From 6ac5878978cd85263980dd61ab4d23c808a26a67 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 20 Dec 2023 14:21:38 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-DOTTIE-3332763 - https://snyk.io/vuln/SNYK-JS-MOMENT-2944238 - https://snyk.io/vuln/SNYK-JS-SEMVER-3247795 - https://snyk.io/vuln/npm:debug:20170905 --- package-lock.json | 84 ++++++++++++++++++++++++++++++++--------------- package.json | 2 +- 2 files changed, 59 insertions(+), 27 deletions(-) diff --git a/package-lock.json b/package-lock.json index b5b2ae2..52c10b4 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1610,7 +1610,8 @@ "commander": { "version": "2.20.3", "resolved": "http://artifactory.eqs.intra/artifactory/api/npm/npm/commander/-/commander-2.20.3.tgz?dl=https://registry.npmjs.org/commander/-/commander-2.20.3.tgz", - "integrity": "sha1-/UhehMA+tIgcIHIrpIA16FMa6zM=" + "integrity": "sha1-/UhehMA+tIgcIHIrpIA16FMa6zM=", + "devOptional": true }, "component-emitter": { "version": "1.3.0", @@ -3651,7 +3652,11 @@ "resolved": "http://artifactory.eqs.intra/artifactory/api/npm/npm/fsevents/-/fsevents-1.2.13.tgz?dl=https://registry.npmjs.org/fsevents/-/fsevents-1.2.13.tgz", "integrity": "sha1-8yXLBFVZJCi88Rs4M3DvcOO/zDg=", "dev": true, - "optional": true + "optional": true, + "requires": { + "bindings": "^1.5.0", + "nan": "^2.12.1" + } }, "normalize-path": { "version": "2.1.1", @@ -4564,16 +4569,16 @@ } }, "moment": { - "version": "2.29.2", - "resolved": "https://registry.npmjs.org/moment/-/moment-2.29.2.tgz", - "integrity": "sha512-UgzG4rvxYpN15jgCmVJwac49h9ly9NurikMWGPdVxm8GZD6XjkKPxDTjQQ43gtGgnV3X0cAyWDdP2Wexoquifg==" + "version": "2.29.4", + "resolved": "https://registry.npmjs.org/moment/-/moment-2.29.4.tgz", + "integrity": "sha512-5LC9SOxjSc2HF6vO2CyuTDNivEdoz2IvyJJGj6X8DJ0eFyfszE0QiEd+iXmBvUP3WHxSjFH/vIsA0EN00cgr8w==" }, "moment-timezone": { - "version": "0.5.28", - "resolved": "http://artifactory.eqs.intra/artifactory/api/npm/npm/moment-timezone/-/moment-timezone-0.5.28.tgz?dl=https://registry.npmjs.org/moment-timezone/-/moment-timezone-0.5.28.tgz", - "integrity": "sha1-8JPXidCR7XsFXYKqgagkZ/cuQzg=", + "version": "0.5.43", + "resolved": "https://registry.npmjs.org/moment-timezone/-/moment-timezone-0.5.43.tgz", + "integrity": "sha512-72j3aNyuIsDxdF1i7CEgV2FfxM1r6aaqJyLB2vwb33mXYyoyLly+F1zbWqhA3/bVIoJ4szlUoMbUnVdid32NUQ==", "requires": { - "moment": ">= 2.9.0" + "moment": "^2.29.4" } }, "morgan": { @@ -5754,25 +5759,23 @@ "integrity": "sha1-1WgS4cAXpuTnw+Ojeh2m143TyT4=" }, "sequelize": { - "version": "5.22.3", - "resolved": "http://artifactory.eqs.intra/artifactory/api/npm/npm/sequelize/-/sequelize-5.22.3.tgz", - "integrity": "sha1-fnqS3dNV2IPJ6xHNsQbYdNDSY28=", + "version": "6.1.0", + "resolved": "https://registry.npmjs.org/sequelize/-/sequelize-6.1.0.tgz", + "integrity": "sha512-8x603RQrj14QZ4dGpsYPMr3YGqsihNX9WPclNN83prwrhHAJH9LHfOG/pK2XUdrwYtbRz+2a7xKXK7rVdw3P2A==", "requires": { - "bluebird": "^3.5.0", - "cls-bluebird": "^2.1.0", "debug": "^4.1.1", "dottie": "^2.0.0", "inflection": "1.12.0", "lodash": "^4.17.15", - "moment": "^2.24.0", - "moment-timezone": "^0.5.21", + "moment": "^2.26.0", + "moment-timezone": "^0.5.31", "retry-as-promised": "^3.2.0", - "semver": "^6.3.0", - "sequelize-pool": "^2.3.0", + "semver": "^7.3.2", + "sequelize-pool": "^6.0.0", "toposort-class": "^1.0.1", - "uuid": "^3.3.3", + "uuid": "^8.1.0", "validator": "^10.11.0", - "wkx": "^0.4.8" + "wkx": "^0.5.0" }, "dependencies": { "debug": { @@ -5783,6 +5786,14 @@ "ms": "^2.1.1" } }, + "lru-cache": { + "version": "6.0.0", + "resolved": "https://registry.npmjs.org/lru-cache/-/lru-cache-6.0.0.tgz", + "integrity": "sha512-Jo6dJ04CmSjuznwJSS3pUeWmd/H0ffTlkXXgwZi+eq1UCmqQwCh+eLsYOYCwY991i2Fah4h1BEMCx4qThGbsiA==", + "requires": { + "yallist": "^4.0.0" + } + }, "ms": { "version": "2.1.2", "resolved": "http://artifactory.eqs.intra/artifactory/api/npm/npm/ms/-/ms-2.1.2.tgz?dl=https://registry.npmjs.org/ms/-/ms-2.1.2.tgz", @@ -5797,9 +5808,30 @@ } }, "semver": { - "version": "6.3.0", - "resolved": "http://artifactory.eqs.intra/artifactory/api/npm/npm/semver/-/semver-6.3.0.tgz?dl=https://registry.npmjs.org/semver/-/semver-6.3.0.tgz", - "integrity": "sha1-7gpkyK9ejO6mdoexM3YeG+y9HT0=" + "version": "7.5.4", + "resolved": "https://registry.npmjs.org/semver/-/semver-7.5.4.tgz", + "integrity": "sha512-1bCSESV6Pv+i21Hvpxp3Dx+pSD8lIPt8uVjRrxAUt/nbswYc+tK6Y2btiULjd4+fnq15PX+nqQDC7Oft7WkwcA==", + "requires": { + "lru-cache": "^6.0.0" + } + }, + "uuid": { + "version": "8.3.2", + "resolved": "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz", + "integrity": "sha512-+NYs2QeMWy+GWFOEm9xnn6HCDp0l7QBD7ml8zLUmJ+93Q5NF0NocErnwkTkXVFNiX3/fpC6afS8Dhb/gz7R7eg==" + }, + "wkx": { + "version": "0.5.0", + "resolved": "https://registry.npmjs.org/wkx/-/wkx-0.5.0.tgz", + "integrity": "sha512-Xng/d4Ichh8uN4l0FToV/258EjMGU9MGcA0HV2d9B/ZpZB3lqQm7nkOdZdm5GhKtLLhAE7PiVQwN4eN+2YJJUg==", + "requires": { + "@types/node": "*" + } + }, + "yallist": { + "version": "4.0.0", + "resolved": "https://registry.npmjs.org/yallist/-/yallist-4.0.0.tgz", + "integrity": "sha512-3wdGidZyq5PB084XLES5TpOSRA3wjXAlIWMhum2kRcv/41Sn2emQ0dycQW4uZXLejwKvg6EsvbdlVL+FYEct7A==" } } }, @@ -5815,9 +5847,9 @@ } }, "sequelize-pool": { - "version": "2.3.0", - "resolved": "http://artifactory.eqs.intra/artifactory/api/npm/npm/sequelize-pool/-/sequelize-pool-2.3.0.tgz?dl=https://registry.npmjs.org/sequelize-pool/-/sequelize-pool-2.3.0.tgz", - "integrity": "sha1-ZPH+h0QigXLEdPUwYEthM75kmT0=" + "version": "6.1.0", + "resolved": "https://registry.npmjs.org/sequelize-pool/-/sequelize-pool-6.1.0.tgz", + "integrity": "sha512-4YwEw3ZgK/tY/so+GfnSgXkdwIJJ1I32uZJztIEgZeAO6HMgj64OzySbWLgxj+tXhZCJnzRfkY9gINw8Ft8ZMg==" }, "sequelize-typescript": { "version": "0.6.11", diff --git a/package.json b/package.json index 806f353..3e2f141 100644 --- a/package.json +++ b/package.json @@ -67,7 +67,7 @@ "passport-github2": "^0.1.11", "passport-local": "^1.0.0", "reflect-metadata": "^0.1.13", - "sequelize": "^5.22.3", + "sequelize": "^6.1.0", "sequelize-typescript": "^0.6.6-beta.1", "snyk": "^1.685.0", "swagger-jsdoc": "^4.0.0",