Skip to content

Commit 2e9490f

Browse files
committed
upgrade minimatch, undici, and underscore.string to secure versions
fixes: - CVE-2025-22150 - CVE-2022-3517 - WS-2017-3772 Signed-off-by: Divyansh Kamboj <[email protected]>
1 parent 8bba3c7 commit 2e9490f

File tree

2 files changed

+31
-49
lines changed

2 files changed

+31
-49
lines changed

package.json

+4-1
Original file line numberDiff line numberDiff line change
@@ -196,7 +196,10 @@
196196
"tough-cookie": "^4.1.3",
197197
"webpack": "^5.96.1",
198198
"webpack-bundle-analyzer/ws": "^7.5.10",
199-
"webpack-dev-server/express": "^4.21.0"
199+
"webpack-dev-server/express": "^4.21.0",
200+
"minimatch": "^3.0.5",
201+
"underscore.string": "^3.3.6",
202+
"undici": "^6.21.1"
200203
},
201204
"engines": {
202205
"node": ">=20.x"

yarn.lock

+27-48
Original file line numberDiff line numberDiff line change
@@ -4623,13 +4623,6 @@ brace-expansion@^1.1.7:
46234623
balanced-match "^1.0.0"
46244624
concat-map "0.0.1"
46254625

4626-
brace-expansion@^2.0.1:
4627-
version "2.0.1"
4628-
resolved "https://registry.yarnpkg.com/brace-expansion/-/brace-expansion-2.0.1.tgz#1edc459e0f0c548486ecf9fc99f2221364b9a0ae"
4629-
integrity sha512-XnAIvQ8eM+kC6aULx6wuQiwVsnzsi9d3WxzV3FpWTGA19F621kwdbsAcFKXgKUHZWsy+mY6iL1sHTxWEFCytDA==
4630-
dependencies:
4631-
balanced-match "^1.0.0"
4632-
46334626
braces@^3.0.3:
46344627
version "3.0.3"
46354628
resolved "https://registry.yarnpkg.com/braces/-/braces-3.0.3.tgz#490332f40919452272d55a8480adc0c441358789"
@@ -5243,10 +5236,10 @@ [email protected]:
52435236
resolved "https://registry.yarnpkg.com/cookie-signature/-/cookie-signature-1.0.6.tgz#e303a882b342cc3ee8ca513a79999734dab3ae2c"
52445237
integrity sha1-4wOogrNCzD7oylE6eZmXNNqzriw=
52455238

5246-
cookie@0.6.0:
5247-
version "0.6.0"
5248-
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.6.0.tgz#2798b04b071b0ecbff0dbb62a505a8efa4e19051"
5249-
integrity sha512-U71cyTamuh1CRNCfpGY6to28lxvNwPG4Guz/EVjgf3Jmzv0vlDp1atT9eS5dDjMYHucpHbWns6Lwf3BKz6svdw==
5239+
cookie@0.7.1:
5240+
version "0.7.1"
5241+
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.7.1.tgz#2f73c42142d5d5cf71310a74fc4ae61670e5dbc9"
5242+
integrity sha512-6DnInpx7SJ2AK3+CTUE/ZM0vWTUboZCegxhC2xiIydHR9jNuTAASBrfEpHhiGOZw/nX51bHt6YQl8jsGo4y/0w==
52505243

52515244
copy-to-clipboard@^3:
52525245
version "3.3.1"
@@ -6821,16 +6814,16 @@ expect@^29.0.0, expect@^29.7.0:
68216814
jest-util "^29.7.0"
68226815

68236816
express@^4.19.2, express@^4.21.0:
6824-
version "4.21.0"
6825-
resolved "https://registry.yarnpkg.com/express/-/express-4.21.0.tgz#d57cb706d49623d4ac27833f1cbc466b668eb915"
6826-
integrity sha512-VqcNGcj/Id5ZT1LZ/cfihi3ttTn+NJmkli2eZADigjq29qTlWi/hAQ43t/VLPq8+UX06FCEx3ByOYet6ZFblng==
6817+
version "4.21.2"
6818+
resolved "https://registry.yarnpkg.com/express/-/express-4.21.2.tgz#cf250e48362174ead6cea4a566abef0162c1ec32"
6819+
integrity sha512-28HqgMZAmih1Czt9ny7qr6ek2qddF4FclbMzwhCREB6OFfH+rXAnuNCwo1/wFvrtbgsQDb4kSbX9de9lFbrXnA==
68276820
dependencies:
68286821
accepts "~1.3.8"
68296822
array-flatten "1.1.1"
68306823
body-parser "1.20.3"
68316824
content-disposition "0.5.4"
68326825
content-type "~1.0.4"
6833-
cookie "0.6.0"
6826+
cookie "0.7.1"
68346827
cookie-signature "1.0.6"
68356828
debug "2.6.9"
68366829
depd "2.0.0"
@@ -6844,7 +6837,7 @@ express@^4.19.2, express@^4.21.0:
68446837
methods "~1.1.2"
68456838
on-finished "2.4.1"
68466839
parseurl "~1.3.3"
6847-
path-to-regexp "0.1.10"
6840+
path-to-regexp "0.1.12"
68486841
proxy-addr "~2.0.7"
68496842
qs "6.13.0"
68506843
range-parser "~1.2.1"
@@ -9581,27 +9574,13 @@ minimalistic-assert@^1.0.0:
95819574
resolved "https://registry.yarnpkg.com/minimalistic-assert/-/minimalistic-assert-1.0.1.tgz#2e194de044626d4a10e7f7fbc00ce73e83e4d5c7"
95829575
integrity sha512-UtJcAD4yEaGtjPezWuO9wC4nwUnVH/8/Im3yEHQP4b67cXlD/Qr9hdITCU1xDbSEXg2XKNaP8jsReV7vQd00/A==
95839576

9584-
minimatch@^3.0.2, minimatch@^3.0.4:
9585-
version "3.0.4"
9586-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-3.0.4.tgz#5166e286457f03306064be5497e8dbb0c3d32083"
9587-
integrity sha512-yJHVQEhyqPLUTgt9B83PXu6W3rx4MvvHvSUvToogpwoGDOUQ+yDrR0HRot+yOCdCO7u4hX3pWft6kWBBcqh0UA==
9588-
dependencies:
9589-
brace-expansion "^1.1.7"
9590-
9591-
minimatch@^3.0.5, minimatch@^3.1.1, minimatch@^3.1.2:
9577+
minimatch@^3.0.2, minimatch@^3.0.4, minimatch@^3.0.5, minimatch@^3.1.1, minimatch@^3.1.2, minimatch@^9.0.4:
95929578
version "3.1.2"
95939579
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-3.1.2.tgz#19cd194bfd3e428f049a70817c038d89ab4be35b"
95949580
integrity sha512-J7p63hRiAjw1NDEww1W7i37+ByIrOWO5XQQAzZ3VOcL0PNybwpfmV/N05zFAzwQ9USyEcX6t3UO+K5aqBQOIHw==
95959581
dependencies:
95969582
brace-expansion "^1.1.7"
95979583

9598-
minimatch@^9.0.4:
9599-
version "9.0.5"
9600-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-9.0.5.tgz#d74f9dd6b57d83d8e98cfb82133b03978bc929e5"
9601-
integrity sha512-G6T0ZX48xgozx7587koeX9Ys2NYy6Gmv//P89sEte9V9whIapMNF4idKxnW2QtCcLiTWlb/wfCabAtAFWhhBow==
9602-
dependencies:
9603-
brace-expansion "^2.0.1"
9604-
96059584
minimist@^1.1.0, minimist@^1.2.0, minimist@^1.2.5, minimist@^1.2.6, minimist@^1.2.8:
96069585
version "1.2.8"
96079586
resolved "https://registry.yarnpkg.com/minimist/-/minimist-1.2.8.tgz#c1a464e7693302e082a075cee0c057741ac4772c"
@@ -10146,10 +10125,10 @@ path-posix@^1.0.0:
1014610125
resolved "https://registry.yarnpkg.com/path-posix/-/path-posix-1.0.0.tgz#06b26113f56beab042545a23bfa88003ccac260f"
1014710126
integrity sha1-BrJhE/Vr6rBCVFojv6iAA8ysJg8=
1014810127

10149-
10150-
version "0.1.10"
10151-
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-0.1.10.tgz#67e9108c5c0551b9e5326064387de4763c4d5f8b"
10152-
integrity sha512-7lf7qcQidTku0Gu3YDPc8DJ1q7OOucfa/BSsIwjuh56VU7katFvuM8hULfkwB3Fns/rsVF7PwPKVw1sl5KQS9w==
10128+
10129+
version "0.1.12"
10130+
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-0.1.12.tgz#d5e1a12e478a976d432ef3c58d534b9923164bb7"
10131+
integrity sha512-RA1GjUVMnvYFxuqovrEqZoxxW5NUZqbwKtYz/Tt7nXerk0LbLblQmrsgdeOxV5SFHf0UDggjS/bSeOZwt1pmEQ==
1015310132

1015410133
path-to-regexp@^1.7.0:
1015510134
version "1.9.0"
@@ -11534,10 +11513,10 @@ spdy@^4.0.2:
1153411513
select-hose "^2.0.0"
1153511514
spdy-transport "^3.0.0"
1153611515

11537-
sprintf-js@^1.0.3:
11538-
version "1.1.2"
11539-
resolved "https://registry.yarnpkg.com/sprintf-js/-/sprintf-js-1.1.2.tgz#da1765262bf8c0f571749f2ad6c26300207ae673"
11540-
integrity sha512-VE0SOVEHCk7Qc8ulkWw3ntAzXuqf7S2lvwQaDLRnUeIEaKNQJzV6BwmLKhOqT61aGhfUMrXeaBk+oDGCzvhcug==
11516+
sprintf-js@^1.1.1:
11517+
version "1.1.3"
11518+
resolved "https://registry.yarnpkg.com/sprintf-js/-/sprintf-js-1.1.3.tgz#4914b903a2f8b685d17fdf78a70e917e872e444a"
11519+
integrity sha512-Oo+0REFV59/rz3gfJNKQiBlwfHaSESl1pcGyABQsnnIfWOFt6JNj5gCog2U6MLZ//IGYD+nA8nI+mTShREReaA==
1154111520

1154211521
sprintf-js@~1.0.2:
1154311522
version "1.0.3"
@@ -12365,18 +12344,18 @@ unbox-primitive@^1.0.2:
1236512344
has-symbols "^1.0.3"
1236612345
which-boxed-primitive "^1.0.2"
1236712346

12368-
underscore.string@~3.3.4:
12369-
version "3.3.5"
12370-
resolved "https://registry.yarnpkg.com/underscore.string/-/underscore.string-3.3.5.tgz#fc2ad255b8bd309e239cbc5816fd23a9b7ea4023"
12371-
integrity sha512-g+dpmgn+XBneLmXXo+sGlW5xQEt4ErkS3mgeN2GFbremYeMBSJKr9Wf2KJplQVaiPY/f7FN6atosWYNm9ovrYg==
12347+
underscore.string@^3.3.6, underscore.string@~3.3.4:
12348+
version "3.3.6"
12349+
resolved "https://registry.yarnpkg.com/underscore.string/-/underscore.string-3.3.6.tgz#ad8cf23d7423cb3b53b898476117588f4e2f9159"
12350+
integrity sha512-VoC83HWXmCrF6rgkyxS9GHv8W9Q5nhMKho+OadDJGzL2oDYbYEppBaCMH6pFlwLeqj2QS+hhkw2kpXkSdD1JxQ==
1237212351
dependencies:
12373-
sprintf-js "^1.0.3"
12352+
sprintf-js "^1.1.1"
1237412353
util-deprecate "^1.0.2"
1237512354

12376-
undici@^6.19.5:
12377-
version "6.20.1"
12378-
resolved "https://registry.yarnpkg.com/undici/-/undici-6.20.1.tgz#fbb87b1e2b69d963ff2d5410a40ffb4c9e81b621"
12379-
integrity sha512-AjQF1QsmqfJys+LXfGTNum+qw4S88CojRInG/6t31W/1fk6G59s92bnAvGz5Cmur+kQv2SURXEvvudLmbrE8QA==
12355+
undici@^6.19.5, undici@^6.21.1:
12356+
version "6.21.2"
12357+
resolved "https://registry.yarnpkg.com/undici/-/undici-6.21.2.tgz#49c5884e8f9039c65a89ee9018ef3c8e2f1f4928"
12358+
integrity sha512-uROZWze0R0itiAKVPsYhFov9LxrPMHLMEQFszeI2gCN6bnIIZ8twzBCJcN2LJrBBLfrP0t1FW0g+JmKVl8Vk1g==
1238012359

1238112360
unicorn-magic@^0.1.0:
1238212361
version "0.1.0"

0 commit comments

Comments
 (0)