0
Fork 0
mirror of https://github.com/verdaccio/verdaccio.git synced 2025-03-11 02:15:57 -05:00

chore: fix security vulnerabilities

This commit is contained in:
Juan Picado @jotadeveloper 2019-02-24 11:54:45 +01:00
parent 5566924edd
commit e46697a33b
No known key found for this signature in database
GPG key ID: 18AC54485952D158
2 changed files with 19 additions and 26 deletions

View file

@ -29,7 +29,7 @@
"date-fns": "1.30.1",
"express": "4.16.4",
"global": "4.3.2",
"handlebars": "4.0.12",
"handlebars": "4.0.13",
"http-errors": "1.7.1",
"js-base64": "2.5.1",
"js-string-escape": "1.0.1",
@ -47,7 +47,7 @@
"request": "2.88.0",
"semver": "5.6.0",
"verdaccio-audit": "1.1.0",
"verdaccio-htpasswd": "2.0.0-beta.0",
"verdaccio-htpasswd": "2.0.0-beta.1",
"verror": "1.10.0"
},
"devDependencies": {

View file

@ -1222,14 +1222,6 @@
babel-plugin-emotion "9.2.10"
babel-plugin-flow-runtime "0.18.0"
"@verdaccio/file-locking@0.0.7":
version "0.0.7"
resolved "https://registry.verdaccio.org/@verdaccio%2ffile-locking/-/file-locking-0.0.7.tgz#5fd1b2bd391e54fa32d079002b5f7ba90844e344"
integrity sha512-yTecDiJrYJMNnsPA4Nminygc/bPRf2HB6Pj/o/IS8scljYvV++LRXuglefM1I7p18qs3mcgX/bofCZM4x2SOJA==
dependencies:
lockfile "1.0.3"
lodash "4.17.10"
"@verdaccio/file-locking@1.0.0":
version "1.0.0"
resolved "https://registry.verdaccio.org/@verdaccio%2ffile-locking/-/file-locking-1.0.0.tgz#2f148612d9ce5c3c0dfd826151561b2aa887777d"
@ -5749,7 +5741,18 @@ handle-thing@^2.0.0:
resolved "https://registry.verdaccio.org/handle-thing/-/handle-thing-2.0.0.tgz#0e039695ff50c93fc288557d696f3c1dc6776754"
integrity sha512-d4sze1JNC454Wdo2fkuyzCr6aHcbL6PGGuFAz0Li/NcOm1tCHGnWDRmJP85dh9IhQErTc2svWFEX5xHIOo//kQ==
handlebars@4.0.12, handlebars@^4.0.2, handlebars@^4.0.3:
handlebars@4.0.13:
version "4.0.13"
resolved "https://registry.verdaccio.org/handlebars/-/handlebars-4.0.13.tgz#89fc17bf26f46fd7f6f99d341d92efaae64f997d"
integrity sha512-uydY0jy4Z3wy/iGXsi64UtLD4t1fFJe16c/NFxsYE4WdQis8ZCzOXUZaPQNG0e5bgtLQV41QTfqBindhEjnpyQ==
dependencies:
async "^2.5.0"
optimist "^0.6.1"
source-map "^0.6.1"
optionalDependencies:
uglify-js "^3.1.4"
handlebars@^4.0.2, handlebars@^4.0.3:
version "4.0.12"
resolved "https://registry.verdaccio.org/handlebars/-/handlebars-4.0.12.tgz#2c15c8a96d46da5e266700518ba8cb8d919d5bc5"
integrity sha512-RhmTekP+FZL+XNhwS1Wf+bTTZpdLougwt5pcgA1tuz6Jcx0fpH/7z0qd71RKnZHBCxIRBHfBOnio4gViPemNzA==
@ -7704,11 +7707,6 @@ locate-path@^3.0.0:
p-locate "^3.0.0"
path-exists "^3.0.0"
lockfile@1.0.3:
version "1.0.3"
resolved "https://registry.verdaccio.org/lockfile/-/lockfile-1.0.3.tgz#2638fc39a0331e9cac1a04b71799931c9c50df79"
integrity sha1-Jjj8OaAzHpysGgS3F5mTHJxQ33k=
lockfile@1.0.4:
version "1.0.4"
resolved "https://registry.verdaccio.org/lockfile/-/lockfile-1.0.4.tgz#07f819d25ae48f87e538e6578b6964a4981a5609"
@ -7924,11 +7922,6 @@ lodash.uniq@^4.5.0:
resolved "https://registry.verdaccio.org/lodash.uniq/-/lodash.uniq-4.5.0.tgz#d0225373aeb652adc1bc82e4945339a842754773"
integrity sha1-0CJTc662Uq3BvILklFM5qEJ1R3M=
lodash@4.17.10:
version "4.17.10"
resolved "https://registry.verdaccio.org/lodash/-/lodash-4.17.10.tgz#1b7793cf7259ea38fb3661d4d38b3260af8ae4e7"
integrity sha512-UejweD1pDoXu+AD825lWwp4ZGtSwgnpZxb3JDViD7StjQz+Nb/6l093lx4OQ0foGWNRoc19mWy7BzL+UAK2iVg==
lodash@4.17.11, lodash@^4.0.0, lodash@^4.13.1, lodash@^4.15.0, lodash@^4.17.10, lodash@^4.17.11, lodash@^4.17.3, lodash@^4.17.4, lodash@^4.17.5, lodash@^4.2.1, lodash@~4.17.10:
version "4.17.11"
resolved "https://registry.verdaccio.org/lodash/-/lodash-4.17.11.tgz#b39ea6229ef607ecd89e2c8df12536891cac9b8d"
@ -12897,12 +12890,12 @@ verdaccio-auth-memory@0.0.4:
resolved "https://registry.verdaccio.org/verdaccio-auth-memory/-/verdaccio-auth-memory-0.0.4.tgz#b44a65209778a8dc3c8d39478141a0bc22e04375"
integrity sha512-0k/RHK1XNmrPiuIbVHMo0I2ggYEwOqNUobgUQlVCTDSoUPS8jxL3MNdcCI2lPfY79G9NzsOKuVwWCXHbIWtH7A==
verdaccio-htpasswd@2.0.0-beta.0:
version "2.0.0-beta.0"
resolved "https://registry.verdaccio.org/verdaccio-htpasswd/-/verdaccio-htpasswd-2.0.0-beta.0.tgz#c15ddbc0f21a7237b65fcb5be59ab64589d72440"
integrity sha512-5JGuQaWQxhVRuzOgVjGpedf9gtmXpNZkLGV9XZeauNR16bPzzbxu6xFGw7RMstXmnaAb4yL03K2Cb+kzAChvQg==
verdaccio-htpasswd@2.0.0-beta.1:
version "2.0.0-beta.1"
resolved "https://registry.verdaccio.org/verdaccio-htpasswd/-/verdaccio-htpasswd-2.0.0-beta.1.tgz#26a4b5900a9d4048993ed5fccb3334c6bfca77c4"
integrity sha512-UipSN6NJLkgl3EWYBFA2cgv6q6lgnZMJECJFEaJEDoNnms18Eqfewy/EKtOfycT0u9EZILuOIjwnjfMoYjVXhA==
dependencies:
"@verdaccio/file-locking" "0.0.7"
"@verdaccio/file-locking" "1.0.0"
apache-md5 "1.1.2"
bcryptjs "2.4.3"
http-errors "1.7.1"