From 815410885e2e84f4d35d526cec0d6fbae4557f18 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 14 Nov 2023 17:31:27 +0000 Subject: [PATCH] fix: backend/package.json & backend/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-SWAGGERUIDIST-6056393 --- backend/package-lock.json | 14 +++++++------- backend/package.json | 2 +- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/backend/package-lock.json b/backend/package-lock.json index 78d8809b861..8f0dc85e885 100644 --- a/backend/package-lock.json +++ b/backend/package-lock.json @@ -9963,16 +9963,16 @@ } }, "swagger-ui-dist": { - "version": "3.25.0", - "resolved": "https://registry.npmjs.org/swagger-ui-dist/-/swagger-ui-dist-3.25.0.tgz", - "integrity": "sha512-vwvJPPbdooTvDwLGzjIXinOXizDJJ6U1hxnJL3y6U3aL1d2MSXDmKg2139XaLBhsVZdnQJV2bOkX4reB+RXamg==" + "version": "5.9.4", + "resolved": "https://registry.npmjs.org/swagger-ui-dist/-/swagger-ui-dist-5.9.4.tgz", + "integrity": "sha512-Ppghvj6Q8XxH5xiSrUjEeCUitrasGtz7v9FCUIBR/4t89fACQ4FnUT9D0yfodUYhB+PrCmYmxwe/2jTDLslHDw==" }, "swagger-ui-express": { - "version": "4.1.4", - "resolved": "https://registry.npmjs.org/swagger-ui-express/-/swagger-ui-express-4.1.4.tgz", - "integrity": "sha512-Ea96ecpC+Iq9GUqkeD/LFR32xSs8gYqmTW1gXCuKg81c26WV6ZC2FsBSPVExQP6WkyUuz5HEiR0sEv/HCC343g==", + "version": "4.2.0", + "resolved": "https://registry.npmjs.org/swagger-ui-express/-/swagger-ui-express-4.2.0.tgz", + "integrity": "sha512-znrHTwh9UpvsjqgWopA4noIet7mi7UGuIYZ465YfUDKQ5Dpas0jxnkfUKCo+0aB17YCBv26AhIjiQYDV4uvJFA==", "requires": { - "swagger-ui-dist": "^3.18.1" + "swagger-ui-dist": ">3.52.5" } }, "symbol-tree": { diff --git a/backend/package.json b/backend/package.json index a43c259f53a..309c5f879b5 100644 --- a/backend/package.json +++ b/backend/package.json @@ -60,7 +60,7 @@ "pg": "^7.9.0", "reflect-metadata": "^0.1.12", "rxjs": "^6.5.4", - "swagger-ui-express": "^4.1.4", + "swagger-ui-express": "^4.2.0", "typeorm": "^0.2.24", "uuid": "^3.4.0", "winston-loggly-bulk": "^2.0.3",