Skip to content

Commit 0d1c565

Browse files
chore(deps): update several dependencies to solve CVEs (#40403)
Co-authored-by: Julio Araujo <julio.araujo@rocket.chat>
1 parent c7020a1 commit 0d1c565

9 files changed

Lines changed: 667 additions & 828 deletions

File tree

apps/meteor/ee/server/services/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@
2828
"@rocket.chat/string-helpers": "~0.32.0",
2929
"@rocket.chat/ui-kit": "workspace:~",
3030
"ajv": "^8.17.1",
31-
"bcrypt": "^5.1.1",
31+
"bcrypt": "^6.0.0",
3232
"body-parser": "^1.20.4",
3333
"colorette": "^2.0.20",
3434
"cookie": "^0.7.2",

apps/meteor/package.json

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@
8585
"@opentelemetry/api": "^1.9.1",
8686
"@opentelemetry/exporter-trace-otlp-grpc": "^0.54.2",
8787
"@opentelemetry/sdk-node": "^0.54.2",
88-
"@parse/node-apn": "^7.0.1",
88+
"@parse/node-apn": "^8.1.0",
8989
"@react-aria/toolbar": "^3.0.0-nightly.5042",
9090
"@react-pdf/renderer": "^4.3.2",
9191
"@rocket.chat/abac": "workspace:^",
@@ -169,7 +169,7 @@
169169
"asterisk-manager": "^0.2.0",
170170
"atlassian-crowd-patched": "^0.5.1",
171171
"bad-words": "^3.0.4",
172-
"bcrypt": "^5.1.1",
172+
"bcrypt": "^6.0.0",
173173
"body-parser": "1.20.4",
174174
"bson": "^6.7.1",
175175
"busboy": "^1.6.0",
@@ -316,7 +316,7 @@
316316
"@babel/preset-react": "~7.27.1",
317317
"@babel/register": "~7.28.6",
318318
"@faker-js/faker": "~8.0.2",
319-
"@playwright/test": "^1.52.0",
319+
"@playwright/test": "~1.52.0",
320320
"@rocket.chat/desktop-api": "workspace:~",
321321
"@rocket.chat/jest-presets": "workspace:~",
322322
"@rocket.chat/livechat": "workspace:^",
@@ -335,7 +335,7 @@
335335
"@types/adm-zip": "^0.5.8",
336336
"@types/archiver": "~6.0.4",
337337
"@types/bad-words": "^3.0.3",
338-
"@types/bcrypt": "^5.0.2",
338+
"@types/bcrypt": "^6.0.0",
339339
"@types/body-parser": "^1.19.6",
340340
"@types/busboy": "^1.5.4",
341341
"@types/chai": "~4.3.20",
@@ -423,7 +423,7 @@
423423
"outdent": "~0.8.0",
424424
"pino-pretty": "13.1.3",
425425
"playwright-core": "~1.52.0",
426-
"playwright-qase-reporter": "~2.1.7",
426+
"playwright-qase-reporter": "~2.5.0",
427427
"postcss": "~8.4.49",
428428
"postcss-custom-properties": "^14.0.6",
429429
"postcss-easy-import": "^4.0.0",

ee/apps/account-service/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@
3131
"@rocket.chat/tools": "workspace:^",
3232
"@rocket.chat/tracing": "workspace:^",
3333
"@types/node": "~22.16.5",
34-
"bcrypt": "^5.1.1",
34+
"bcrypt": "^6.0.0",
3535
"ejson": "^2.2.3",
3636
"eventemitter3": "^5.0.4",
3737
"mem": "^8.1.1",
@@ -45,7 +45,7 @@
4545
},
4646
"devDependencies": {
4747
"@rocket.chat/tsconfig": "workspace:*",
48-
"@types/bcrypt": "^5.0.2",
48+
"@types/bcrypt": "^6.0.0",
4949
"@types/polka": "^0.5.8",
5050
"@types/prometheus-gc-stats": "^0.6.4",
5151
"eslint": "~9.39.4",

ee/packages/federation-matrix/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@
4747
"@types/sanitize-html": "~2.16.1",
4848
"eslint": "~9.39.4",
4949
"jest": "~30.2.0",
50-
"jest-qase-reporter": "^2.1.4",
50+
"jest-qase-reporter": "^2.4.0",
5151
"matrix-js-sdk": "^38.4.0",
5252
"pino-pretty": "13.1.3",
5353
"typescript": "~5.9.3"

ee/packages/license/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,12 +20,12 @@
2020
"@rocket.chat/core-typings": "workspace:^",
2121
"@rocket.chat/jwt": "workspace:^",
2222
"@rocket.chat/logger": "workspace:^",
23-
"bcrypt": "^5.1.1"
23+
"bcrypt": "^6.0.0"
2424
},
2525
"devDependencies": {
2626
"@rocket.chat/jest-presets": "workspace:~",
2727
"@rocket.chat/tsconfig": "workspace:*",
28-
"@types/bcrypt": "^5.0.2",
28+
"@types/bcrypt": "^6.0.0",
2929
"@types/jest": "~30.0.0",
3030
"@types/ws": "^8.5.14",
3131
"eslint": "~9.39.4",

package.json

Lines changed: 59 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,16 @@
3737
"resolutions": {
3838
"@sematext/gc-stats@npm:^1.5.9": "patch:@sematext/gc-stats@npm%3A1.5.9#~/.yarn/patches/@sematext-gc-stats-npm-1.5.9-01e77be4d0.patch",
3939
"adm-zip": "0.5.9",
40+
"axios@npm:^1.6.1": "1.15.2",
41+
"axios@npm:^1.7.4": "1.15.2",
42+
"axios@npm:^1.7.8": "1.15.2",
43+
"axios@npm:^1.11.0": "1.15.2",
44+
"axios@npm:^1.13.2": "1.15.2",
45+
"sass/immutable": "5.1.5",
46+
"jws@npm:^3.2.2": "3.2.3",
47+
"jws@npm:^4.0.0": "4.0.1",
48+
"tar-fs@npm:^2.0.0": "2.1.4",
49+
"tar-fs@npm:^3.0.6": "3.0.10",
4050
"brace-expansion@npm:^2.0.1": "^2.0.3",
4151
"brace-expansion@npm:^5.0.2": "^5.0.5",
4252
"@meteorjs/crypto-browserify/pbkdf2": "3.1.3",
@@ -56,6 +66,14 @@
5666
"mongodb": "6.10.0",
5767
"protobufjs": "7.5.5",
5868
"webdav/axios": "0.31.1",
69+
"flatted@npm:^3.1.0": "3.4.2",
70+
"flatted@npm:^3.2.9": "3.4.2",
71+
"flatted@npm:^3.3.1": "3.4.2",
72+
"glob@npm:^10.0.0": "10.5.0",
73+
"glob@npm:^10.2.2": "10.5.0",
74+
"glob@npm:^10.3.7": "10.5.0",
75+
"glob@npm:^10.3.10": "10.5.0",
76+
"glob@npm:^11.0.0": "11.1.0",
5977
"picomatch@npm:^2.0.4": "^2.3.2",
6078
"picomatch@npm:^2.2.1": "^2.3.2",
6179
"picomatch@npm:^2.2.3": "^2.3.2",
@@ -91,11 +109,50 @@
91109
"create-hash/cipher-base": "1.0.7",
92110
"create-hmac/cipher-base": "1.0.7",
93111
"create-hash/sha.js": "2.4.12",
94-
"create-hmac/sha.js": "2.4.12"
112+
"create-hmac/sha.js": "2.4.12",
113+
"@typescript-eslint/typescript-estree/minimatch": "10.2.5",
114+
"depcheck/minimatch": "7.4.9",
115+
"eslint-plugin-import/minimatch": "3.1.5",
116+
"eslint-plugin-jsx-a11y/minimatch": "3.1.5",
117+
"eslint-plugin-react/minimatch": "3.1.5",
118+
"fork-ts-checker-webpack-plugin/minimatch": "3.1.5",
119+
"mocha/minimatch": "4.2.6",
120+
"multimatch/minimatch": "3.1.5",
121+
"npm-run-all/minimatch": "3.1.5",
122+
"postcss-bem-linter/minimatch": "3.1.5",
123+
"postcss-url/minimatch": "3.1.5",
124+
"readdir-glob/minimatch": "5.1.9",
125+
"test-exclude/minimatch": "3.1.5",
126+
"webdav/minimatch": "5.1.9",
127+
"glob@npm:7.2.0/minimatch": "3.1.5",
128+
"minimatch@npm:^3.1.1": "3.1.5",
129+
"minimatch@npm:^9.0.4": "9.0.9",
130+
"minimatch@npm:^10.0.0": "10.2.5",
131+
"nodemailer@npm:^8.0.5": "8.0.7",
132+
"mailparser/nodemailer": "7.0.13",
133+
"normalize-package-data@npm:2.5.0/semver": "5.7.2",
134+
"make-dir@npm:2.1.0/semver": "5.7.2",
135+
"utf7/semver": "5.7.2",
136+
"semver@npm:^7.3.2": "7.7.4",
137+
"semver@npm:^7.3.4": "7.7.4",
138+
"semver@npm:^7.3.5": "7.7.4",
139+
"semver@npm:^7.3.7": "7.7.4",
140+
"semver@npm:^7.5.2": "7.7.4",
141+
"semver@npm:^7.5.3": "7.7.4",
142+
"semver@npm:^7.5.4": "7.7.4",
143+
"semver@npm:^7.6.2": "7.7.4",
144+
"semver@npm:^7.6.3": "7.7.4",
145+
"semver@npm:^7.7.1": "7.7.4",
146+
"semver@npm:^7.7.2": "7.7.4",
147+
"semver@npm:^7.7.3": "7.7.4",
148+
"@peggyjs/from-mem/semver": "7.7.4",
149+
"node-gyp/tar": "7.5.13",
150+
"cacache/tar": "7.5.13",
151+
"@mapbox/node-pre-gyp/tar": "7.5.13"
95152
},
96153
"dependencies": {
97154
"@types/stream-buffers": "^3.0.8",
98-
"node-gyp": "^10.2.0"
155+
"node-gyp": "^11.0.0"
99156
},
100157
"devDependencies": {
101158
"@changesets/cli": "^2.27.12",

packages/livechat/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@
7777
"babel-loader": "~10.0.0",
7878
"cross-env": "^7.0.3",
7979
"css-loader": "^4.3.0",
80-
"cssnano": "^7.0.7",
80+
"cssnano": "^7.1.7",
8181
"desvg-loader": "^0.1.0",
8282
"eslint": "~9.39.4",
8383
"file-loader": "^6.2.0",

packages/ui-voip/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@
2626
"react-i18next": "~13.2.2"
2727
},
2828
"devDependencies": {
29-
"@playwright/test": "^1.52.0",
29+
"@playwright/test": "~1.52.0",
3030
"@react-spectrum/test-utils": "~1.0.0-alpha.8",
3131
"@rocket.chat/core-typings": "workspace:^",
3232
"@rocket.chat/css-in-js": "~0.31.25",

0 commit comments

Comments
 (0)