Update package versions to avoid CVEs #50
Merged
+10
−11,543
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Below CVEs are reported by nSpect. Update the package versions to avoid those issues.
id : BDSA-2023-1661
tough-cookie
to at least4.1.3
id: BDSA-2025-1027
serialize-javascript
to at least6.0.2
id : BDSA-2024-5787,
webpack
to at least5.94.0
id: BDSA-2023-1408, security: avoid cross-realm objects webpack/webpack#16500
webpack
to at least5.76.0
Note: both
yarn.lock
are removed, since currently we're not able to build the examples to get those updated.Checklist