From 5a5889d09687844fae6aff2e10e74c95859f51c3 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 25 Oct 2017 08:19:10 +0000 Subject: [PATCH] fix: package.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/npm:superagent:20170807 Latest report for jce-il/example-mean-app: https://snyk.io/test/github/jce-il/example-mean-app --- package.json | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/package.json b/package.json index d9ac19a..318dcb9 100644 --- a/package.json +++ b/package.json @@ -6,7 +6,7 @@ "dependencies": { "accepts": "^1.1.4", "after": "^0.8.1", - "body-parser": "^1.8.4", + "body-parser": "~1.9.3", "connect-redis": "^2.1.0", "cookie": "^0.1.2", "cookie-parser": "^1.3.4", @@ -16,7 +16,7 @@ "ejs": "^1.0.0", "escape-html": "^1.0.1", "etag": "^1.4.0", - "express": "^4.12.3", + "express": "~4.10.3", "express-session": "^1.8.2", "finalhandler": "^0.2.0", "fresh": "^0.2.4", @@ -28,7 +28,7 @@ "merge-descriptors": "^0.0.2", "method-override": "^2.2.0", "methods": "^1.1.0", - "morgan": "^1.3.2", + "morgan": "~1.5.0", "multiparty": "^3.3.2", "on-finished": "^2.1.1", "parseurl": "^1.3.0", @@ -39,16 +39,13 @@ "send": "^0.9.3", "serve-static": "^1.6.5", "should": "^4.0.4", - "supertest": "^0.14.0", + "supertest": "^3.0.0", "type-is": "^1.5.7", "utils-merge": "^1.0.0", "vary": "^1.0.0", "vhost": "^3.0.0", "bcrypt-nodejs": "0.0.3", - "body-parser": "~1.9.3", - "express": "~4.10.3", - "jsonwebtoken": "^5.0.0", - "morgan": "~1.5.0" + "jsonwebtoken": "^5.0.0" }, "devDependencies": { "mocha": "^1.21.5"