Skip to content

Commit 2e089af

Browse files
dependency: update dependency flat to 5.0.2 and yargs-unparser to 1.6.4 (#33048)
* chore(deps): update dependency flat to 5.0.2 and yargs-unparser to 1.6.4 * update changelog
1 parent 7b46b9b commit 2e089af

File tree

3 files changed

+40
-20
lines changed

3 files changed

+40
-20
lines changed

cli/CHANGELOG.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ _Released 12/2/2025 (PENDING)_
1111

1212
- Updated the error message shown when the `cy.prompt()` bundle is deleted while in use. Ensured that the Cloud bundles are written atomically to avoid concurrent downloads causing issues. Addressed in [#33034](https://github.com/cypress-io/cypress/pull/33034).
1313

14+
**Dependency Updates:**
15+
16+
- Upgraded `yargs-unparser` from `1.6.0` to `1.6.4` (which upgraded `flat` from `4.1.1` to `5.0.2`) to resolve [CVE-2020-36632](https://github.com/advisories/GHSA-52f5-9888-hmc6). Addressed [#27763](https://github.com/cypress-io/cypress/issues/27763).
17+
1418
## 15.7.0
1519

1620
_Released 11/19/2025_

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -284,7 +284,8 @@
284284
"browserify-sign": "4.2.2",
285285
"devtools-protocol": "0.0.1528500",
286286
"node-abi": "4.9.0",
287-
"vue-template-compiler": "2.6.12"
287+
"vue-template-compiler": "2.6.12",
288+
"yargs-unparser": "1.6.4"
288289
},
289290
"packageManager": "yarn@1.22.22+sha512.a6b2f7906b721bba3d67d4aff083df04dad64c399707841b7acf00f6b133b7ac24255f2652fa22ae3534329dc6180534e98d17432037ff6fd140556e2bb3137e"
290291
}

yarn.lock

Lines changed: 34 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -17703,13 +17703,6 @@ flat-cache@^4.0.0:
1770317703
flatted "^3.2.9"
1770417704
keyv "^4.5.4"
1770517705

17706-
flat@^4.1.0:
17707-
version "4.1.1"
17708-
resolved "https://registry.yarnpkg.com/flat/-/flat-4.1.1.tgz#a392059cc382881ff98642f5da4dde0a959f309b"
17709-
integrity sha512-FmTtBsHskrU6FJ2VxCnsDb84wu9zhmO3cUX2kGFb5tuwhfXxGciiT0oRY+cck35QmG+NmGh5eLz6lLCpWTqwpA==
17710-
dependencies:
17711-
is-buffer "~2.0.3"
17712-
1771317706
flat@^5.0.2:
1771417707
version "5.0.2"
1771517708
resolved "https://registry.yarnpkg.com/flat/-/flat-5.0.2.tgz#8ca6fe332069ffa9d324c327198c598259ceb241"
@@ -20215,11 +20208,6 @@ is-buffer@^1.1.5, is-buffer@~1.1.6:
2021520208
resolved "https://registry.yarnpkg.com/is-buffer/-/is-buffer-1.1.6.tgz#efaa2ea9daa0d7ab2ea13a97b2b8ad51fefbe8be"
2021620209
integrity sha512-NcdALwpXkTm5Zvvbk7owOUSvVvBKDgKP5/ewfXEznmQFfs4ZRmanOeKBTjRVjka3QFoN6XJ+9F3USqfHqTaU5w==
2021720210

20218-
is-buffer@~2.0.3:
20219-
version "2.0.5"
20220-
resolved "https://registry.yarnpkg.com/is-buffer/-/is-buffer-2.0.5.tgz#ebc252e400d22ff8d77fa09888821a24a658c191"
20221-
integrity sha512-i2R6zNFDwgEHJyQUtJEk0XFi1i0dPFn/oqjK3/vPCcDeJvW5NQ83V8QbicfF1SupOaB0h8ntgBC2YiE7dfyctQ==
20222-
2022320211
is-bun-module@^2.0.0:
2022420212
version "2.0.0"
2022520213
resolved "https://registry.yarnpkg.com/is-bun-module/-/is-bun-module-2.0.0.tgz#4d7859a87c0fcac950c95e666730e745eae8bddd"
@@ -34211,6 +34199,14 @@ yargs-parser@5.0.0-security.0:
3421134199
camelcase "^3.0.0"
3421234200
object.assign "^4.1.0"
3421334201

34202+
yargs-parser@^15.0.1:
34203+
version "15.0.3"
34204+
resolved "https://registry.yarnpkg.com/yargs-parser/-/yargs-parser-15.0.3.tgz#316e263d5febe8b38eef61ac092b33dfcc9b1115"
34205+
integrity sha512-/MVEVjTXy/cGAjdtQf8dW3V9b97bPN7rNn8ETj6BmAQL7ibC7O1Q9SPJbGjgh3SlwoBNXMzj/ZGIj8mBgl12YA==
34206+
dependencies:
34207+
camelcase "^5.0.0"
34208+
decamelize "^1.2.0"
34209+
3421434210
yargs-parser@^18.1.2:
3421534211
version "18.1.3"
3421634212
resolved "https://registry.yarnpkg.com/yargs-parser/-/yargs-parser-18.1.3.tgz#be68c4975c6b2abf469236b0c870362fab09a7b0"
@@ -34238,14 +34234,16 @@ yargs-parser@^9.0.2:
3423834234
dependencies:
3423934235
camelcase "^4.1.0"
3424034236

34241-
yargs-unparser@1.6.0:
34242-
version "1.6.0"
34243-
resolved "https://registry.yarnpkg.com/yargs-unparser/-/yargs-unparser-1.6.0.tgz#ef25c2c769ff6bd09e4b0f9d7c605fb27846ea9f"
34244-
integrity sha512-W9tKgmSn0DpSatfri0nx52Joq5hVXgeLiqR/5G0sZNDoLZFOr/xjBUDcShCOGNsBnEMNo1KAMBkTej1Hm62HTw==
34237+
yargs-unparser@1.6.0, yargs-unparser@1.6.4:
34238+
version "1.6.4"
34239+
resolved "https://registry.yarnpkg.com/yargs-unparser/-/yargs-unparser-1.6.4.tgz#38e62a38354bf8d24dc9c171cc4926526e71b7bf"
34240+
integrity sha512-QxEx9+qEr7jwVM4ngnk95+sKZ5QXm5gx0cL97LDby0SiC8HHoUK0LPBg475JwQcRCqIVfMD8SubCWp1dEgKuwQ==
3424534241
dependencies:
34246-
flat "^4.1.0"
34247-
lodash "^4.17.15"
34248-
yargs "^13.3.0"
34242+
camelcase "^5.3.1"
34243+
decamelize "^1.2.0"
34244+
flat "^5.0.2"
34245+
is-plain-obj "^1.1.0"
34246+
yargs "^14.2.3"
3424934247

3425034248
yargs@13.3.0:
3425134249
version "13.3.0"
@@ -34353,6 +34351,23 @@ yargs@^11.0.0:
3435334351
y18n "^3.2.1"
3435434352
yargs-parser "^9.0.2"
3435534353

34354+
yargs@^14.2.3:
34355+
version "14.2.3"
34356+
resolved "https://registry.yarnpkg.com/yargs/-/yargs-14.2.3.tgz#1a1c3edced1afb2a2fea33604bc6d1d8d688a414"
34357+
integrity sha512-ZbotRWhF+lkjijC/VhmOT9wSgyBQ7+zr13+YLkhfsSiTriYsMzkTUFP18pFhWwBeMa5gUc1MzbhrO6/VB7c9Xg==
34358+
dependencies:
34359+
cliui "^5.0.0"
34360+
decamelize "^1.2.0"
34361+
find-up "^3.0.0"
34362+
get-caller-file "^2.0.1"
34363+
require-directory "^2.1.1"
34364+
require-main-filename "^2.0.0"
34365+
set-blocking "^2.0.0"
34366+
string-width "^3.0.0"
34367+
which-module "^2.0.0"
34368+
y18n "^4.0.0"
34369+
yargs-parser "^15.0.1"
34370+
3435634371
yargs@^15.1.0, yargs@^15.3.1:
3435734372
version "15.4.1"
3435834373
resolved "https://registry.yarnpkg.com/yargs/-/yargs-15.4.1.tgz#0d87a16de01aee9d8bec2bfbf74f67851730f4f8"

0 commit comments

Comments
 (0)