From 795fea309dfe6985c3c251252ff64d5af67915c7 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 28 Aug 2020 00:43:03 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-608086 --- package.json | 2 +- yarn.lock | 9 +++++++-- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/package.json b/package.json index cdf719c..4bc9612 100644 --- a/package.json +++ b/package.json @@ -17,7 +17,7 @@ "bluebird": "^3.5.1", "js-yaml": "^3.10.0", "knex": "^0.14.2", - "lodash": "^4.17.4", + "lodash": "^4.17.17", "merge-stream": "^1.0.1", "moment": "^2.20.1", "request": "^2.83.0", diff --git a/yarn.lock b/yarn.lock index 3aa7070..d928db2 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1782,6 +1782,11 @@ lodash@^4.14.0, lodash@^4.17.4, lodash@^4.6.0: version "4.17.4" resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.4.tgz#78203a4d1c328ae1d86dca6460e369b57f4055ae" +lodash@^4.17.17: + version "4.17.20" + resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.20.tgz#b44a9b6297bcb698f1c51a3545a2b3b368d59c52" + integrity sha512-PlhdFcillOINfeV7Ni6oF1TAEayyZBoZ8bcshTHqOYJYlrqzRK5hagpagky5o4HfCzzd1TRkXPMFq6cKk9rGmA== + longest@^1.0.1: version "1.0.1" resolved "https://registry.yarnpkg.com/longest/-/longest-1.0.1.tgz#30a0b2da38f73770e8294a0d22e6625ed77d0097" @@ -3010,9 +3015,9 @@ watchpack@^1.4.0: chokidar "^1.7.0" graceful-fs "^4.1.2" -"web3-typed@https://github.com/cashila/web3-typed": +"web3-typed@https://github.com/Softmotions/web3-typed.git": version "0.17.0-beta" - resolved "https://github.com/cashila/web3-typed#fcdff55f5464711937b1b328b01fe36d5c6735c7" + resolved "https://github.com/Softmotions/web3-typed.git#2305ebd0adedfe218ea24fc069798f6115a70d03" dependencies: "@types/bignumber.js" "^4.0.2"