From 02ca6bdf49cfbcfc8a28c4e8989163544fdc5f62 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 15 Jul 2024 16:24:29 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-TOMPHTTPBARESERVERNODE-6405832 --- package-lock.json | 17 ++++++----------- package.json | 2 +- 2 files changed, 7 insertions(+), 12 deletions(-) diff --git a/package-lock.json b/package-lock.json index 45d2126c..29c9600b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,23 +9,23 @@ "version": "2.0.1", "license": "ISC", "dependencies": { - "@tomphttp/bare-server-node": "2.0.1", + "@tomphttp/bare-server-node": "^2.0.2", "cors": "^2.8.5", "express": "^4.19.2", "jquery": "^3.7.1" } }, "node_modules/@tomphttp/bare-server-node": { - "version": "2.0.1", - "resolved": "https://registry.npmjs.org/@tomphttp/bare-server-node/-/bare-server-node-2.0.1.tgz", - "integrity": "sha512-L42TC/AldYRFBRZSxhkI0FC5TL8EC/NAsepNC/cWYTTiHQJ7mGg/vdTqNz8ShTYHr6LTHYkuD3/81nhX55SYtA==", + "version": "2.0.2", + "resolved": "https://registry.npmjs.org/@tomphttp/bare-server-node/-/bare-server-node-2.0.2.tgz", + "integrity": "sha512-C9UPAY2gNF4mY+2r2wyRqz8tK6Qv4Ps5Q0P8kZx1tCw9oIaTnwfcofEKIyJY7ds6bYnCd1TE7PVz6AioNVuQQA==", + "license": "GPL-3.0", "dependencies": { "async-exit-hook": "^2.0.1", "commander": "^10.0.1", "dotenv": "^16.0.3", - "headers-polyfill": "^3.1.2", "http-errors": "^2.0.0", - "ipaddr.js": "^2.0.1", + "ipaddr.js": "^2.1.0", "source-map-support": "^0.5.21", "ws": "^8.13.0" }, @@ -427,11 +427,6 @@ "node": ">= 0.4" } }, - "node_modules/headers-polyfill": { - "version": "3.3.0", - "resolved": "https://registry.npmjs.org/headers-polyfill/-/headers-polyfill-3.3.0.tgz", - "integrity": "sha512-5e57etwBpNcDc0b6KCVWEh/Ro063OxPvzVimUdM0/tsYM/T7Hfy3kknIGj78SFTOhNd8AZY41U8mOHoO4LzmIQ==" - }, "node_modules/http-errors": { "version": "2.0.0", "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-2.0.0.tgz", diff --git a/package.json b/package.json index d298d845..ee9c6194 100644 --- a/package.json +++ b/package.json @@ -9,7 +9,7 @@ "author": "", "license": "ISC", "dependencies": { - "@tomphttp/bare-server-node": "2.0.1", + "@tomphttp/bare-server-node": "2.0.2", "cors": "^2.8.5", "express": "^4.19.2", "jquery": "^3.7.1"