From aaa6fb83aedf2111b077b2fc1d0638b7ff73d110 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 11 Mar 2022 16:16:10 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-YUP-2420835 --- package.json | 2 +- yarn.lock | 29 +++++++++++------------------ 2 files changed, 12 insertions(+), 19 deletions(-) diff --git a/package.json b/package.json index f0c41d658..1350fc3c5 100644 --- a/package.json +++ b/package.json @@ -86,7 +86,7 @@ "source-map-explorer": "^2.1.2", "swiper": "^6.7.5", "uuid": "^3.4.0", - "yup": "^0.29.2" + "yup": "^0.30.0" }, "devDependencies": { "@wojtekmaj/enzyme-adapter-react-17": "^0.6.0", diff --git a/yarn.lock b/yarn.lock index a6a46ded5..4898a2183 100644 --- a/yarn.lock +++ b/yarn.lock @@ -5815,11 +5815,6 @@ flush-write-stream@^1.0.0: inherits "^2.0.3" readable-stream "^2.3.6" -fn-name@~3.0.0: - version "3.0.0" - resolved "https://registry.npmjs.org/fn-name/-/fn-name-3.0.0.tgz" - integrity sha512-eNMNr5exLoavuAMhIUVsOKF79SWd/zG104ef6sxBTSw+cZc6BXdQXDvYcGvp0VbxVVSp1XDUNoz7mg1xMtSznA== - follow-redirects@^1.0.0, follow-redirects@^1.10.0, follow-redirects@^1.14.0: version "1.14.8" resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.14.8.tgz#016996fb9a11a100566398b1c6839337d7bfa8fc" @@ -10848,10 +10843,10 @@ propagate@^1.0.0: resolved "https://registry.npmjs.org/propagate/-/propagate-1.0.0.tgz" integrity sha1-AMLa7t2iDofjeCs0Stuhzd1q1wk= -property-expr@^2.0.2: - version "2.0.4" - resolved "https://registry.npmjs.org/property-expr/-/property-expr-2.0.4.tgz" - integrity sha512-sFPkHQjVKheDNnPvotjQmm3KD3uk1fWKUN7CrpdbwmUx3CrG3QiM8QpTSimvig5vTXmTvjz7+TDvXOI9+4rkcg== +property-expr@^2.0.4: + version "2.0.5" + resolved "https://registry.yarnpkg.com/property-expr/-/property-expr-2.0.5.tgz#278bdb15308ae16af3e3b9640024524f4dc02cb4" + integrity sha512-IJUkICM5dP5znhCckHSv30Q4b5/JA5enCtkRHYaOVOAocnH/1BQEYTC5NMfT3AVl/iXKdr3aqQbQn9DxyWknwA== proxy-addr@~2.0.5: version "2.0.6" @@ -13196,7 +13191,7 @@ symbol-tree@^3.2.2: resolved "https://registry.yarnpkg.com/symbol-tree/-/symbol-tree-3.2.4.tgz#430637d248ba77e078883951fb9aa0eed7c63fa2" integrity sha512-9QNk5KwDF+Bvz+PyObkmSYjI5ksVUYtjW7AU22r2NKcfLJcXp96hkDWU3+XndOsUb+AQ9QhfzfCT2O+CNWT5Tw== -synchronous-promise@^2.0.10, synchronous-promise@^2.0.13: +synchronous-promise@^2.0.10: version "2.0.15" resolved "https://registry.yarnpkg.com/synchronous-promise/-/synchronous-promise-2.0.15.tgz#07ca1822b9de0001f5ff73595f3d08c4f720eb8e" integrity sha512-k8uzYIkIVwmT+TcglpdN50pS2y1BDcUnBPK9iJeGu0Pl1lOI8pD6wtzgw91Pjpe+RxtTncw32tLxs/R0yNL2Mg== @@ -14570,17 +14565,15 @@ yargs@^16.2.0: y18n "^5.0.5" yargs-parser "^20.2.2" -yup@^0.29.2: - version "0.29.3" - resolved "https://registry.npmjs.org/yup/-/yup-0.29.3.tgz" - integrity sha512-RNUGiZ/sQ37CkhzKFoedkeMfJM0vNQyaz+wRZJzxdKE7VfDeVKH8bb4rr7XhRLbHJz5hSjoDNwMEIaKhuMZ8gQ== +yup@^0.30.0: + version "0.30.0" + resolved "https://registry.yarnpkg.com/yup/-/yup-0.30.0.tgz#427ee076abb1d7e01e747fb782801f7df252fb76" + integrity sha512-GX3vqpC9E+Ow0fmQPgqbEg7UV40XRrN1IOEgKF5v04v6T4ha2vBas/hu0thWgewk8L4wUEBLRO/EnXwYyP+p+A== dependencies: "@babel/runtime" "^7.10.5" - fn-name "~3.0.0" - lodash "^4.17.15" + lodash "^4.17.20" lodash-es "^4.17.11" - property-expr "^2.0.2" - synchronous-promise "^2.0.13" + property-expr "^2.0.4" toposort "^2.0.2" zrender@5.2.1: