From 3148a2628a57c39f83a687487a9797f47bba639c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 29 Apr 2024 23:28:58 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-EJS-6689533 --- package.json | 2 +- yarn.lock | 15 +++++++++++++-- 2 files changed, 14 insertions(+), 3 deletions(-) diff --git a/package.json b/package.json index cc9e9a26c..c4899bab9 100644 --- a/package.json +++ b/package.json @@ -38,7 +38,7 @@ "castv2-client": "^1.2.0", "chokidar": "^3.5.3", "discord-auto-rpc": "^1.0.17", - "ejs": "^3.1.9", + "ejs": "^3.1.10", "electron-fetch": "^1.9.1", "electron-log": "^4.4.8", "electron-notarize": "^1.2.2", diff --git a/yarn.lock b/yarn.lock index e0fc8aa89..15f414294 100644 --- a/yarn.lock +++ b/yarn.lock @@ -4152,7 +4152,7 @@ __metadata: castv2-client: ^1.2.0 chokidar: ^3.5.3 discord-auto-rpc: ^1.0.17 - ejs: ^3.1.9 + ejs: ^3.1.10 electron: "github:castlabs/electron-releases" electron-builder: ^23.6.0 electron-builder-notarize-pkg: ^1.2.0 @@ -5238,7 +5238,18 @@ __metadata: languageName: node linkType: hard -"ejs@npm:^3.1.7, ejs@npm:^3.1.9": +"ejs@npm:^3.1.10": + version: 3.1.10 + resolution: "ejs@npm:3.1.10" + dependencies: + jake: ^10.8.5 + bin: + ejs: bin/cli.js + checksum: ce90637e9c7538663ae023b8a7a380b2ef7cc4096de70be85abf5a3b9641912dde65353211d05e24d56b1f242d71185c6d00e02cb8860701d571786d92c71f05 + languageName: node + linkType: hard + +"ejs@npm:^3.1.7": version: 3.1.9 resolution: "ejs@npm:3.1.9" dependencies: