From bd15433c09ad9d0f01c4b2d1986e802853013c18 Mon Sep 17 00:00:00 2001 From: Tommy Markley Date: Wed, 23 Mar 2022 16:09:38 -0500 Subject: [PATCH] Bumps `node-forge` from v1.2.1 to v1.3.0 (#1369) * Addresses CVEs: CVE-2022-24771, CVE-2022-24772, CVE-2022-24773 * [CHANGELOG](https://github.com/digitalbazaar/forge/blob/v1.3.0/CHANGELOG.md) Resolves #1365 Resolves #1366 Resolves #1367 Signed-off-by: Tommy Markley --- package.json | 4 ++-- yarn.lock | 16 ++++++++-------- 2 files changed, 10 insertions(+), 10 deletions(-) diff --git a/package.json b/package.json index 6b8c7a6a4fd5..f59f44cc0c98 100644 --- a/package.json +++ b/package.json @@ -177,7 +177,7 @@ "moment-timezone": "^0.5.27", "mustache": "^2.3.2", "node-fetch": "^2.6.7", - "node-forge": "^1.2.1", + "node-forge": "^1.3.0", "p-map": "^4.0.0", "pegjs": "0.10.0", "proxy-from-env": "1.0.0", @@ -287,7 +287,7 @@ "@types/moment-timezone": "^0.5.12", "@types/mustache": "^0.8.31", "@types/node": "^14.17.32", - "@types/node-forge": "^1.0.0", + "@types/node-forge": "^1.0.1", "@types/normalize-path": "^3.0.0", "@types/pegjs": "^0.10.1", "@types/pngjs": "^3.4.0", diff --git a/yarn.lock b/yarn.lock index 25209c226dde..7d2b37e0ce4f 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3170,10 +3170,10 @@ dependencies: "@types/node" "*" -"@types/node-forge@^1.0.0": - version "1.0.0" - resolved "https://registry.yarnpkg.com/@types/node-forge/-/node-forge-1.0.0.tgz#0b4e9507209485945115a4db4879f39632230593" - integrity sha512-h0bgwPKq5u99T9Gor4qtV1lCZ41xNkai0pie1n/a2mh2/4+jENWOlo7AJ4YKxTZAnSZ8FRurUpdIN7ohaPPuHA== +"@types/node-forge@^1.0.1": + version "1.0.1" + resolved "https://registry.yarnpkg.com/@types/node-forge/-/node-forge-1.0.1.tgz#0df103639da9d5ec6a708d462020f0df70679f37" + integrity sha512-96ELNKv9tQJ19afdBUiM5iDw7OYEc53iUc51gAPR2aGaqRsO1DBROjqgZRjZa1tkPj7TnEOR0EnyAX6iryGkzA== dependencies: "@types/node" "*" @@ -13745,10 +13745,10 @@ node-fetch@^2.3.0, node-fetch@^2.6.1, node-fetch@^2.6.7: dependencies: whatwg-url "^5.0.0" -node-forge@^1.2.0, node-forge@^1.2.1: - version "1.2.1" - resolved "https://registry.yarnpkg.com/node-forge/-/node-forge-1.2.1.tgz#82794919071ef2eb5c509293325cec8afd0fd53c" - integrity sha512-Fcvtbb+zBcZXbTTVwqGA5W+MKBj56UjVRevvchv5XrcyXbmNdesfZL37nlcWOfpgHhgmxApw3tQbTr4CqNmX4w== +node-forge@^1.2.0, node-forge@^1.2.1, node-forge@^1.3.0: + version "1.3.0" + resolved "https://registry.yarnpkg.com/node-forge/-/node-forge-1.3.0.tgz#37a874ea723855f37db091e6c186e5b67a01d4b2" + integrity sha512-08ARB91bUi6zNKzVmaj3QO7cr397uiDT2nJ63cHjyNtCTWIgvS47j3eT0WfzUwS9+6Z5YshRaoasFkXCKrIYbA== node-gyp-build@^4.2.3: version "4.2.3"