Skip to content

Commit ede3d6f

Browse files
deps: upgrade multer
The commit upgrades `multer` to fix a security vulnerability in `dicer` which it previously used. Signed-off-by: vince-fugnitto <[email protected]>
1 parent dbc5742 commit ede3d6f

File tree

2 files changed

+16
-26
lines changed

2 files changed

+16
-26
lines changed

packages/filesystem/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
"body-parser": "^1.18.3",
1414
"http-status-codes": "^1.3.0",
1515
"minimatch": "^3.0.4",
16-
"multer": "^1.4.2",
16+
"multer": "1.4.4-lts.1",
1717
"rimraf": "^2.6.2",
1818
"tar-fs": "^1.16.2",
1919
"trash": "^6.1.1",

yarn.lock

Lines changed: 15 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -3767,13 +3767,12 @@ builtins@^1.0.3:
37673767
resolved "https://registry.yarnpkg.com/builtins/-/builtins-1.0.3.tgz#cb94faeb61c8696451db36534e1422f94f0aee88"
37683768
integrity sha1-y5T662HIaWRR2zZTThQi+U8K7og=
37693769

3770-
busboy@^0.2.11:
3771-
version "0.2.14"
3772-
resolved "https://registry.yarnpkg.com/busboy/-/busboy-0.2.14.tgz#6c2a622efcf47c57bbbe1e2a9c37ad36c7925453"
3773-
integrity sha1-bCpiLvz0fFe7vh4qnDetNseSVFM=
3770+
busboy@^1.0.0:
3771+
version "1.6.0"
3772+
resolved "https://registry.yarnpkg.com/busboy/-/busboy-1.6.0.tgz#966ea36a9502e43cdb9146962523b92f531f6893"
3773+
integrity sha512-8SFQbg/0hQ9xy3UNTB0YEnsNBbWfhf7RtnzpL7TkBiTBRfrQ9Fxcnz7VJsleJpyp6rVLvXiuORqjlHi5q+PYuA==
37743774
dependencies:
3775-
dicer "0.2.5"
3776-
readable-stream "1.1.x"
3775+
streamsearch "^1.1.0"
37773776

37783777
byline@^5.0.0:
37793778
version "5.0.0"
@@ -4823,14 +4822,6 @@ dezalgo@^1.0.0:
48234822
asap "^2.0.0"
48244823
wrappy "1"
48254824

4826-
4827-
version "0.2.5"
4828-
resolved "https://registry.yarnpkg.com/dicer/-/dicer-0.2.5.tgz#5996c086bb33218c812c090bddc09cd12facb70f"
4829-
integrity sha1-WZbAhrszIYyBLAkL3cCc0S+stw8=
4830-
dependencies:
4831-
readable-stream "1.1.x"
4832-
streamsearch "0.1.2"
4833-
48344825
diff-sequences@^27.5.1:
48354826
version "27.5.1"
48364827
resolved "https://registry.yarnpkg.com/diff-sequences/-/diff-sequences-27.5.1.tgz#eaecc0d327fd68c8d9672a1e64ab8dccb2ef5327"
@@ -8129,17 +8120,16 @@ [email protected], ms@^2.0.0, ms@^2.1.1, ms@^2.1.2:
81298120
resolved "https://registry.yarnpkg.com/ms/-/ms-2.1.3.tgz#574c8138ce1d2b5861f0b44579dbadd60c6615b2"
81308121
integrity sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==
81318122

8132-
multer@^1.4.2:
8133-
version "1.4.4"
8134-
resolved "https://registry.yarnpkg.com/multer/-/multer-1.4.4.tgz#e2bc6cac0df57a8832b858d7418ccaa8ebaf7d8c"
8135-
integrity sha512-2wY2+xD4udX612aMqMcB8Ws2Voq6NIUPEtD1be6m411T4uDH/VtL9i//xvcyFlTVfRdaBsk7hV5tgrGQqhuBiw==
8123+
8124+
version "1.4.4-lts.1"
8125+
resolved "https://registry.yarnpkg.com/multer/-/multer-1.4.4-lts.1.tgz#24100f701a4611211cfae94ae16ea39bb314e04d"
8126+
integrity sha512-WeSGziVj6+Z2/MwQo3GvqzgR+9Uc+qt8SwHKh3gvNPiISKfsMfG4SvCOFYlxxgkXt7yIV2i1yczehm0EOKIxIg==
81368127
dependencies:
81378128
append-field "^1.0.0"
8138-
busboy "^0.2.11"
8129+
busboy "^1.0.0"
81398130
concat-stream "^1.5.2"
81408131
mkdirp "^0.5.4"
81418132
object-assign "^4.1.1"
8142-
on-finished "^2.3.0"
81438133
type-is "^1.6.4"
81448134
xtend "^4.0.0"
81458135

@@ -8694,7 +8684,7 @@ octicons@^7.1.0:
86948684
dependencies:
86958685
object-assign "^4.1.1"
86968686

8697-
[email protected], on-finished@^2.3.0:
8687+
86988688
version "2.4.1"
86998689
resolved "https://registry.yarnpkg.com/on-finished/-/on-finished-2.4.1.tgz#58c8c44116e54845ad57f14ab10b03533184ac3f"
87008690
integrity sha512-oVlzkg3ENAhCk2zdv7IJwd/QUD4z2RxRwpkcGY8psCVcCYZNq4wYnVWALHM+brtuJjePWiYF/ClmuDr8Ch5+kg==
@@ -10677,10 +10667,10 @@ stream-combiner@~0.0.4:
1067710667
dependencies:
1067810668
duplexer "~0.1.1"
1067910669

10680-
streamsearch@0.1.2:
10681-
version "0.1.2"
10682-
resolved "https://registry.yarnpkg.com/streamsearch/-/streamsearch-0.1.2.tgz#808b9d0e56fc273d809ba57338e929919a1a9f1a"
10683-
integrity sha1-gIudDlb8Jz2Am6VzOOkpkZoanxo=
10670+
streamsearch@^1.1.0:
10671+
version "1.1.0"
10672+
resolved "https://registry.yarnpkg.com/streamsearch/-/streamsearch-1.1.0.tgz#404dd1e2247ca94af554e841a8ef0eaa238da764"
10673+
integrity sha512-Mcc5wHehp9aXz1ax6bZUyY5afg9u2rv5cqQI3mRrYkGC8rW2hM02jWuwjtL++LS5qinSyhj2QfLyNsuc+VsExg==
1068410674

1068510675
strict-uri-encode@^2.0.0:
1068610676
version "2.0.0"

0 commit comments

Comments
 (0)