From e5391519eb624c7f4201ad577eec258877893b6c Mon Sep 17 00:00:00 2001 From: Nazar Gargol Date: Mon, 24 Jun 2019 15:47:37 +0200 Subject: [PATCH] Bumped js-yaml version to 3.13.1 no issue - The 3.13.1 version contains security fixes described in https://github.com/nodeca/js-yaml/commit/b2f9e882397660da37c5c5bb92e8ccc7bb9eb668 --- package.json | 2 +- yarn.lock | 10 +++++++++- 2 files changed, 10 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index e8466fbbec..ad99cac4fe 100644 --- a/package.json +++ b/package.json @@ -86,7 +86,7 @@ "image-size": "0.6.3", "intl": "1.2.5", "intl-messageformat": "1.3.0", - "js-yaml": "3.12.1", + "js-yaml": "3.13.1", "jsonpath": "1.0.0", "jsonwebtoken": "8.4.0", "knex": "0.14.6", diff --git a/yarn.lock b/yarn.lock index 34862d7f3c..e510cc0444 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3714,7 +3714,15 @@ js-tokens@^3.0.2: version "3.0.2" resolved "https://registry.yarnpkg.com/js-tokens/-/js-tokens-3.0.2.tgz#9866df395102130e38f7f996bceb65443209c25b" -js-yaml@3.12.1, js-yaml@^3.12.0, js-yaml@^3.9.1: +js-yaml@3.13.1: + version "3.13.1" + resolved "https://registry.yarnpkg.com/js-yaml/-/js-yaml-3.13.1.tgz#aff151b30bfdfa8e49e05da22e7415e9dfa37847" + integrity sha512-YfbcO7jXDdyj0DGxYVSlSeQNHbD7XPWvrVWeVUujrQEoZzWJIRrCPoyk6kL6IAjAG2IolMK4T0hNUe0HOUs5Jw== + dependencies: + argparse "^1.0.7" + esprima "^4.0.0" + +js-yaml@^3.12.0, js-yaml@^3.9.1: version "3.12.1" resolved "https://registry.yarnpkg.com/js-yaml/-/js-yaml-3.12.1.tgz#295c8632a18a23e054cf5c9d3cecafe678167600" dependencies: