From 2ac777045925b1ce475c0452c5618ae299cda7f9 Mon Sep 17 00:00:00 2001 From: "Juan Picado @jotadeveloper" Date: Wed, 23 Oct 2019 20:49:36 +0200 Subject: [PATCH] fix: security vulnerability at readme in dompurify dep (#1532) Fix Cross-site Scripting (XSS) in @verdaccio/readme --- package.json | 14 +++++++------- yarn.lock | Bin 367245 -> 368070 bytes 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/package.json b/package.json index 4c1de55b8..b9fbcf07d 100644 --- a/package.json +++ b/package.json @@ -16,10 +16,10 @@ "verdaccio": "./bin/verdaccio" }, "dependencies": { - "@verdaccio/commons-api": "8.1.2", - "@verdaccio/local-storage": "8.1.2", - "@verdaccio/readme": "8.1.2", - "@verdaccio/streams": "8.1.2", + "@verdaccio/commons-api": "8.2.0", + "@verdaccio/local-storage": "8.2.0", + "@verdaccio/readme": "8.2.0", + "@verdaccio/streams": "8.2.0", "@verdaccio/ui-theme": "0.3.2", "JSONStream": "1.3.5", "async": "3.1.0", @@ -49,7 +49,7 @@ "request": "2.87.0", "semver": "6.3.0", "verdaccio-audit": "8.1.4", - "verdaccio-htpasswd": "8.1.2" + "verdaccio-htpasswd": "8.2.0" }, "devDependencies": { "@commitlint/cli": "8.2.0", @@ -88,8 +88,8 @@ "standard-version": "7.0.0", "supertest": "4.0.2", "typescript": "3.6.3", - "verdaccio-auth-memory": "8.1.2", - "verdaccio-memory": "8.1.2" + "verdaccio-auth-memory": "8.2.0", + "verdaccio-memory": "8.2.0" }, "keywords": [ "private", diff --git a/yarn.lock b/yarn.lock index 14837091af073479cb3ebb33f4d13183641ac34f..8cb2cc2f06ad1e5758e6d7d9ffe66ce0df01dc29 100644 GIT binary patch delta 2567 zcmY+GNvPz;8OQ1FX*-!rGQ3&dEV0S>ISe*Eev+!BDk;g}=~gf5eN}GU2`)E9*L4x;d5^ zuf#8w^s6f{L~@nlVug|=k+w%1wh-+ub~$@6z3 z=g;jw`6zuV@IoNni##RBk9AUHVgv<=Q6};L5KELGQvfjqzyyTN46_Ivxq)tkYu zz4#Afp`_riYUIaf#RE0+qqE{dIzsoKeDKKb_tTL}kF^s40hu8PLkgHBBTF_UDoM;R zh$s?+2m%Grg2BOWqK7)m=lL-mZ3wMS>e*#>vh1&6ro8RtRxJdf--NFU?F)czDn2@Y zE4;>DxPI$MkWSeMew&Hhxe*pecWxcsTUjn8ra7`XZ|PcO=6%ikh2UN`a^>;=K>c~1!#f}hV2jAIY#E9oD?An`QwSsbXTCaY57uR^*tQGhj-N-gym76`XeA8HO2(N^ zxgzq%;@Gc_TkD~N@_I>68#{tqD65TOUUH<}rjf}^MwQ%L?aca<5idf#$kb21$VQxt z!K@wm;(Mm;&hNd1kA-7?|K7D1gFmz*Kj6<^&pI@OheE`F2^1hfi4qj@FGER2W{4Cv zC2Sdh1_z(S9(L%YB&ojLO>%UwnWl`k%cdTi?&`3XBpz<``Y8!isxvO^Z)Mc(6$Zs} z0h;wfI@8X}Wu zNH{ZP$YjMdMMDOr687yw)a%`5(g&TC*KBmv+IW>0VNc{|h?T9?YTKB}g?7@C^Jh4iC~6gKmY)Pf@M*I zNv06aaJF}juC<%6%1=o3ex^S5`x$K z*umqT6AfY!Dl!p?R>*<`p+ylf5sytv6nRCE%}}%vJoCHQp`I8vwiz~V)UxYVuRLqk zA;++;%xiML(w`ZVnQl!m;``2KuGTt*{E(1R!`GWDrx3PEzo_Oil}%~AQK!4LQ+4Lu z3R8!{A`!VBXsg)G_*r)agH2wUEs5MUVF4d)?T`#M=g&fDOG?tEo zR^#jfB`Q7a%ERq?uHtq==#IJaQd{TpMoOrYB1irCcHCK7h23o8P;A>)XCUw`ystNJ zy#B^#v6DAGJNK{s=`i1a{P!1w_ucsU;9Wa@`?2SeBp_KqSP?NX7(?L($QFSjWd0ufS43taV1;lCinL!`IMn@#QS9tAF&(Cbrc|=Zx@hxcqjSFR_%vBD{T$Xz zAzR{Vwo_f;zTlP`SzI0@6E!(i$j#TJ-$;qh0)nA2Eh|t+W;$O-=K0_sYUE-Nb>lz( zrrg_)Pa_Ny3y1TVA`yl)02Eu{p+qrE(?XI7O^GoR1n=LEU2An4`qtOf!Ms+`>si0= zZRMVdz=|&o%1)v>tvZV>o1%1cH%kjfMjw@+&xWw!Ha6H^i`WDv_!wvHD sV|`Z*{&FXNBlwjUfBG!SPcuCNg8A#`ZUkR?@hhBvGtFG7%66i{>05(;TP@$_?an}_rU^Ycv72gb8sS*s5H~w`N-{b$j z|DE4NfBLKFtG}fF`t=Arq2ovXpWVpqXzBrfa{2qUYq6M1Y-eoEV{!hC_YR={-6Hk8 z|Lt#3_maVblhttdWsXKFV0A^u8W0Su3mT(iMbH$UF;rF15ekM1Is3(vsN`DZ(n23k z?KZ(mchQ;^EU#E7Wxz}tR=gTP)-Ey06nR(xNnUpH<5I5Y5xUzcv+gWca0W87a>lEw zQLch*qL^6c7dh5n-jCclf90FhXAW*W3pGkn_u!t`9yc}+EhvapblOlDgm{2?!fOoS zX%=c20h(x-!~XBzjNIxl2C-2hljzfkt?r6e)@_WJqM8w!xt%F0YpyU!R%o}W<|h+* zKF?HL9yPMov@1$nZn)0VGj}wZ4v@qSEDNgx)M%Za{qV=P{YaYnLfo`8#XNRamaPm) z>e<@ApP^z`+S44uERXQz2Y6KlP%sR@B8Fp;9{55Ozygl-n;#rRC03ZAxtHM*=@m1w zlBAl+<8CI=-GQP2s`Z__+wzNcq73bfwd^P6Q;)RRalgQo5>vIC)moDUr-+M94e66Y z!;|?z&glgt?)rapA}<|WO7Fk4j>JCobbI_KZsd#MVCp|7Qu;HU`JG7JxLmlsFA&f) z;Z%+2tR_GMaFA9p<^&qiyb1t^AyIg6_UOqiDK9Ii+gz<2gSRWKQ>K(o$^%i5x}#!R zKTS$G?X&`RjYKZL9QT@?wAf#l8biIZYLhJ7u$7LKmezFB1xTdb@vM_p)cmRc_Tj;u zxHVg>?Xls-;`9kPVd6m&VzG&%TeDakq5v%Pf1aa`E}e)U#p0=OVZER zYAdd~+BOC~hc8zgWNx;W3TL@WEvI26%?yg8p#U1$(<*3q}pWX|f_%B35hyKThp?A*z77cxL-*^5HO8H+&h3+0R zdy|o-u>wX4%X4}VL87Y)Ruus=tO^-UGgO@;Dgyr7Z-t`r5&*oePer<1XqSh1u*|GD zTOLWS)W~$R+eJa~(v?}!?QQ9C&8!+VdB-)x0_o+XNv$v}iIcRrLxMcWx>(9F65nfe z<;`o4Q=#+6sj$HXy9qy0brAXQe>Et(SGVEofx~bQnTA9M(BPpiAY!l#%^3^{;)gM< z5Caj6cplQ|?BV^Wq%{YvOom|;+ZNL#Yo~MFIh2^TYr9##=Q)|RBGi{d=yh$UpB(nJ zwPRZ4EYlj4d+RdqVYLf4<)8x)IQIuv;HkM9Ml z@4WC)m^s0I`upLVVfutV|E(APQ1d^&70USk{7d*YVE@g7Q3QnsD$n8|Q4C?(OSv_U z1ogoKq6bk^4GkgMziv`D@75RAaGmR$r9`W^|@MNp5BTOFuif<Fa%IjtGA(3AK^@jb8%_dYu&$jw{QRED zHUDTGdHsKg|Is?~@)hRb!~uh61qN$64q8@6fDt$*xE`v&08I@#4AC0e=T0)Ja=E@S zIY3i{u