Skip to content

Commit d4d3977

Browse files
davsclausclaude
andauthored
chore: upgrade glob and js-yaml to fix security advisories (#1660)
* chore: upgrade glob and js-yaml to fix security advisories Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore: update antora-ui-camel yarn.lock for js-yaml 4.x Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * chore: dedupe js-yaml and minipass in lockfiles Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 1301e4a commit d4d3977

5 files changed

Lines changed: 63 additions & 73 deletions

File tree

antora-ui-camel/gulp.d/tasks/build-preview-pages.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ module.exports = (src, previewSrc, previewDest, sink = () => map()) => (done) =>
7575
)
7676

7777
function loadSampleUiModel (src) {
78-
return fs.readFile(ospath.join(src, 'ui-model.yml'), 'utf8').then((contents) => yaml.safeLoad(contents))
78+
return fs.readFile(ospath.join(src, 'ui-model.yml'), 'utf8').then((contents) => yaml.load(contents))
7979
}
8080

8181
function registerPartials (src) {

antora-ui-camel/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@
5151
"gulp-terser": "^1.2.0",
5252
"handlebars": "^4.7.9",
5353
"highlight.js": "~11",
54-
"js-yaml": "~3.14.2",
54+
"js-yaml": "^4.2.0",
5555
"merge-stream": "~2.0",
5656
"plugin-error": "~1.0",
5757
"postcss-calc": "~7.0",

antora-ui-camel/yarn.lock

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1017,7 +1017,7 @@ __metadata:
10171017
gulp-terser: "npm:^1.2.0"
10181018
handlebars: "npm:^4.7.9"
10191019
highlight.js: "npm:~11"
1020-
js-yaml: "npm:~3.14.2"
1020+
js-yaml: "npm:^4.2.0"
10211021
merge-stream: "npm:~2.0"
10221022
plugin-error: "npm:~1.0"
10231023
postcss-calc: "npm:~7.0"
@@ -7467,7 +7467,7 @@ __metadata:
74677467
languageName: node
74687468
linkType: hard
74697469

7470-
"js-yaml@npm:^3.13.0, js-yaml@npm:^3.13.1, js-yaml@npm:^3.9.0, js-yaml@npm:~3.14.2":
7470+
"js-yaml@npm:^3.13.0, js-yaml@npm:^3.13.1, js-yaml@npm:^3.9.0":
74717471
version: 3.14.2
74727472
resolution: "js-yaml@npm:3.14.2"
74737473
dependencies:
@@ -7479,14 +7479,14 @@ __metadata:
74797479
languageName: node
74807480
linkType: hard
74817481

7482-
"js-yaml@npm:^4.1.0, js-yaml@npm:^4.1.1":
7483-
version: 4.1.1
7484-
resolution: "js-yaml@npm:4.1.1"
7482+
"js-yaml@npm:^4.1.0, js-yaml@npm:^4.1.1, js-yaml@npm:^4.2.0":
7483+
version: 4.2.0
7484+
resolution: "js-yaml@npm:4.2.0"
74857485
dependencies:
74867486
argparse: "npm:^2.0.1"
74877487
bin:
74887488
js-yaml: bin/js-yaml.js
7489-
checksum: 10/a52d0519f0f4ef5b4adc1cde466cb54c50d56e2b4a983b9d5c9c0f2f99462047007a6274d7e95617a21d3c91fde3ee6115536ed70991cd645ba8521058b78f77
7489+
checksum: 10/51de2067a2b44b07ba5206132e56005f8b568ff279bb4d2f645068958c56fa4827d40a6841c983234671fa0a134bf094d0b0717873c2a3d319185297af145a6d
74907490
languageName: node
74917491
linkType: hard
74927492

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,14 +51,14 @@
5151
"chalk": "5.3.0",
5252
"del": "^6.0.0",
5353
"escape-string-regexp": "~2.0",
54-
"glob": "^11.1.0",
54+
"glob": "^13.0.6",
5555
"gulp": "~4.0",
5656
"gulp-cheerio": "~1.0",
5757
"gulp-htmlmin": "~5.0",
5858
"gulp-inject": "^5.0.2",
5959
"html-validate": "^8.9.1",
6060
"hugo-extended": "^0.121.2",
61-
"js-yaml": "~4.1.1",
61+
"js-yaml": "^4.2.0",
6262
"jsdom": "^27.1.0",
6363
"netlify-cli": "17.26.3",
6464
"node-html-parser": "^7.0.1",

yarn.lock

Lines changed: 53 additions & 63 deletions
Original file line numberDiff line numberDiff line change
@@ -1348,22 +1348,6 @@ __metadata:
13481348
languageName: node
13491349
linkType: hard
13501350

1351-
"@isaacs/balanced-match@npm:^4.0.1":
1352-
version: 4.0.1
1353-
resolution: "@isaacs/balanced-match@npm:4.0.1"
1354-
checksum: 10/102fbc6d2c0d5edf8f6dbf2b3feb21695a21bc850f11bc47c4f06aa83bd8884fde3fe9d6d797d619901d96865fdcb4569ac2a54c937992c48885c5e3d9967fe8
1355-
languageName: node
1356-
linkType: hard
1357-
1358-
"@isaacs/brace-expansion@npm:^5.0.0":
1359-
version: 5.0.0
1360-
resolution: "@isaacs/brace-expansion@npm:5.0.0"
1361-
dependencies:
1362-
"@isaacs/balanced-match": "npm:^4.0.1"
1363-
checksum: 10/cf3b7f206aff12128214a1df764ac8cdbc517c110db85249b945282407e3dfc5c6e66286383a7c9391a059fc8e6e6a8ca82262fc9d2590bd615376141fbebd2d
1364-
languageName: node
1365-
linkType: hard
1366-
13671351
"@isaacs/cliui@npm:^8.0.2":
13681352
version: 8.0.2
13691353
resolution: "@isaacs/cliui@npm:8.0.2"
@@ -3820,7 +3804,7 @@ __metadata:
38203804
gulp-terser: "npm:^1.2.0"
38213805
handlebars: "npm:^4.7.9"
38223806
highlight.js: "npm:~11"
3823-
js-yaml: "npm:~3.14.2"
3807+
js-yaml: "npm:^4.2.0"
38243808
merge-stream: "npm:~2.0"
38253809
plugin-error: "npm:~1.0"
38263810
postcss-calc: "npm:~7.0"
@@ -3892,14 +3876,14 @@ __metadata:
38923876
chalk: "npm:5.3.0"
38933877
del: "npm:^6.0.0"
38943878
escape-string-regexp: "npm:~2.0"
3895-
glob: "npm:^11.1.0"
3879+
glob: "npm:^13.0.6"
38963880
gulp: "npm:~4.0"
38973881
gulp-cheerio: "npm:~1.0"
38983882
gulp-htmlmin: "npm:~5.0"
38993883
gulp-inject: "npm:^5.0.2"
39003884
html-validate: "npm:^8.9.1"
39013885
hugo-extended: "npm:^0.121.2"
3902-
js-yaml: "npm:~4.1.1"
3886+
js-yaml: "npm:^4.2.0"
39033887
jsdom: "npm:^27.1.0"
39043888
netlify-cli: "npm:17.26.3"
39053889
node-html-parser: "npm:^7.0.1"
@@ -4555,6 +4539,13 @@ __metadata:
45554539
languageName: node
45564540
linkType: hard
45574541

4542+
"balanced-match@npm:^4.0.2":
4543+
version: 4.0.4
4544+
resolution: "balanced-match@npm:4.0.4"
4545+
checksum: 10/fb07bb66a0959c2843fc055838047e2a95ccebb837c519614afb067ebfdf2fa967ca8d712c35ced07f2cd26fc6f07964230b094891315ad74f11eba3d53178a0
4546+
languageName: node
4547+
linkType: hard
4548+
45584549
"base64-js@npm:^1.0.2, base64-js@npm:^1.3.1":
45594550
version: 1.5.1
45604551
resolution: "base64-js@npm:1.5.1"
@@ -4845,6 +4836,15 @@ __metadata:
48454836
languageName: node
48464837
linkType: hard
48474838

4839+
"brace-expansion@npm:^5.0.5":
4840+
version: 5.0.6
4841+
resolution: "brace-expansion@npm:5.0.6"
4842+
dependencies:
4843+
balanced-match: "npm:^4.0.2"
4844+
checksum: 10/a7acf120fefa79e9d7c9c92898114f57c07596a3920197f3c5917e6a628b04220a5f7f9618c30bdd973a6576a32113b99f9c3f1c8245ccc399dd2a9a718d81d8
4845+
languageName: node
4846+
linkType: hard
4847+
48484848
"braces@npm:^2.3.1, braces@npm:^2.3.2":
48494849
version: 2.3.2
48504850
resolution: "braces@npm:2.3.2"
@@ -10386,7 +10386,7 @@ __metadata:
1038610386
languageName: node
1038710387
linkType: hard
1038810388

10389-
"foreground-child@npm:^3.1.0, foreground-child@npm:^3.3.1":
10389+
"foreground-child@npm:^3.1.0":
1039010390
version: 3.3.1
1039110391
resolution: "foreground-child@npm:3.3.1"
1039210392
dependencies:
@@ -11033,19 +11033,14 @@ __metadata:
1103311033
languageName: node
1103411034
linkType: hard
1103511035

11036-
"glob@npm:^11.1.0":
11037-
version: 11.1.0
11038-
resolution: "glob@npm:11.1.0"
11036+
"glob@npm:^13.0.6":
11037+
version: 13.0.6
11038+
resolution: "glob@npm:13.0.6"
1103911039
dependencies:
11040-
foreground-child: "npm:^3.3.1"
11041-
jackspeak: "npm:^4.1.1"
11042-
minimatch: "npm:^10.1.1"
11043-
minipass: "npm:^7.1.2"
11044-
package-json-from-dist: "npm:^1.0.0"
11045-
path-scurry: "npm:^2.0.0"
11046-
bin:
11047-
glob: dist/esm/bin.mjs
11048-
checksum: 10/da4501819633daff8822c007bb3f93d5c4d2cbc7b15a8e886660f4497dd251a1fb4f53a85fba1e760b31704eff7164aeb2c7a82db10f9f2c362d12c02fe52cf3
11040+
minimatch: "npm:^10.2.2"
11041+
minipass: "npm:^7.1.3"
11042+
path-scurry: "npm:^2.0.2"
11043+
checksum: 10/201ad69e5f0aa74e1d8c00a481581f8b8c804b6a4fbfabeeb8541f5d756932800331daeba99b58fb9e4cd67e12ba5a7eba5b82fb476691588418060b84353214
1104911044
languageName: node
1105011045
linkType: hard
1105111046

@@ -13688,15 +13683,6 @@ __metadata:
1368813683
languageName: node
1368913684
linkType: hard
1369013685

13691-
"jackspeak@npm:^4.1.1":
13692-
version: 4.1.1
13693-
resolution: "jackspeak@npm:4.1.1"
13694-
dependencies:
13695-
"@isaacs/cliui": "npm:^8.0.2"
13696-
checksum: 10/ffceb270ec286841f48413bfb4a50b188662dfd599378ce142b6540f3f0a66821dc9dcb1e9ebc55c6c3b24dc2226c96e5819ba9bd7a241bd29031b61911718c7
13697-
languageName: node
13698-
linkType: hard
13699-
1370013686
"jest-get-type@npm:^27.5.1":
1370113687
version: 27.5.1
1370213688
resolution: "jest-get-type@npm:27.5.1"
@@ -13773,7 +13759,7 @@ __metadata:
1377313759
languageName: node
1377413760
linkType: hard
1377513761

13776-
"js-yaml@npm:^3.13.0, js-yaml@npm:^3.13.1, js-yaml@npm:~3.14.2":
13762+
"js-yaml@npm:^3.13.0, js-yaml@npm:^3.13.1":
1377713763
version: 3.14.2
1377813764
resolution: "js-yaml@npm:3.14.2"
1377913765
dependencies:
@@ -13785,7 +13771,18 @@ __metadata:
1378513771
languageName: node
1378613772
linkType: hard
1378713773

13788-
"js-yaml@npm:^4.0.0, js-yaml@npm:^4.1.0, js-yaml@npm:^4.1.1, js-yaml@npm:~4.1, js-yaml@npm:~4.1.1":
13774+
"js-yaml@npm:^4.0.0, js-yaml@npm:^4.1.0, js-yaml@npm:^4.1.1, js-yaml@npm:^4.2.0":
13775+
version: 4.2.0
13776+
resolution: "js-yaml@npm:4.2.0"
13777+
dependencies:
13778+
argparse: "npm:^2.0.1"
13779+
bin:
13780+
js-yaml: bin/js-yaml.js
13781+
checksum: 10/51de2067a2b44b07ba5206132e56005f8b568ff279bb4d2f645068958c56fa4827d40a6841c983234671fa0a134bf094d0b0717873c2a3d319185297af145a6d
13782+
languageName: node
13783+
linkType: hard
13784+
13785+
"js-yaml@npm:~4.1":
1378913786
version: 4.1.1
1379013787
resolution: "js-yaml@npm:4.1.1"
1379113788
dependencies:
@@ -15300,12 +15297,12 @@ __metadata:
1530015297
languageName: node
1530115298
linkType: hard
1530215299

15303-
"minimatch@npm:^10.1.1":
15304-
version: 10.1.1
15305-
resolution: "minimatch@npm:10.1.1"
15300+
"minimatch@npm:^10.2.2":
15301+
version: 10.2.5
15302+
resolution: "minimatch@npm:10.2.5"
1530615303
dependencies:
15307-
"@isaacs/brace-expansion": "npm:^5.0.0"
15308-
checksum: 10/110f38921ea527022e90f7a5f43721838ac740d0a0c26881c03b57c261354fb9a0430e40b2c56dfcea2ef3c773768f27210d1106f1f2be19cde3eea93f26f45e
15304+
brace-expansion: "npm:^5.0.5"
15305+
checksum: 10/19e87a931aff60ee7b9d80f39f817b8bfc54f61f8356ee3549fbf636dbccacacfec8d803eac73293955c4527cd085247dfc064bce4a5e349f8f3b85e2bf5da0f
1530915306
languageName: node
1531015307
linkType: hard
1531115308

@@ -15431,10 +15428,10 @@ __metadata:
1543115428
languageName: node
1543215429
linkType: hard
1543315430

15434-
"minipass@npm:^5.0.0 || ^6.0.2 || ^7.0.0, minipass@npm:^7.0.2, minipass@npm:^7.0.3, minipass@npm:^7.1.2":
15435-
version: 7.1.2
15436-
resolution: "minipass@npm:7.1.2"
15437-
checksum: 10/c25f0ee8196d8e6036661104bacd743785b2599a21de5c516b32b3fa2b83113ac89a2358465bc04956baab37ffb956ae43be679b2262bf7be15fce467ccd7950
15431+
"minipass@npm:^5.0.0 || ^6.0.2 || ^7.0.0, minipass@npm:^7.0.2, minipass@npm:^7.0.3, minipass@npm:^7.1.2, minipass@npm:^7.1.3":
15432+
version: 7.1.3
15433+
resolution: "minipass@npm:7.1.3"
15434+
checksum: 10/175e4d5e20980c3cd316ae82d2c031c42f6c746467d8b1905b51060a0ba4461441a0c25bb67c025fd9617f9a3873e152c7b543c6b5ac83a1846be8ade80dffd6
1543815435
languageName: node
1543915436
linkType: hard
1544015437

@@ -17148,13 +17145,6 @@ __metadata:
1714817145
languageName: node
1714917146
linkType: hard
1715017147

17151-
"package-json-from-dist@npm:^1.0.0":
17152-
version: 1.0.1
17153-
resolution: "package-json-from-dist@npm:1.0.1"
17154-
checksum: 10/58ee9538f2f762988433da00e26acc788036914d57c71c246bf0be1b60cdbd77dd60b6a3e1a30465f0b248aeb80079e0b34cb6050b1dfa18c06953bb1cbc7602
17155-
languageName: node
17156-
linkType: hard
17157-
1715817148
"package-json@npm:^8.1.0":
1715917149
version: 8.1.1
1716017150
resolution: "package-json@npm:8.1.1"
@@ -17450,13 +17440,13 @@ __metadata:
1745017440
languageName: node
1745117441
linkType: hard
1745217442

17453-
"path-scurry@npm:^2.0.0":
17454-
version: 2.0.1
17455-
resolution: "path-scurry@npm:2.0.1"
17443+
"path-scurry@npm:^2.0.2":
17444+
version: 2.0.2
17445+
resolution: "path-scurry@npm:2.0.2"
1745617446
dependencies:
1745717447
lru-cache: "npm:^11.0.0"
1745817448
minipass: "npm:^7.1.2"
17459-
checksum: 10/1e9c74e9ccf94d7c16056a5cb2dba9fa23eec1bc221ab15c44765486b9b9975b4cd9a4d55da15b96eadf67d5202e9a2f1cec9023fbb35fe7d9ccd0ff1891f88b
17449+
checksum: 10/2b4257422bcb870a4c2d205b3acdbb213a72f5e2250f61c80f79c9d014d010f82bdf8584441612c8e1fa4eb098678f5704a66fa8377d72646bad4be38e57a2c3
1746017450
languageName: node
1746117451
linkType: hard
1746217452

0 commit comments

Comments
 (0)