From e72b4d14124502040fa312a9f5bf04aa0fede5a0 Mon Sep 17 00:00:00 2001 From: julianajlk Date: Thu, 2 May 2024 11:00:47 -0400 Subject: [PATCH 1/3] chore: Upgrade webpack-dev-middleware and follow-redirects --- package-lock.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index bdc76c7f7..d0168321c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9466,9 +9466,9 @@ } }, "node_modules/follow-redirects": { - "version": "1.15.5", - "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.5.tgz", - "integrity": "sha512-vSFWUON1B+yAw1VN4xMfxgn5fTUiaOzAJCKBwIIgT/+7CuGy9+r+5gITvP62j3RmaD5Ph65UaERdOSRGUzZtgw==", + "version": "1.15.6", + "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.6.tgz", + "integrity": "sha512-wWN62YITEaOpSK584EZXJafH1AGpO8RVgElfkuXbTOrPX4fIfOyEpW/CsiNd8JdYrAoOvafRTOEnvsO++qCqFA==", "funding": [ { "type": "individual", @@ -19338,9 +19338,9 @@ } }, "node_modules/webpack-dev-middleware": { - "version": "5.3.3", - "resolved": "https://registry.npmjs.org/webpack-dev-middleware/-/webpack-dev-middleware-5.3.3.tgz", - "integrity": "sha512-hj5CYrY0bZLB+eTO+x/j67Pkrquiy7kWepMHmUMoPsmcUaeEnQJqFzHJOyxgWlq746/wUuA64p9ta34Kyb01pA==", + "version": "5.3.4", + "resolved": "https://registry.npmjs.org/webpack-dev-middleware/-/webpack-dev-middleware-5.3.4.tgz", + "integrity": "sha512-BVdTqhhs+0IfoeAf7EoH5WE+exCmqGerHfDM0IL096Px60Tq2Mn9MAbnaGUe6HiMa41KMCYF19gyzZmBcq/o4Q==", "dependencies": { "colorette": "^2.0.10", "memfs": "^3.4.3", From 6b67ba57dc6f902de8b6c2f4ac92cfbf5d0c89a3 Mon Sep 17 00:00:00 2001 From: julianajlk Date: Thu, 2 May 2024 11:01:50 -0400 Subject: [PATCH 2/3] chore: Remove the above from allowlist after upgrade --- audit-ci.json | 2 -- 1 file changed, 2 deletions(-) diff --git a/audit-ci.json b/audit-ci.json index d598dccb1..135ae9fc3 100644 --- a/audit-ci.json +++ b/audit-ci.json @@ -1,8 +1,6 @@ { "allowlist": [ "GHSA-wf5p-g6vw-rhxx", - "GHSA-cxjh-pqwp-8mfp", - "GHSA-wr3j-pwj9-hqq6", "GHSA-rv95-896h-c2vc", "GHSA-8cp3-66vr-3r4c" ], From 28ba29b82d7b62f1ee5d6c6e93f4a48661ecc6c5 Mon Sep 17 00:00:00 2001 From: julianajlk Date: Thu, 2 May 2024 11:04:27 -0400 Subject: [PATCH 3/3] chore: Remove GHSA-8cp3-66vr-3r4c from allowlist as per npm recommendation --- audit-ci.json | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/audit-ci.json b/audit-ci.json index 135ae9fc3..6a826db6b 100644 --- a/audit-ci.json +++ b/audit-ci.json @@ -1,8 +1,7 @@ { "allowlist": [ "GHSA-wf5p-g6vw-rhxx", - "GHSA-rv95-896h-c2vc", - "GHSA-8cp3-66vr-3r4c" + "GHSA-rv95-896h-c2vc" ], "moderate": true }