Skip to content

Commit 846dd06

Browse files
authored
chore(deps): unpin semver (#5469)
* chore(deps): unpin semver all deps have upgraded to address the vulnerability https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795 * chore(deps): bump http-cache-semantics
1 parent ef9827a commit 846dd06

File tree

2 files changed

+23
-8
lines changed

2 files changed

+23
-8
lines changed

package.json

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -98,14 +98,12 @@
9898
"resolutions": {
9999
"//": {
100100
"http-cache-semantics": "Pinned to address security vulnerability",
101-
"semver": "Pinned to address security vulnerability",
102101
"@types/estree": [
103102
"Used by us and our dependencies. Because it's a type definition package,",
104103
"we need everyone to use the same types (mixing versions breaks stuff)."
105104
]
106105
},
107-
"http-cache-semantics": "4.1.1",
108-
"semver": "7.6.0",
106+
"http-cache-semantics": "4.2.0",
109107
"@types/estree": "^1.0.8"
110108
},
111109
"dependencies": {}

yarn.lock

Lines changed: 22 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2109,9 +2109,11 @@
21092109

21102110
"@lwc/eslint-plugin-lwc-internal@link:./scripts/eslint-plugin":
21112111
version "0.0.0"
2112+
uid ""
21122113

21132114
"@lwc/test-utils-lwc-internals@link:./scripts/test-utils":
21142115
version "0.0.0"
2116+
uid ""
21152117

21162118
"@napi-rs/wasm-runtime@0.2.4":
21172119
version "0.2.4"
@@ -8212,10 +8214,10 @@ http-assert@^1.3.0:
82128214
deep-equal "~1.0.1"
82138215
http-errors "~1.8.0"
82148216

8215-
http-cache-semantics@3.8.1, http-cache-semantics@4.1.1, http-cache-semantics@^4.0.0, http-cache-semantics@^4.1.0, http-cache-semantics@^4.1.1:
8216-
version "4.1.1"
8217-
resolved "https://registry.yarnpkg.com/http-cache-semantics/-/http-cache-semantics-4.1.1.tgz#abe02fcb2985460bf0323be664436ec3476a6d5a"
8218-
integrity sha512-er295DKPVsV82j5kw1Gjt+ADA/XYHsajl82cGNQG2eyoPkvgUhX+nDIyelzhIWbbsXP39EHcI6l5tYs2FYqYXQ==
8217+
http-cache-semantics@3.8.1, http-cache-semantics@4.2.0, http-cache-semantics@^4.0.0, http-cache-semantics@^4.1.0, http-cache-semantics@^4.1.1:
8218+
version "4.2.0"
8219+
resolved "https://registry.yarnpkg.com/http-cache-semantics/-/http-cache-semantics-4.2.0.tgz#205f4db64f8562b76a4ff9235aa5279839a09dd5"
8220+
integrity sha512-dTxcvPXqPvXBQpq5dUr6mEMJX4oIEFv6bwom3FDwKRDsuIjjJGANqhBuoAn9c1RQJIdAKav33ED65E2ys+87QQ==
82198221

82208222
http-errors@2.0.0, http-errors@^2.0.0:
82218223
version "2.0.0"
@@ -12225,13 +12227,28 @@ semver-truncate@^1.1.2:
1222512227
dependencies:
1222612228
semver "^5.3.0"
1222712229

12228-
semver@7.6.0, semver@^5.3.0, semver@^5.5.0, semver@^5.6.0, semver@^6.3.0, semver@^6.3.1, semver@^7.1.1, semver@^7.3.2, semver@^7.3.5, semver@^7.5.3, semver@^7.5.4, semver@^7.6.0, semver@^7.6.3, semver@^7.7.2:
12230+
semver@^5.3.0, semver@^5.5.0, semver@^5.6.0:
12231+
version "5.7.2"
12232+
resolved "https://registry.yarnpkg.com/semver/-/semver-5.7.2.tgz#48d55db737c3287cd4835e17fa13feace1c41ef8"
12233+
integrity sha512-cBznnQ9KjJqU67B52RMC65CMarK2600WFnbkcaiwWq3xy/5haFJlshgnpjovMVJ+Hff49d8GEn0b87C5pDQ10g==
12234+
12235+
semver@^6.3.0, semver@^6.3.1:
12236+
version "6.3.1"
12237+
resolved "https://registry.yarnpkg.com/semver/-/semver-6.3.1.tgz#556d2ef8689146e46dcea4bfdd095f3434dffcb4"
12238+
integrity sha512-BR7VvDCVHO+q2xBEWskxS6DJE1qRnb7DxzUrogb71CWoSficBxYsiAGd+Kl0mmq/MprG9yArRkyrQxTO6XjMzA==
12239+
12240+
semver@^7.1.1, semver@^7.3.2, semver@^7.3.5, semver@^7.5.3, semver@^7.5.4, semver@^7.6.0:
1222912241
version "7.6.0"
1223012242
resolved "https://registry.yarnpkg.com/semver/-/semver-7.6.0.tgz#1a46a4db4bffcccd97b743b5005c8325f23d4e2d"
1223112243
integrity sha512-EnwXhrlwXMk9gKu5/flx5sv/an57AkRplG3hTK68W7FRDN+k+OWBj65M7719OkA82XLBxrcX0KSHj+X5COhOVg==
1223212244
dependencies:
1223312245
lru-cache "^6.0.0"
1223412246

12247+
semver@^7.6.3, semver@^7.7.2:
12248+
version "7.7.2"
12249+
resolved "https://registry.yarnpkg.com/semver/-/semver-7.7.2.tgz#67d99fdcd35cec21e6f8b87a7fd515a33f982b58"
12250+
integrity sha512-RF0Fw+rO5AMf9MAyaRXI4AV0Ulj5lMHqVxxdSgiVbixSCXoEmmX/jk0CuJw4+3SqroYO9VoUh+HcuJivvtJemA==
12251+
1223512252
send@0.19.0:
1223612253
version "0.19.0"
1223712254
resolved "https://registry.yarnpkg.com/send/-/send-0.19.0.tgz#bbc5a388c8ea6c048967049dbeac0e4a3f09d7f8"

0 commit comments

Comments
 (0)