3d814b6b999b2ff0318bf"
1114711144
integrity sha512-aX/y5pVRkfRnfmuX+OdbSdXvPe6ieKX/G2s7e98f4poJHnqH3281gDPm/metm6E/WRamfx7WC4HUqkWHfQHprw==

0 commit comments

Comments
 (0)