Skip to content

Commit b079439

Browse files
Andrei Banshchikovmeta-codesync[bot]
authored andcommitted
Upgrading serialize-javascript package in QuickLayout Docs
Summary: Received an alert on a vulnerability in serialize-javascript package, upgraded to latest patched version (7.0.5, major bump from 6.0.2). Forces all transitive consumers via yarn `resolutions`. Mirrors D101617088 approach. Differential Revision: D102589513 fbshipit-source-id: 37a767182dd220116613ddd4b5fceb5e0904126e
1 parent 978452a commit b079439

2 files changed

Lines changed: 7 additions & 15 deletions

File tree

Sources/QuickLayout/docs/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,7 @@
5757
"express/path-to-regexp": "0.1.13",
5858
"lodash": "4.18.1",
5959
"lodash-es": "4.18.1",
60-
"picomatch": "2.3.2"
60+
"picomatch": "2.3.2",
61+
"serialize-javascript": "7.0.5"
6162
}
6263
}

Sources/QuickLayout/docs/yarn.lock

Lines changed: 5 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -9710,13 +9710,6 @@ quick-lru@^5.1.1:
97109710
resolved "https://registry.yarnpkg.com/quick-lru/-/quick-lru-5.1.1.tgz#366493e6b3e42a3a6885e2e99d18f80fb7a8c932"
97119711
integrity sha512-WuyALRjWPDGtt/wzJiadO5AXY+8hZ80hVpe6MyivgraREW751X3SbhRvG3eLKOYN+8VEvqLcf3wdnt44Z4S4SA==
97129712

9713-
randombytes@^2.1.0:
9714-
version "2.1.0"
9715-
resolved "https://registry.yarnpkg.com/randombytes/-/randombytes-2.1.0.tgz#df6f84372f0270dc65cdf6291349ab7a473d4f2a"
9716-
integrity sha512-vYl3iOX+4CKUWuxGi9Ukhie6fsqXqS9FE2Zaic4tNFD2N2QQaXOMFbuKK4QmDHC0JO6B1Zp41J0LpT0oR68amQ==
9717-
dependencies:
9718-
safe-buffer "^5.1.0"
9719-
97209713
range-parser@1.2.0:
97219714
version "1.2.0"
97229715
resolved "https://registry.yarnpkg.com/range-parser/-/range-parser-1.2.0.tgz#f49be6b487894ddc40dcc94a322f611092e00d5e"
@@ -10312,7 +10305,7 @@ sade@^1.7.3:
1031210305
dependencies:
1031310306
mri "^1.1.0"
1031410307

10315-
safe-buffer@5.2.1, safe-buffer@>=5.1.0, safe-buffer@^5.1.0, safe-buffer@~5.2.0:
10308+
safe-buffer@5.2.1, safe-buffer@>=5.1.0, safe-buffer@~5.2.0:
1031610309
version "5.2.1"
1031710310
resolved "https://registry.yarnpkg.com/safe-buffer/-/safe-buffer-5.2.1.tgz#1eaf9fa9bdb1fdd4ec75f58f9cdb4e6b7827eec6"
1031810311
integrity sha512-rp3So07KcdmmKbGvgaNxQSJr7bGVSVk5S9Eq1F+ppbRo70+YeaDxkw5Dd8NPN+GD6bjnYm2VuPuCXmpuYvmCXQ==
@@ -10429,12 +10422,10 @@ send@~0.19.0, send@~0.19.1:
1042910422
range-parser "~1.2.1"
1043010423
statuses "~2.0.2"
1043110424

10432-
serialize-javascript@^6.0.0, serialize-javascript@^6.0.1:
10433-
version "6.0.2"
10434-
resolved "https://registry.yarnpkg.com/serialize-javascript/-/serialize-javascript-6.0.2.tgz#defa1e055c83bf6d59ea805d8da862254eb6a6c2"
10435-
integrity sha512-Saa1xPByTTq2gdeFZYLLo+RFE35NHZkAbqZeWNd3BpzppeVisAqpDjcp8dyf6uIvEqJRd46jemmyA4iFIeVk8g==
10436-
dependencies:
10437-
randombytes "^2.1.0"
10425+
serialize-javascript@7.0.5, serialize-javascript@^6.0.0, serialize-javascript@^6.0.1:
10426+
version "7.0.5"
10427+
resolved "https://registry.yarnpkg.com/serialize-javascript/-/serialize-javascript-7.0.5.tgz#c798cc0552ffbb08981914a42a8756e339d0d5b1"
10428+
integrity sha512-F4LcB0UqUl1zErq+1nYEEzSHJnIwb3AF2XWB94b+afhrekOUijwooAYqFyRbjYkm2PAKBabx6oYv/xDxNi8IBw==
1043810429

1043910430
serve-handler@^6.1.6:
1044010431
version "6.1.7"

0 commit comments

Comments
 (0)