diff --git a/CHANGELOG.md b/CHANGELOG.md index 242668295..a0c313f81 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,6 +13,7 @@ Inspired by [Keep a Changelog](https://keepachangelog.com/en/1.0.0/) ### Deprecated ### Removed ### Fixed +- Upgrade `JSON11` from 1.1.2 to 2.0.0 to ensure UTF-8 safety when stringifying JSON data ### Security ## [2.12.0] diff --git a/package.json b/package.json index c3117f294..2273e19ce 100644 --- a/package.json +++ b/package.json @@ -104,7 +104,7 @@ "dependencies": { "aws4": "^1.11.0", "debug": "^4.3.1", - "json11": "^1.1.2", + "json11": "^2.0.0", "hpagent": "^1.2.0", "ms": "^2.1.3", "secure-json-parse": "^2.4.0" diff --git a/yarn.lock b/yarn.lock index efdeea8cd..7809badda 100644 --- a/yarn.lock +++ b/yarn.lock @@ -2091,10 +2091,10 @@ json-stable-stringify-without-jsonify@^1.0.1: resolved "https://registry.yarnpkg.com/json-stable-stringify-without-jsonify/-/json-stable-stringify-without-jsonify-1.0.1.tgz#9db7b59496ad3f3cfef30a75142d2d930ad72651" integrity sha1-nbe1lJatPzz+8wp1FC0tkwrXJlE= -json11@^1.1.2: - version "1.1.2" - resolved "https://registry.yarnpkg.com/json11/-/json11-1.1.2.tgz#35ffd3ee5073b0cc09ef826b0a0dc005ebef2b5b" - integrity sha512-5r1RHT1/Gr/jsI/XZZj/P6F11BKM8xvTaftRuiLkQI9Z2PFDukM82Ysxw8yDszb3NJP/NKnRlSGmhUdG99rlBw== +json11@^2.0.0: + version "2.0.0" + resolved "https://registry.yarnpkg.com/json11/-/json11-2.0.0.tgz#06c4ad0a40b50c5de99a87f6d3028593137e5641" + integrity sha512-VuKJKUSPEJape+daTm70Nx7vdcdorf4S6LCyN2z0jUVH4UrQ4ftXo2kC0bnHpCREmxHuHqCNVPA75BjI3CB6Ag== json5@^2.1.2: version "2.2.3"