From 4945ec8acdfbd6404791b1a4d2c471b8f80de0ff Mon Sep 17 00:00:00 2001 From: Arnaud Besnier Date: Fri, 26 Jan 2024 13:54:09 +0100 Subject: [PATCH] fix(security): patch lodash.set dependency vulnerabilities (#657) --- package.json | 2 +- yarn.lock | 14 ++++---------- 2 files changed, 5 insertions(+), 11 deletions(-) diff --git a/package.json b/package.json index fabf604a5..49a78bee2 100644 --- a/package.json +++ b/package.json @@ -84,7 +84,7 @@ "jest": "27.3.1", "lint-staged": "12.3.7", "mock-stdin": "1.0.0", - "nock": "13.0.4", + "nock": "13.5.0", "prettier": "2.8.3", "rimraf": "3.0.2", "semantic-release": "19.0.3", diff --git a/yarn.lock b/yarn.lock index a2d543d7d..7de86a295 100644 --- a/yarn.lock +++ b/yarn.lock @@ -7534,11 +7534,6 @@ lodash.once@^4.0.0: resolved "https://registry.npmjs.org/lodash.once/-/lodash.once-4.1.1.tgz" integrity sha1-DdOXEhPHxW34gJd9UEyI+0cal6w= -lodash.set@^4.3.2: - version "4.3.2" - resolved "https://registry.npmjs.org/lodash.set/-/lodash.set-4.3.2.tgz" - integrity sha512-4hNPN5jlm/N/HLMCO43v8BXKq9Z7QdAGc/VGrRD61w8gN9g/6jF9A4L1pbUgBLCffi0w9VsXfTOij5x8iTyFvg== - lodash.snakecase@^4.0.1, lodash.snakecase@^4.1.1: version "4.1.1" resolved "https://registry.yarnpkg.com/lodash.snakecase/-/lodash.snakecase-4.1.1.tgz#39d714a35357147837aefd64b5dcbb16becd8f8d" @@ -8253,14 +8248,13 @@ nice-try@^1.0.4: resolved "https://registry.npmjs.org/nice-try/-/nice-try-1.0.5.tgz" integrity sha512-1nh45deeb5olNY7eX82BkPO7SSxR5SSYJiPTrTdFUVYwAl8CKMA5N9PjTYkHiRjisVcxcQ1HXdLhx2qxxJzLNQ== -nock@13.0.4: - version "13.0.4" - resolved "https://registry.npmjs.org/nock/-/nock-13.0.4.tgz" - integrity sha512-alqTV8Qt7TUbc74x1pKRLSENzfjp4nywovcJgi/1aXDiUxXdt7TkruSTF5MDWPP7UoPVgea4F9ghVdmX0xxnSA== +nock@13.5.0: + version "13.5.0" + resolved "https://registry.yarnpkg.com/nock/-/nock-13.5.0.tgz#82cd33b0dba6095d3f5a28d0ff2edac970fa05ec" + integrity sha512-9hc1eCS2HtOz+sE9W7JQw/tXJktg0zoPSu48s/pYe73e25JW9ywiowbqnUSd7iZPeVawLcVpPZeZS312fwSY+g== dependencies: debug "^4.1.0" json-stringify-safe "^5.0.1" - lodash.set "^4.3.2" propagate "^2.0.0" node-abi@^3.3.0: