Commit c3801a9
committed
fix: resolve npm audit vulnerabilities via overrides
Add npm overrides to force mocha's transitive dependencies to patched
versions:
- diff ^7.0.0 -> ^8.0.3 (fixes GHSA-73rr-hh4g-fpgx DoS)
- serialize-javascript ^6.0.2 -> ^7.0.5 (fixes GHSA-5c6j-r48x-rmvq
RCE, GHSA-qj8w-gfj5-8c6v DoS)
npm audit now reports 0 vulnerabilities. All 162 tests pass.
Closes #37
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>1 parent 903dfe0 commit c3801a9
2 files changed
Lines changed: 14 additions & 19 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
130 | 130 | | |
131 | 131 | | |
132 | 132 | | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
133 | 139 | | |
134 | 140 | | |
135 | 141 | | |
| |||
0 commit comments