Skip to content

Commit d52b6a3

Browse files
committed
fix(web-scripts): resolve sec issue with minimist, must use ^1.2.6
1 parent db8bb35 commit d52b6a3

File tree

3 files changed

+46
-10
lines changed

3 files changed

+46
-10
lines changed

package.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,5 +26,8 @@
2626
"husky": "^8.0.1",
2727
"lerna": "^5.1.8",
2828
"typescript": "^4.2.3"
29+
},
30+
"resolutions": {
31+
"minimist": "^1.2.6"
2932
}
3033
}

packages/web-scripts/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,9 @@
4242
"@types/react": "^18.0.15",
4343
"@types/react-dom": "^18.0.6",
4444
"commander": "^6.1.0",
45-
"commitizen": "^4.2.3",
45+
"commitizen": "^4.2.4",
4646
"cross-spawn-promise": "^0.10.1",
47-
"cz-conventional-changelog": "^3.0.2",
47+
"cz-conventional-changelog": "^3.3.0",
4848
"debug": "^4.1.1",
4949
"eslint": "^8.10.0",
5050
"jest": "^28.1.2",

yarn.lock

Lines changed: 41 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -2204,13 +2204,51 @@
22042204
dependencies:
22052205
"@sinonjs/commons" "^1.7.0"
22062206

2207+
"@spotify/eslint-config-base@^13.0.1":
2208+
version "13.0.1"
2209+
resolved "https://registry.yarnpkg.com/@spotify/eslint-config-base/-/eslint-config-base-13.0.1.tgz#91471028de6426a1f1a5cc06aa9aeb6d8c85565f"
2210+
integrity sha512-7dC5zMJpNud9UBCHVk/IWfZOXKyuRkcyopHzTJi3xsfmZcZvi0jTSVIf7sv8315lpjmqroVZoUdKbxZFkZcZpA==
2211+
22072212
"@spotify/eslint-config-oss@^1.0.0":
22082213
version "1.0.2"
22092214
resolved "https://registry.yarnpkg.com/@spotify/eslint-config-oss/-/eslint-config-oss-1.0.2.tgz#b0e56e549c78dcdd79063ce48521f10c3420f701"
22102215
integrity sha512-3Tn6R98f5BWeb8anOhxYdvZywasp1RaJb+y65W7Db5+xiQVmCnSFvIM3jwysQpu1xRdlUJSCqeDHR7S4Nz3thw==
22112216
dependencies:
22122217
eslint-plugin-notice "^0.9.10"
22132218

2219+
"@spotify/eslint-config-react@^13.0.1":
2220+
version "13.0.1"
2221+
resolved "https://registry.yarnpkg.com/@spotify/eslint-config-react/-/eslint-config-react-13.0.1.tgz#f309f5d3c53ef1e2c7c6ce05f76ee681970112c3"
2222+
integrity sha512-gyC0CtJ2H9K57HyQG5/RcMsJiB6qmVbBHOHWukZcPLfYtwkK201kgMjHrVfJXoSN+mJxcWhDVPxqe+eA7LHshQ==
2223+
2224+
"@spotify/eslint-config-typescript@^13.0.1":
2225+
version "13.0.1"
2226+
resolved "https://registry.yarnpkg.com/@spotify/eslint-config-typescript/-/eslint-config-typescript-13.0.1.tgz#47801a66d5569074a110f4422eba60aafc6bd7f8"
2227+
integrity sha512-1wLQFyN2H2v+rn/mytA2PGzmGxOmdZdcKBpNyW+4z0qJydpvavp2SeBj/X+FEbwKoYBoUdG9QLr40eLQh1ZHZA==
2228+
2229+
"@spotify/eslint-plugin@^13.0.0":
2230+
version "13.0.1"
2231+
resolved "https://registry.yarnpkg.com/@spotify/eslint-plugin/-/eslint-plugin-13.0.1.tgz#46789dbbbae4a5154197d678d498e93e6930cd4f"
2232+
integrity sha512-N5mipnByFPrCFLhYXgevNGGgiqzmk7mGrvm58Gh2iobzvPi6pLtGS0R//Jg5cXydYnJ5wupK1zAxuG3AD1lULQ==
2233+
2234+
"@spotify/prettier-config@^13.0.1":
2235+
version "13.0.1"
2236+
resolved "https://registry.yarnpkg.com/@spotify/prettier-config/-/prettier-config-13.0.1.tgz#0fdceb3d4ab543259ce6adc0ec1d10e34898b812"
2237+
integrity sha512-oVd4hjx2+y0MeUdk1l+ItwVLwlrDlvTlGwXBWMMzPYc7DLyxuxFvDfoHGkAQkrikfAgtdnzxrW6u9a8ywUqdfw==
2238+
2239+
"@spotify/tsconfig@^13.0.1":
2240+
version "13.0.1"
2241+
resolved "https://registry.yarnpkg.com/@spotify/tsconfig/-/tsconfig-13.0.1.tgz#c9495476ff36e9b8a6e47870e489a9755488666d"
2242+
integrity sha512-gwF13n4WEsfOneHbIzmJuOrmeuusSdFzT7mxEEFsxPEeoLuFDGW6Gahf1qUsdhFWlVbuIqVwN0GRczAdENUXuA==
2243+
2244+
"@spotify/web-scripts-utils@^13.0.1":
2245+
version "13.0.1"
2246+
resolved "https://registry.yarnpkg.com/@spotify/web-scripts-utils/-/web-scripts-utils-13.0.1.tgz#73c944c84befc0fb0b1ccd414bb3f126100b0852"
2247+
integrity sha512-goL6BjMmFfsnFrxEYpZGU6qB4gRDpkK3H8+3av4AbLbbCgMJd652jCpnF93DY5dDeggK39uZv/FCjIKKIVA5Tg==
2248+
dependencies:
2249+
glob "^7.1.4"
2250+
read-pkg-up "^7.0.1"
2251+
22142252
"@tootallnate/once@1":
22152253
version "1.1.2"
22162254
resolved "https://registry.yarnpkg.com/@tootallnate/once/-/once-1.1.2.tgz#ccb91445360179a04e7fe6aff78c00ffc1eeaf82"
@@ -3304,7 +3342,7 @@ commander@^9.3.0:
33043342
resolved "https://registry.yarnpkg.com/commander/-/commander-9.3.0.tgz#f619114a5a2d2054e0d9ff1b31d5ccf89255e26b"
33053343
integrity sha512-hv95iU5uXPbK83mjrJKuZyFM/LBAoCV/XhVGkS5Je6tl7sxr6A0ITMw5WoRV46/UaJ46Nllm3Xt7IaJhXTIkzw==
33063344

3307-
commitizen@^4.0.3, commitizen@^4.2.3:
3345+
commitizen@^4.0.3, commitizen@^4.2.4:
33083346
version "4.2.4"
33093347
resolved "https://registry.yarnpkg.com/commitizen/-/commitizen-4.2.4.tgz#a3e5b36bd7575f6bf6e7aa19dbbf06b0d8f37165"
33103348
integrity sha512-LlZChbDzg3Ir3O2S7jSo/cgWp5/QwylQVr59K4xayVq8S4/RdKzSyJkghAiZZHfhh5t4pxunUoyeg0ml1q/7aw==
@@ -3566,7 +3604,7 @@ cz-conventional-changelog@3.2.0:
35663604
optionalDependencies:
35673605
"@commitlint/load" ">6.1.1"
35683606

3569-
cz-conventional-changelog@^3.0.2:
3607+
cz-conventional-changelog@^3.3.0:
35703608
version "3.3.0"
35713609
resolved "https://registry.yarnpkg.com/cz-conventional-changelog/-/cz-conventional-changelog-3.3.0.tgz#9246947c90404149b3fe2cf7ee91acad3b7d22d2"
35723610
integrity sha512-U466fIzU5U22eES5lTNiNbZ+d8dfcHcssH4o7QsdWaCcRs/feIPCxKYSWkYBNs5mny7MvEfwpTLWjvbm94hecw==
@@ -6306,12 +6344,7 @@ minimist-options@4.1.0:
63066344
is-plain-obj "^1.1.0"
63076345
kind-of "^6.0.3"
63086346

6309-
minimist@1.2.5:
6310-
version "1.2.5"
6311-
resolved "https://registry.yarnpkg.com/minimist/-/minimist-1.2.5.tgz#67d66014b66a6a8aaa0c083c5fd58df4e4e97602"
6312-
integrity sha512-FM9nNUYrRBAELZQT3xeZQ7fmMOBg6nWNmJKTcgsJeaLstP/UODVpGsr5OhXhhXg6f+qtJ8uiZ+PUxkDWcgIXLw==
6313-
6314-
minimist@^1.2.0, minimist@^1.2.5:
6347+
minimist@1.2.5, minimist@^1.2.0, minimist@^1.2.5, minimist@^1.2.6:
63156348
version "1.2.6"
63166349
resolved "https://registry.yarnpkg.com/minimist/-/minimist-1.2.6.tgz#8637a5b759ea0d6e98702cfb3a9283323c93af44"
63176350
integrity sha512-Jsjnk4bw3YJqYzbdyBiNsPWHPfO++UGG749Cxs6peCu5Xg4nrena6OVxOYxrQTqww0Jmwt+Ref8rggumkTLz9Q==

0 commit comments

Comments
 (0)