fix: package.json & yarn.lock to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-DOTPROP-543489
This commit is contained in:
2020-02-01 01:03:51 +00:00
parent 7f62282728
commit 52fb03c01b
2 changed files with 84 additions and 57 deletions
+1 -1
View File
@@ -28,7 +28,7 @@
"nuxt": "^2.8.1",
"nuxt-i18n": "^6.0.1",
"sass-loader": "^7.0.3",
"snyk": "^1.258.2",
"snyk": "^1.290.1",
"vue": "^2.6.10",
"vue-numeral-filter": "^1.1.1",
"vuetify": "^2.1.9"
+83 -56
View File
@@ -1391,6 +1391,13 @@
dependencies:
tslib "^1.9.3"
"@snyk/cli-interface@2.3.1":
version "2.3.1"
resolved "https://registry.yarnpkg.com/@snyk/cli-interface/-/cli-interface-2.3.1.tgz#73f2f4bd717b9f03f096ede3ff5830eb8d2f3716"
integrity sha512-JZvsmhDXSyjv1dkc12lPI3tNTNYlIaOiIQMYFg2RgqF3QmWjTyBUgRZcF7LoKyufHtS4dIudM6k1aHBpSaDrhw==
dependencies:
tslib "^1.9.3"
"@snyk/cocoapods-lockfile-parser@3.0.0":
version "3.0.0"
resolved "https://registry.yarnpkg.com/@snyk/cocoapods-lockfile-parser/-/cocoapods-lockfile-parser-3.0.0.tgz#514b744cedd9d3d3efb2a5d06fce1662fec2ff1a"
@@ -1411,6 +1418,18 @@
dependencies:
lodash "^4.17.13"
"@snyk/configstore@3.2.0-rc1", "@snyk/configstore@^3.2.0-rc1":
version "3.2.0-rc1"
resolved "https://registry.yarnpkg.com/@snyk/configstore/-/configstore-3.2.0-rc1.tgz#385c050d11926a26d0335a4b3be9e55f90f6e0ac"
integrity sha512-CV3QggFY8BY3u8PdSSlUGLibqbqCG1zJRmGM2DhnhcxQDRRPTGTP//l7vJphOVsUP1Oe23+UQsj7KRWpRUZiqg==
dependencies:
dot-prop "^5.2.0"
graceful-fs "^4.1.2"
make-dir "^1.0.0"
unique-string "^1.0.0"
write-file-atomic "^2.0.0"
xdg-basedir "^3.0.0"
"@snyk/dep-graph@1.13.1":
version "1.13.1"
resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.13.1.tgz#45721f7e21136b62d1cdd99b3319e717d9071dfb"
@@ -1458,6 +1477,22 @@
source-map-support "^0.5.7"
tslib "^1.9.3"
"@snyk/update-notifier@^2.5.1-rc1":
version "2.5.1-rc1"
resolved "https://registry.yarnpkg.com/@snyk/update-notifier/-/update-notifier-2.5.1-rc1.tgz#a014669bcd555f71916e06fdba2afe04b1801035"
integrity sha512-cIK+dMUsXBl4K9AKg5EYhdxWts0tAUvyu1WePse+tjzX4E9poME/wojkDrWQl1/SKLlhA559ftiOODmVa1adCg==
dependencies:
"@snyk/configstore" "3.2.0-rc1"
boxen "^1.2.1"
chalk "^2.0.1"
import-lazy "^2.1.0"
is-ci "^1.0.10"
is-installed-globally "^0.1.0"
is-npm "^1.0.0"
latest-version "^3.0.0"
semver-diff "^2.0.0"
xdg-basedir "^3.0.0"
"@types/agent-base@^4.2.0":
version "4.2.0"
resolved "https://registry.yarnpkg.com/@types/agent-base/-/agent-base-4.2.0.tgz#00644e8b395b40e1bf50aaf1d22cabc1200d5051"
@@ -3545,18 +3580,6 @@ concat-stream@1.6.2, concat-stream@^1.5.0:
readable-stream "^2.2.2"
typedarray "^0.0.6"
configstore@^3.0.0, configstore@^3.1.2:
version "3.1.2"
resolved "https://registry.yarnpkg.com/configstore/-/configstore-3.1.2.tgz#c6f25defaeef26df12dd33414b001fe81a543f8f"
integrity sha512-vtv5HtGjcYUgFrXc6Kx747B83MRRVS5R1VTEQoXvuP+kMI+if6uywV0nDGoiydJRy4yk7h9od5Og0kxx4zUXmw==
dependencies:
dot-prop "^4.1.0"
graceful-fs "^4.1.2"
make-dir "^1.0.0"
unique-string "^1.0.0"
write-file-atomic "^2.0.0"
xdg-basedir "^3.0.0"
confusing-browser-globals@^1.0.7:
version "1.0.9"
resolved "https://registry.yarnpkg.com/confusing-browser-globals/-/confusing-browser-globals-1.0.9.tgz#72bc13b483c0276801681871d4898516f8f54fdd"
@@ -4227,10 +4250,10 @@ dimport@^1.0.0:
dependencies:
rewrite-imports "^2.0.3"
dockerfile-ast@0.0.16:
version "0.0.16"
resolved "https://registry.yarnpkg.com/dockerfile-ast/-/dockerfile-ast-0.0.16.tgz#10b329d343329dab1de70375833495f85ad65913"
integrity sha512-+HZToHjjiLPl46TqBrok5dMrg5oCkZFPSROMQjRmvin0zG4FxK0DJXTpV/CUPYY2zpmEvVza55XLwSHFx/xZMw==
dockerfile-ast@0.0.18:
version "0.0.18"
resolved "https://registry.yarnpkg.com/dockerfile-ast/-/dockerfile-ast-0.0.18.tgz#94a0ba84eb9b3e9fb7bd6beae0ea7eb6dcbca75a"
integrity sha512-SEp95qCox1KAzf8BBtjHoBDD0a7/eNlZJ6fgDf9RxqeSEDwLuEN9YjdZ/tRlkrYLxXR4i+kqZzS4eDRSqs8VKQ==
dependencies:
vscode-languageserver-types "^3.5.0"
@@ -4309,13 +4332,20 @@ dot-case@^2.1.0:
dependencies:
no-case "^2.2.0"
dot-prop@^4.1.0, dot-prop@^4.1.1:
dot-prop@^4.1.1:
version "4.2.0"
resolved "https://registry.yarnpkg.com/dot-prop/-/dot-prop-4.2.0.tgz#1f19e0c2e1aa0e32797c49799f2837ac6af69c57"
integrity sha512-tUMXrxlExSW6U2EXiiKGSBVdYgtV8qlHL+C10TsW4PURY/ic+eaysnSkwB4kA/mBlCyy/IKDJ+Lc3wbWeaXtuQ==
dependencies:
is-obj "^1.0.0"
dot-prop@^5.2.0:
version "5.2.0"
resolved "https://registry.yarnpkg.com/dot-prop/-/dot-prop-5.2.0.tgz#c34ecc29556dc45f1f4c22697b6f4904e0cc4fcb"
integrity sha512-uEUyaDKoSQ1M4Oq8l45hSE26SnTxL6snNnqvK/VWx5wJhmff5z0FUVJDKDanor/6w3kzE3i7XZOk+7wC0EXr1A==
dependencies:
is-obj "^2.0.0"
dotenv@^8.0.0:
version "8.2.0"
resolved "https://registry.yarnpkg.com/dotenv/-/dotenv-8.2.0.tgz#97e619259ada750eea3e4ea3e26bceea5424b16a"
@@ -4743,6 +4773,13 @@ etag@^1.8.1, etag@~1.8.1:
resolved "https://registry.yarnpkg.com/etag/-/etag-1.8.1.tgz#41ae2eeb65efa62268aebfea83ac7d79299b0887"
integrity sha1-Qa4u62XvpiJorr/qg6x9eSmbCIc=
event-loop-spinner@^1.1.0:
version "1.1.0"
resolved "https://registry.yarnpkg.com/event-loop-spinner/-/event-loop-spinner-1.1.0.tgz#96de9c70e6e2b0b3e257b0901e25e792e3c9c8d0"
integrity sha512-YVFs6dPpZIgH665kKckDktEVvSBccSYJmoZUfhNUdv5d3Xv+Q+SKF4Xis1jolq9aBzuW1ZZhQh/m/zU/TPdDhw==
dependencies:
tslib "^1.10.0"
eventemitter2@4.1.2:
version "4.1.2"
resolved "https://registry.yarnpkg.com/eventemitter2/-/eventemitter2-4.1.2.tgz#0e1a8477af821a6ef3995b311bf74c23a5247f15"
@@ -6342,6 +6379,11 @@ is-obj@^1.0.0:
resolved "https://registry.yarnpkg.com/is-obj/-/is-obj-1.0.1.tgz#3e4729ac1f5fde025cd7d83a896dab9f4f67db0f"
integrity sha1-PkcprB9f3gJc19g6iW2rn09n2w8=
is-obj@^2.0.0:
version "2.0.0"
resolved "https://registry.yarnpkg.com/is-obj/-/is-obj-2.0.0.tgz#473fb05d973705e3fd9620545018ca8e22ef4982"
integrity sha512-drqDG3cbczxxEJRoOXcOjtdp1J/lyp1mNn0xaznRs8+muBhgQcrnbspox5X5fOw0HnMnbfDzvnEMEtqDEJEo8w==
is-observable@^1.1.0:
version "1.1.0"
resolved "https://registry.yarnpkg.com/is-observable/-/is-observable-1.1.0.tgz#b3e986c8f44de950867cab5403f5a3465005975e"
@@ -10085,13 +10127,14 @@ snyk-config@^2.2.1:
lodash "^4.17.15"
nconf "^0.10.0"
snyk-docker-plugin@1.33.1:
version "1.33.1"
resolved "https://registry.yarnpkg.com/snyk-docker-plugin/-/snyk-docker-plugin-1.33.1.tgz#9fe0acf9964ed3bc49721163ed88de32b212ed05"
integrity sha512-xfs3DN1tPMTh6J8x2341wGK4HRr+pI5+i/YRuRmsslnBnwk/DkKYcbt8zOIWk6kzMoW8vo+9LqqXBQO/24szKg==
snyk-docker-plugin@1.38.0:
version "1.38.0"
resolved "https://registry.yarnpkg.com/snyk-docker-plugin/-/snyk-docker-plugin-1.38.0.tgz#afe0ac316e461b200bcd0063295a3f8bd3655e93"
integrity sha512-43HbJj6QatuL2BNG+Uq2Taa73wdfSQSID8FJWW4q5/LYgd9D+RtdiE4lAMwxqYYbvThU9uuza4epuF/B1CAlYw==
dependencies:
debug "^4.1.1"
dockerfile-ast "0.0.16"
dockerfile-ast "0.0.18"
event-loop-spinner "^1.1.0"
semver "^6.1.0"
tar-stream "^2.1.0"
tslib "^1"
@@ -10135,12 +10178,12 @@ snyk-module@1.9.1, snyk-module@^1.6.0, snyk-module@^1.9.1:
debug "^3.1.0"
hosted-git-info "^2.7.1"
snyk-mvn-plugin@2.7.0:
version "2.7.0"
resolved "https://registry.yarnpkg.com/snyk-mvn-plugin/-/snyk-mvn-plugin-2.7.0.tgz#39996df2a878b16a7e3cbe5b63a7c43855031d49"
integrity sha512-DLBt+6ZvtoleXE7Si3wAa6gdPSWsXdIQEY6m2zW2InN9WiaRwIEKMCY822eFmRPZVNNmZNRUIeQsoHZwv/slqQ==
snyk-mvn-plugin@2.8.0:
version "2.8.0"
resolved "https://registry.yarnpkg.com/snyk-mvn-plugin/-/snyk-mvn-plugin-2.8.0.tgz#20c4201debd99928ade099fd426d13bd17b2cc85"
integrity sha512-Jt6lsVOFOYj7rp0H2IWz/BZS9xxaO0jEFTAoafLCocJIWWuGhPpVocCqmh/hrYAdKY9gS4gVOViMJ3EvcC1r1Q==
dependencies:
"@snyk/cli-interface" "2.2.0"
"@snyk/cli-interface" "2.3.1"
debug "^4.1.1"
lodash "^4.17.15"
needle "^2.4.0"
@@ -10204,10 +10247,10 @@ snyk-policy@1.13.5:
snyk-try-require "^1.3.1"
then-fs "^2.0.0"
snyk-python-plugin@1.16.0:
version "1.16.0"
resolved "https://registry.yarnpkg.com/snyk-python-plugin/-/snyk-python-plugin-1.16.0.tgz#0eae3c085a87b7d91f8097f598571104c01e0f08"
integrity sha512-IA53xOcy1s881tbIrIXNqIuCNozd4PAVWN8oF0xgRn2NQbq0e7EWt7kFPJbmZodpLCDpXaKKqV2MHbXruFIsrw==
snyk-python-plugin@1.17.0:
version "1.17.0"
resolved "https://registry.yarnpkg.com/snyk-python-plugin/-/snyk-python-plugin-1.17.0.tgz#9bc38ba3c799c3cbef7676a1081f52608690d254"
integrity sha512-EKdVOUlvhiVpXA5TeW8vyxYVqbITAfT+2AbL2ZRiiUNLP5ae+WiNYaPy7aB5HAS9IKBKih+IH8Ag65Xu1IYSYA==
dependencies:
"@snyk/cli-interface" "^2.0.3"
tmp "0.0.33"
@@ -10271,22 +10314,23 @@ snyk-try-require@1.3.1, snyk-try-require@^1.1.1, snyk-try-require@^1.3.1:
lru-cache "^4.0.0"
then-fs "^2.0.0"
snyk@^1.258.2:
version "1.279.1"
resolved "https://registry.yarnpkg.com/snyk/-/snyk-1.279.1.tgz#5665edcba8f6f7d5677df67bbaf8e329be0fb9e6"
integrity sha512-i2bpYgXgRYUCKKuVOjVha3P9tl4T7fXurF/IAwnyueaXRcoos8LHeka9larQArEAHkOGqHgq94ZFhkleo8lZiA==
snyk@^1.290.1:
version "1.290.1"
resolved "https://registry.yarnpkg.com/snyk/-/snyk-1.290.1.tgz#9705761ae03b4a41a2ee9d214c87e72e7d0c258a"
integrity sha512-8fB+b+trI5a6mU5cAKXOU2RG15xxr++4zYxkfNpkFkhbUqkcLsJtXD4H7Pcs6vXcOvoiEafyziPTpYurPFDXBQ==
dependencies:
"@snyk/cli-interface" "2.3.0"
"@snyk/configstore" "^3.2.0-rc1"
"@snyk/dep-graph" "1.13.1"
"@snyk/gemfile" "1.2.0"
"@snyk/snyk-cocoapods-plugin" "2.0.1"
"@snyk/update-notifier" "^2.5.1-rc1"
"@types/agent-base" "^4.2.0"
"@types/restify" "^4.3.6"
abbrev "^1.1.1"
ansi-escapes "3.2.0"
chalk "^2.4.2"
cli-spinner "0.2.10"
configstore "^3.1.2"
debug "^3.1.0"
diff "^4.0.1"
git-url-parse "11.1.2"
@@ -10300,16 +10344,16 @@ snyk@^1.258.2:
proxy-from-env "^1.0.0"
semver "^6.0.0"
snyk-config "^2.2.1"
snyk-docker-plugin "1.33.1"
snyk-docker-plugin "1.38.0"
snyk-go-plugin "1.11.1"
snyk-gradle-plugin "3.2.4"
snyk-module "1.9.1"
snyk-mvn-plugin "2.7.0"
snyk-mvn-plugin "2.8.0"
snyk-nodejs-lockfile-parser "1.17.0"
snyk-nuget-plugin "1.16.0"
snyk-php-plugin "1.7.0"
snyk-policy "1.13.5"
snyk-python-plugin "1.16.0"
snyk-python-plugin "1.17.0"
snyk-resolve "1.0.1"
snyk-resolve-deps "4.4.0"
snyk-sbt-plugin "2.11.0"
@@ -10319,7 +10363,6 @@ snyk@^1.258.2:
strip-ansi "^5.2.0"
tempfile "^2.0.0"
then-fs "^2.0.0"
update-notifier "^2.5.0"
uuid "^3.3.2"
wrap-ansi "^5.1.0"
@@ -11325,22 +11368,6 @@ upath@^1.1.1, upath@^1.2.0:
resolved "https://registry.yarnpkg.com/upath/-/upath-1.2.0.tgz#8f66dbcd55a883acdae4408af8b035a5044c1894"
integrity sha512-aZwGpamFO61g3OlfT7OQCHqhGnW43ieH9WZeP7QxN/G/jS4jfqUkZxoryvJgVPEcrl5NL/ggHsSmLMHuH64Lhg==
update-notifier@^2.5.0:
version "2.5.0"
resolved "https://registry.yarnpkg.com/update-notifier/-/update-notifier-2.5.0.tgz#d0744593e13f161e406acb1d9408b72cad08aff6"
integrity sha512-gwMdhgJHGuj/+wHJJs9e6PcCszpxR1b236igrOkUofGhqJuG+amlIKwApH1IW1WWl7ovZxsX49lMBWLxSdm5Dw==
dependencies:
boxen "^1.2.1"
chalk "^2.0.1"
configstore "^3.0.0"
import-lazy "^2.1.0"
is-ci "^1.0.10"
is-installed-globally "^0.1.0"
is-npm "^1.0.0"
latest-version "^3.0.0"
semver-diff "^2.0.0"
xdg-basedir "^3.0.0"
upper-case-first@^1.1.0, upper-case-first@^1.1.2:
version "1.1.2"
resolved "https://registry.yarnpkg.com/upper-case-first/-/upper-case-first-1.1.2.tgz#5d79bedcff14419518fd2edb0a0507c9b6859115"