From 2a717b3800eedc308d5c18aee1e1e381e8d6f14f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 4 Jul 2022 10:45:33 +0200 Subject: [PATCH] fix(security): patch semantic-release dependency vulnerability (#969) chore(deps-dev): bump semantic-release from 19.0.2 to 19.0.3 Bumps [semantic-release](https://github.com/semantic-release/semantic-release) from 19.0.2 to 19.0.3. - [Release notes](https://github.com/semantic-release/semantic-release/releases) - [Commits](https://github.com/semantic-release/semantic-release/compare/v19.0.2...v19.0.3) --- updated-dependencies: - dependency-name: semantic-release dependency-type: direct:development ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package.json | 2 +- yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index b1a21b17b..459e67bee 100644 --- a/package.json +++ b/package.json @@ -64,7 +64,7 @@ "mysql2": "2.1.0", "onchange": "6.0.0", "pg": "8.4.2", - "semantic-release": "19.0.2", + "semantic-release": "19.0.3", "semantic-release-npm-deprecate-old-versions": "1.3.2", "semantic-release-slack-bot": "3.5.2", "sequelize": "5.21.3", diff --git a/yarn.lock b/yarn.lock index 49905b2d0..654767bce 100644 --- a/yarn.lock +++ b/yarn.lock @@ -8951,10 +8951,10 @@ semantic-release-slack-bot@3.5.2: node-fetch "^2.3.0" slackify-markdown "^4.3.0" -semantic-release@19.0.2: - version "19.0.2" - resolved "https://registry.yarnpkg.com/semantic-release/-/semantic-release-19.0.2.tgz#6011683c06d7b416e5faa5a3f43b22bbf3798aa8" - integrity sha512-7tPonjZxukKECmClhsfyMKDt0GR38feIC2HxgyYaBi+9tDySBLjK/zYDLhh+m6yjnHIJa9eBTKYE7k63ZQcYbw== +semantic-release@19.0.3: + version "19.0.3" + resolved "https://registry.yarnpkg.com/semantic-release/-/semantic-release-19.0.3.tgz#9291053ad9890052f28e7c5921d4741530d516fd" + integrity sha512-HaFbydST1cDKZHuFZxB8DTrBLJVK/AnDExpK0s3EqLIAAUAHUgnd+VSJCUtTYQKkAkauL8G9CucODrVCc7BuAA== dependencies: "@semantic-release/commit-analyzer" "^9.0.2" "@semantic-release/error" "^3.0.0"