From 0dc73fc508546816707d5e66669319672e1f6ea0 Mon Sep 17 00:00:00 2001 From: gopijaganthan <42249619+gopijaganthan@users.noreply.github.com> Date: Tue, 22 Mar 2022 12:01:11 +0100 Subject: [PATCH 1/2] Fixing pollution vulnerability in minimist fixing prototype Pollution vulnerability in minimist updating minimist version to 1.2.6 ref: https://www.npmjs.com/advisories/1067259 --- package.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index 0004294..c71f012 100644 --- a/package.json +++ b/package.json @@ -18,7 +18,7 @@ ], "devDependencies": { "@types/jest": "^27.0.3", - "@types/minimist": "^1.2.0", + "@types/minimist": "^1.2.6", "@types/node": "^6.0.54", "@types/strip-bom": "^3.0.0", "@types/strip-json-comments": "^0.0.30", @@ -35,7 +35,7 @@ "dependencies": { "@types/json5": "^0.0.29", "json5": "^1.0.1", - "minimist": "^1.2.0", + "minimist": "^1.2.6", "strip-bom": "^3.0.0" }, "scripts": { From 80acb9481c44b6e839a7e4393ec7e9f13ca47f9e Mon Sep 17 00:00:00 2001 From: "g.jaganathan" Date: Tue, 22 Mar 2022 12:07:26 +0100 Subject: [PATCH 2/2] updating yarn lock file --- package.json | 2 +- yarn.lock | 5 +++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/package.json b/package.json index c71f012..517b43b 100644 --- a/package.json +++ b/package.json @@ -18,7 +18,7 @@ ], "devDependencies": { "@types/jest": "^27.0.3", - "@types/minimist": "^1.2.6", + "@types/minimist": "^1.2.0", "@types/node": "^6.0.54", "@types/strip-bom": "^3.0.0", "@types/strip-json-comments": "^0.0.30", diff --git a/yarn.lock b/yarn.lock index 25bf34e..e36172c 100644 --- a/yarn.lock +++ b/yarn.lock @@ -2333,6 +2333,11 @@ minimist@^1.2.5: resolved "https://registry.yarnpkg.com/minimist/-/minimist-1.2.5.tgz#67d66014b66a6a8aaa0c083c5fd58df4e4e97602" integrity sha512-FM9nNUYrRBAELZQT3xeZQ7fmMOBg6nWNmJKTcgsJeaLstP/UODVpGsr5OhXhhXg6f+qtJ8uiZ+PUxkDWcgIXLw== +minimist@^1.2.6: + version "1.2.6" + resolved "https://registry.yarnpkg.com/minimist/-/minimist-1.2.6.tgz#8637a5b759ea0d6e98702cfb3a9283323c93af44" + integrity sha512-Jsjnk4bw3YJqYzbdyBiNsPWHPfO++UGG749Cxs6peCu5Xg4nrena6OVxOYxrQTqww0Jmwt+Ref8rggumkTLz9Q== + mkdirp@^0.5.1: version "0.5.1" resolved "https://registry.yarnpkg.com/mkdirp/-/mkdirp-0.5.1.tgz#30057438eac6cf7f8c4767f38648d6697d75c903"