From 673df54f64f58f25679cda7e18d373307bd1a647 Mon Sep 17 00:00:00 2001 From: Liran Tal Date: Sat, 29 Jul 2023 12:46:23 +0300 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities (#240) The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-SEMVER-3247795 Co-authored-by: snyk-bot --- package.json | 2 +- yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index 9a2ec5e..e3c40b8 100644 --- a/package.json +++ b/package.json @@ -76,7 +76,7 @@ "figures": "^2.0.0", "glob": "^7.2.0", "lockfile-lint": "^3.0.9", - "semver": "7.3.8" + "semver": "7.5.2" }, "devDependencies": { "standard": "^12.0.1" diff --git a/yarn.lock b/yarn.lock index 59d1815..7de4021 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1715,10 +1715,10 @@ sax@>=0.6.0: version "5.5.0" resolved "https://registry.npmjs.org/semver/-/semver-5.5.0.tgz#dc4bbc7a6ca9d916dee5d43516f0092b58f7b8ab" -semver@7.3.8: - version "7.3.8" - resolved "https://registry.yarnpkg.com/semver/-/semver-7.3.8.tgz#07a78feafb3f7b32347d725e33de7e2a2df67798" - integrity sha512-NB1ctGL5rlHrPJtFDVIVzTyQylMLu9N9VICA6HSFJo8MCGVTMW6gfpicwKmmK/dAjTOrqu5l63JJOpDSrAis3A== +semver@7.5.2: + version "7.5.2" + resolved "https://registry.yarnpkg.com/semver/-/semver-7.5.2.tgz#5b851e66d1be07c1cdaf37dfc856f543325a2beb" + integrity sha512-SoftuTROv/cRjCze/scjGyiDtcUyxw1rgYQSZY7XTmtR5hX+dm76iDbTH8TkLPHCQmlbQVSSbNZCPM2hb0knnQ== dependencies: lru-cache "^6.0.0"