From 8e857dc563d77f04df60ed8d674b8cb7d977f416 Mon Sep 17 00:00:00 2001 From: Alex <33497058+bexsoft@users.noreply.github.com> Date: Mon, 18 Jul 2022 19:00:48 -0500 Subject: [PATCH] Updated security issue with glob-parent dependency (#2177) Signed-off-by: Benjamin Perez --- portal-ui/package.json | 7 ++++--- portal-ui/yarn.lock | 27 +++++++++------------------ 2 files changed, 13 insertions(+), 21 deletions(-) diff --git a/portal-ui/package.json b/portal-ui/package.json index bf4eb7f51..7db7fbe06 100644 --- a/portal-ui/package.json +++ b/portal-ui/package.json @@ -81,9 +81,10 @@ "resolutions": { "nth-check": "^2.0.1", "postcss": "^8.2.13", - "react-scripts/**/node-forge ": "^1.3.0", - "react-scripts/**/async ": "^2.6.4", + "react-scripts/**/node-forge": "^1.3.0", + "react-scripts/**/async": "^2.6.4", "react-scripts/workbox-webpack-plugin/workbox-build/@surma/rollup-plugin-off-main-thread/ejs/jake/async": "^2.6.4", - "react-scripts/webpack-dev-server/portfinder/async": "^2.6.4" + "react-scripts/webpack-dev-server/portfinder/async": "^2.6.4", + "react-scripts/**/glob-parent": "^6.0.1" } } diff --git a/portal-ui/yarn.lock b/portal-ui/yarn.lock index c068ce9bc..7c16036b5 100644 --- a/portal-ui/yarn.lock +++ b/portal-ui/yarn.lock @@ -3113,14 +3113,6 @@ ast-types-flow@^0.0.7: resolved "https://registry.yarnpkg.com/ast-types-flow/-/ast-types-flow-0.0.7.tgz#f70b735c6bca1a5c9c22d982c3e39e7feba3bdad" integrity sha512-eBvWn1lvIApYMhzQMsu9ciLfkBY499mFZlNqG+/9WR7PVlroQw0vG30cOQQbaKz3sCEc44TAOu2ykzqXSNnwag== -"async @^2.6.4", async@^2.6.4, async@^3.2.3: - name async - version "2.6.4" - resolved "https://registry.yarnpkg.com/async/-/async-2.6.4.tgz#706b7ff6084664cd7eae713f6f965433b5504221" - integrity sha512-mzo5dfJYwAn29PeiJ0zvwTo04zj8HDJj0Mn8TD7sno7q12prdbnasKJHhkm2c1LgrhlJ0teaea8860oxi51mGA== - dependencies: - lodash "^4.17.14" - async-exit-hook@^1.1.2: version "1.1.2" resolved "https://registry.yarnpkg.com/async-exit-hook/-/async-exit-hook-1.1.2.tgz#8095d75e488c29acee0551fe87252169d789cfba" @@ -3131,6 +3123,13 @@ async@3.2.3, async@^3.1.0: resolved "https://registry.yarnpkg.com/async/-/async-3.2.3.tgz#ac53dafd3f4720ee9e8a160628f18ea91df196c9" integrity sha512-spZRyzKL5l5BZQrr/6m/SqFdBN0q3OCI0f9rjfBzCMBIP4p75P620rR3gTmaksNOhmzgdxcaxdNfMy6anrbM0g== +async@^2.6.4, async@^3.2.3: + version "2.6.4" + resolved "https://registry.yarnpkg.com/async/-/async-2.6.4.tgz#706b7ff6084664cd7eae713f6f965433b5504221" + integrity sha512-mzo5dfJYwAn29PeiJ0zvwTo04zj8HDJj0Mn8TD7sno7q12prdbnasKJHhkm2c1LgrhlJ0teaea8860oxi51mGA== + dependencies: + lodash "^4.17.14" + asynckit@^0.4.0: version "0.4.0" resolved "https://registry.yarnpkg.com/asynckit/-/asynckit-0.4.0.tgz#c79ed97f7f34cb8f2ba1bc9790bcc366474b4b79" @@ -5846,14 +5845,7 @@ get-symbol-description@^1.0.0: call-bind "^1.0.2" get-intrinsic "^1.1.1" -glob-parent@^5.1.2, glob-parent@~5.1.2: - version "5.1.2" - resolved "https://registry.yarnpkg.com/glob-parent/-/glob-parent-5.1.2.tgz#869832c58034fe68a4093c17dc15e8340d8401c4" - integrity sha512-AOIgSQCepiJYwP3ARnGx+5VnTu2HBYdzbGP45eLw1vr3zB3vZLeyed1sC9hnbcOc9/SrMyM5RPQrkGz4aS9Zow== - dependencies: - is-glob "^4.0.1" - -glob-parent@^6.0.1, glob-parent@^6.0.2: +glob-parent@^5.1.2, glob-parent@^6.0.1, glob-parent@^6.0.2, glob-parent@~5.1.2: version "6.0.2" resolved "https://registry.yarnpkg.com/glob-parent/-/glob-parent-6.0.2.tgz#6d237d99083950c79290f24c7642a3de9a28f9e3" integrity sha512-XxwI8EOhVQgWp6iDL+3b0r86f4d6AX6zSU55HfB4ydCEuXLXc5FcYeOu+nnGftS4TEju/11rt4KJPTMgbfmv4A== @@ -8079,8 +8071,7 @@ node-fetch@^2.6.1: dependencies: whatwg-url "^5.0.0" -"node-forge @^1.3.0", node-forge@^1: - name node-forge +node-forge@^1, node-forge@^1.3.0: version "1.3.1" resolved "https://registry.yarnpkg.com/node-forge/-/node-forge-1.3.1.tgz#be8da2af243b2417d5f646a770663a92b7e9ded3" integrity sha512-dPEtOeMvF9VMcYV/1Wb8CPoVAXtp6MKMlcbAt4ddqmGqUJ6fQZFXkNZNkNlfevtNkGtaSoXf/vNNNSvgrdXwtA==