Skip to content

Commit eaad30b

Browse files
authored
Security: update basic-ftp, hono, postcss, ip-address, fast-uri, remove request(gulp-remote-src) (#33558)
1 parent 1c6930d commit eaad30b

8 files changed

Lines changed: 164 additions & 619 deletions

File tree

.github/renovate.json

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -141,7 +141,6 @@
141141
"gulp-jsbeautifier",
142142
"gulp-multi-process",
143143
"gulp-notify",
144-
"gulp-remote-src",
145144
"gulp-rename",
146145
"gulp-tap",
147146
"gulp-uglify-es",

package.json

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@
5050
"lint-staged": "14.0.1",
5151
"nx": "22.4.5",
5252
"nx-cloud": "19.1.0",
53-
"postcss": "8.4.38",
53+
"postcss": "~8.5.10",
5454
"shelljs": "0.8.5",
5555
"shx": "0.4.0",
5656
"source-map": "0.7.4",
@@ -67,12 +67,12 @@
6767
"pnpm": {
6868
"overrides": {
6969
"@devexpress/callsite-record@^4.1.6": "4.1.7",
70-
"@hono/node-server@<1.19.10": "^1.19.10",
70+
"@hono/node-server@<1.19.13": "^1.19.13",
7171
"@modelcontextprotocol/sdk@>=1.10.0 <=1.25.3": "^1.26.0",
7272
"@tootallnate/once@<3.0.1": "^3.0.1",
7373
"ajv@>=7.0.0-alpha.0 <8.18.0": "^8.18.0",
7474
"axios@<1.15.2": "^1.15.2",
75-
"basic-ftp@<=5.2.2": "~5.3.0",
75+
"basic-ftp@<5.3.1": ">=5.3.1",
7676
"bn.js@<4.12.3": "4.12.3",
7777
"bn.js@>=5.0.0 <5.2.3": "5.2.3",
7878
"brace-expansion@<1.1.13": "1.1.13",
@@ -81,15 +81,17 @@
8181
"cookie@<0.7.0": "^0.7.0",
8282
"diff@>=4.0.0 <4.0.4": "4.0.4",
8383
"diff@>=5.0.0 <5.2.2": "5.2.2",
84-
"dompurify@<=3.3.1": "^3.3.2",
84+
"dompurify@<=3.3.3": ">=3.4.0",
8585
"express-rate-limit@>=8.2.0 <8.2.2": "^8.2.2",
86+
"fast-uri@<3.1.2": ">=3.1.2",
8687
"flatted@<3.4.0": "^3.4.0",
8788
"form-data@<2.5.4": "2.5.5",
8889
"form-data@>=4.0.0 <4.0.4": "^4.0.5",
8990
"glob@>=10.2.0 <10.5.0": "^10.5.0",
90-
"hono@<4.12.4": "^4.12.4",
91+
"hono@<4.12.18": ">=4.12.18",
9192
"immutable@>=4.0.0-rc.1 <4.3.8": "^4.3.8",
9293
"immutable@>=5.0.0 <5.1.5": "^5.1.5",
94+
"ip-address@<=10.1.0": ">=10.1.1",
9395
"json5@<1.0.2": "^2.2.3",
9496
"lodash.template@<4.18.1": "4.18.1",
9597
"lodash@<4.18.1": "4.18.1",
@@ -102,9 +104,10 @@
102104
"path-to-regexp@0.1.12": "0.1.13",
103105
"path-to-regexp@>=8.0.0 <8.4.0": "8.4.0",
104106
"pbkdf2@<=3.1.2": "^3.1.3",
107+
"postcss@<8.5.10": "8.5.10",
105108
"picomatch@>=2.0.0 <2.3.2": "2.3.2",
106109
"picomatch@>=4.0.0 <4.0.4": "4.0.4",
107-
"qs": ">=6.14.1",
110+
"qs": ">=6.14.2",
108111
"rollup@< 4.59.0": "^4.59.0",
109112
"rollup@<2.79.2": "^4.53.3",
110113
"semver@<5.7.2": "^5.7.2",

packages/devextreme-themebuilder/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@
3030
"dependencies": {
3131
"autoprefixer": "^10.4.21",
3232
"clean-css": "^5.3.0",
33-
"postcss": "^8.2.6",
33+
"postcss": "^8.5.10",
3434
"sass-embedded": "1.66.0"
3535
},
3636
"devDependencies": {

packages/devextreme/build/gulp/test_timezones_data.js

Lines changed: 0 additions & 103 deletions
This file was deleted.

packages/devextreme/package.json

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -159,7 +159,6 @@
159159
"gulp-multi-process": "1.4.0",
160160
"gulp-notify": "4.0.0",
161161
"gulp-plumber": "1.2.1",
162-
"gulp-remote-src": "0.4.4",
163162
"gulp-rename": "1.4.0",
164163
"gulp-replace": "0.6.1",
165164
"gulp-sass": "6.0.1",

packages/sbom/package.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,5 +5,10 @@
55
"devDependencies": {
66
"@devexpress/sbom-toolkit": "0.6.1"
77
},
8+
"pnpm": {
9+
"overrides": {
10+
"fast-uri@<3.1.2": ">=3.1.2"
11+
}
12+
},
813
"packageManager": "pnpm@9.15.4"
914
}

packages/sbom/pnpm-lock.yaml

Lines changed: 7 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)