diff --git a/CHANGELOG.md b/CHANGELOG.md index 869e55642..1be6197ed 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Okta Node SDK Changelog +## 6.2.0 + +### Others + +- [#295](https://github.com/okta/okta-sdk-nodejs/pull/295) Upgrades `parse-link-header` to v2.0 to resolve `ReDos` vulnerability issue. + ## 6.1.0 ### Features diff --git a/package.json b/package.json index ffe506c2e..8f73598d6 100644 --- a/package.json +++ b/package.json @@ -37,7 +37,7 @@ "js-yaml": "^4.1.0", "lodash": "^4.17.20", "njwt": "^1.0.0", - "parse-link-header": "^1.0.1", + "parse-link-header": "^2.0.0", "rasha": "^1.2.5", "safe-flat": "^2.0.2" }, @@ -85,4 +85,4 @@ "tsd": { "directory": "test/type" } -} \ No newline at end of file +} diff --git a/yarn.lock b/yarn.lock index 5148864dd..37db7451d 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3605,10 +3605,10 @@ parse-json@^5.0.0: json-parse-even-better-errors "^2.3.0" lines-and-columns "^1.1.6" -parse-link-header@^1.0.1: - version "1.0.1" - resolved "https://registry.yarnpkg.com/parse-link-header/-/parse-link-header-1.0.1.tgz#bedfe0d2118aeb84be75e7b025419ec8a61140a7" - integrity sha1-vt/g0hGK64S+deewJUGeyKYRQKc= +parse-link-header@^2.0.0: + version "2.0.0" + resolved "https://registry.yarnpkg.com/parse-link-header/-/parse-link-header-2.0.0.tgz#949353e284f8aa01f2ac857a98f692b57733f6b7" + integrity sha512-xjU87V0VyHZybn2RrCX5TIFGxTVZE6zqqZWMPlIKiSKuWh/X5WZdt+w1Ki1nXB+8L/KtL+nZ4iq+sfI6MrhhMw== dependencies: xtend "~4.0.1"