From deddff1d712d5d8c5863c9fe15da306970fcd0bc Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 13 Oct 2023 19:41:53 +0000 Subject: [PATCH] fix: upgrade jsonwebtoken from 9.0.0 to 9.0.2 Snyk has created this PR to upgrade jsonwebtoken from 9.0.0 to 9.0.2. See this package in npm: See this project in Snyk: https://app.snyk.io/org/macpro-mdct/project/09eaf66d-df6d-46fe-9a1d-af8bb99d93f3?utm_source=github&utm_medium=referral&page=upgrade-pr --- services/uploads/package.json | 2 +- services/uploads/yarn.lock | 20 +++++++++++++------- 2 files changed, 14 insertions(+), 8 deletions(-) diff --git a/services/uploads/package.json b/services/uploads/package.json index 056ed96dc..107119ae9 100644 --- a/services/uploads/package.json +++ b/services/uploads/package.json @@ -23,7 +23,7 @@ "fast-xml-parser": "4.2.5", "flat": "^5.0.2", "json2csv": "^5.0.6", - "jsonwebtoken": "9.0.0", + "jsonwebtoken": "9.0.2", "luxon": "3.3.0", "uuid": "^7.0.3" }, diff --git a/services/uploads/yarn.lock b/services/uploads/yarn.lock index 6664f7391..3547a8ed5 100644 --- a/services/uploads/yarn.lock +++ b/services/uploads/yarn.lock @@ -1635,15 +1635,21 @@ jsonschema@^1.4.0: resolved "https://registry.yarnpkg.com/jsonschema/-/jsonschema-1.4.0.tgz#1afa34c4bc22190d8e42271ec17ac8b3404f87b2" integrity sha512-/YgW6pRMr6M7C+4o8kS+B/2myEpHCrxO4PEWnqJNBFMjn7EWXqlQ4tGwL6xTHeRplwuZmcAncdvfOad1nT2yMw== -jsonwebtoken@9.0.0: - version "9.0.0" - resolved "https://registry.yarnpkg.com/jsonwebtoken/-/jsonwebtoken-9.0.0.tgz#d0faf9ba1cc3a56255fe49c0961a67e520c1926d" - integrity sha512-tuGfYXxkQGDPnLJ7SibiQgVgeDgfbPq2k2ICcbgqW8WxWLBAxKQM/ZCu/IT8SOSwmaYl4dpTFCW5xZv7YbbWUw== +jsonwebtoken@9.0.2: + version "9.0.2" + resolved "https://registry.yarnpkg.com/jsonwebtoken/-/jsonwebtoken-9.0.2.tgz#65ff91f4abef1784697d40952bb1998c504caaf3" + integrity sha512-PRp66vJ865SSqOlgqS8hujT5U4AOgMfhrwYIuIhfKaoSCZcirrmASQr8CX7cUg+RMih+hgznrjp99o+W4pJLHQ== dependencies: jws "^3.2.2" - lodash "^4.17.21" + lodash.includes "^4.3.0" + lodash.isboolean "^3.0.3" + lodash.isinteger "^4.0.4" + lodash.isnumber "^3.0.3" + lodash.isplainobject "^4.0.6" + lodash.isstring "^4.0.1" + lodash.once "^4.0.0" ms "^2.1.1" - semver "^7.3.8" + semver "^7.5.4" jsonwebtoken@^8.5.1: version "8.5.1" @@ -2423,7 +2429,7 @@ semver@^6.0.0, semver@^6.2.0, semver@^6.3.0: resolved "https://registry.yarnpkg.com/semver/-/semver-6.3.1.tgz#556d2ef8689146e46dcea4bfdd095f3434dffcb4" integrity sha512-BR7VvDCVHO+q2xBEWskxS6DJE1qRnb7DxzUrogb71CWoSficBxYsiAGd+Kl0mmq/MprG9yArRkyrQxTO6XjMzA== -semver@^7.3.4, semver@^7.3.8: +semver@^7.3.4, semver@^7.5.4: version "7.5.4" resolved "https://registry.yarnpkg.com/semver/-/semver-7.5.4.tgz#483986ec4ed38e1c6c48c34894a9182dbff68a6e" integrity sha512-1bCSESV6Pv+i21Hvpxp3Dx+pSD8lIPt8uVjRrxAUt/nbswYc+tK6Y2btiULjd4+fnq15PX+nqQDC7Oft7WkwcA==