From b343add87838fe6a94343f5df9ff7b2e9f6a3f4c Mon Sep 17 00:00:00 2001 From: Michael Bond Date: Tue, 4 Sep 2018 07:23:25 -0400 Subject: [PATCH] fix: Update dependency `rc` to latest version Updating `rc` to the latest version (1.2.8) addresses the issue where `rc` version 1.1.6 depended on a version of deep-extend which has a security vulnerability. Signed-off-by: Michael Bond --- package-lock.json | 16 ++++++++-------- package.json | 2 +- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/package-lock.json b/package-lock.json index 01b8fec3..e3db7832 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1749,24 +1749,24 @@ "dev": true }, "rc": { - "version": "1.2.6", - "resolved": "https://registry.npmjs.org/rc/-/rc-1.2.6.tgz", - "integrity": "sha1-6xiYnG1PTxYsOZ953dKfODVWgJI=", + "version": "1.2.8", + "resolved": "https://registry.npmjs.org/rc/-/rc-1.2.8.tgz", + "integrity": "sha512-y3bGgqKj3QBdxLbLkomlohkvsA8gdAiUQlSBJnBhfn+BPxg4bc62d8TcBW15wavDfgexCgccckhcZvywyQYPOw==", "requires": { - "deep-extend": "0.4.2", + "deep-extend": "0.6.0", "ini": "1.3.5", "minimist": "1.2.0", "strip-json-comments": "2.0.1" }, "dependencies": { "deep-extend": { - "version": "0.4.2", - "resolved": "https://registry.npmjs.org/deep-extend/-/deep-extend-0.4.2.tgz", - "integrity": "sha1-SLaZwn4zS/ifEIkr5DL25MfTSn8=" + "version": "0.6.0", + "resolved": "https://registry.npmjs.org/deep-extend/-/deep-extend-0.6.0.tgz", + "integrity": "sha512-LOHxIOaPYdHlJRtCQfDIVZtfw/ufM8+rVj649RIHzcm/vGwQRXFt6OPqIFWsm2XEMrNIEtWR64sY1LEKD2vAOA==" }, "minimist": { "version": "1.2.0", - "resolved": "https://registry.npmjs.org/minimist/-/minimist-1.2.0.tgz", + "resolved": "http://registry.npmjs.org/minimist/-/minimist-1.2.0.tgz", "integrity": "sha1-o1AIsg9BOD7sH7kU9M1d95omQoQ=" } } diff --git a/package.json b/package.json index 4a7ad5b5..78d0aaa9 100644 --- a/package.json +++ b/package.json @@ -56,7 +56,7 @@ "parse-database-url": "~0.3.0", "pkginfo": "^0.4.0", "prompt": "^1.0.0", - "rc": "^1.1.6", + "rc": "^1.2.8", "resolve": "^1.1.6", "semver": "^5.3.0", "tunnel-ssh": "^4.0.0"