Skip to content

Commit aaaf703

Browse files
committed
minor #1356 Upgrading some dependencies with vulnerability issues (Kocal)
This PR was squashed before being merged into the main branch. Discussion ---------- Upgrading some dependencies with vulnerability issues | Q | A | ------------- | --- | Bug fix? | no | New feature? | no <!-- please update CHANGELOG.md file --> | Deprecations? | no <!-- please update CHANGELOG.md file --> | Issues | Fix #... <!-- prefix each issue number with "Fix #", no need to create an issue if none exists, explain below instead --> | License | MIT <!-- Replace this notice by a description of your feature/bugfix. This will help reviewers and should be a good start for the documentation. Additionally (see https://symfony.com/releases): - Always add tests and ensure they pass. - Features and deprecations must be submitted against the latest branch. - For new features, provide some code snippets to help understand usage. - Changelog entry should follow https://symfony.com/doc/current/contributing/code/conventions.html#writing-a-changelog-entry - Never break backward compatibility. --> Purely internal, it won't impact end-users (except for suggesting a newer version of `webpack-dev-server`). That's mainly to close issues opened in https://github.com/symfony/webpack-encore/security/dependabot Commits ------- 93f37f5 Upgrade Express to 4.21.1, to fix issues with cookie, send, and path-to-regexp abc75cf Update http-proxy-middleware to 2.0.7 (https://github.com/symfony/webpack-encore/security/dependabot/144) a96b9fd Update cross-spawn to 7.0.6 (https://github.com/symfony/webpack-encore/security/dependabot/145)
2 parents 57cd2bf + 93f37f5 commit aaaf703

File tree

11 files changed

+57
-83
lines changed

11 files changed

+57
-83
lines changed

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,7 @@
9797
"vue-loader": "^17.0.0",
9898
"webpack": "^5.72",
9999
"webpack-cli": "^5.1.4",
100-
"webpack-dev-server": "^5.0.4",
100+
"webpack-dev-server": "^5.1.0",
101101
"webpack-notifier": "^1.15.0"
102102
},
103103
"peerDependencies": {

test_apps/npm-with-babel/package-lock.json

+3-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

test_apps/npm-with-external-babel-config/package-lock.json

+3-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

test_apps/npm/package-lock.json

+3-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

test_apps/pnpm-with-babel/pnpm-lock.yaml

+3-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

test_apps/pnpm-with-external-babel-config/pnpm-lock.yaml

+3-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

test_apps/pnpm/pnpm-lock.yaml

+3-3
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

test_apps/yarn-pnp-with-babel/yarn.lock

+3-3
Original file line numberDiff line numberDiff line change
@@ -1818,13 +1818,13 @@ __metadata:
18181818
linkType: hard
18191819

18201820
"cross-spawn@npm:^7.0.3":
1821-
version: 7.0.3
1822-
resolution: "cross-spawn@npm:7.0.3"
1821+
version: 7.0.6
1822+
resolution: "cross-spawn@npm:7.0.6"
18231823
dependencies:
18241824
path-key: "npm:^3.1.0"
18251825
shebang-command: "npm:^2.0.0"
18261826
which: "npm:^2.0.1"
1827-
checksum: 10/e1a13869d2f57d974de0d9ef7acbf69dc6937db20b918525a01dacb5032129bd552d290d886d981e99f1b624cb03657084cc87bd40f115c07ecf376821c729ce
1827+
checksum: 10/0d52657d7ae36eb130999dffff1168ec348687b48dd38e2ff59992ed916c88d328cf1d07ff4a4a10bc78de5e1c23f04b306d569e42f7a2293915c081e4dfee86
18281828
languageName: node
18291829
linkType: hard
18301830

test_apps/yarn-pnp-with-external-babel-config/yarn.lock

+3-3
Original file line numberDiff line numberDiff line change
@@ -1818,13 +1818,13 @@ __metadata:
18181818
linkType: hard
18191819

18201820
"cross-spawn@npm:^7.0.3":
1821-
version: 7.0.3
1822-
resolution: "cross-spawn@npm:7.0.3"
1821+
version: 7.0.6
1822+
resolution: "cross-spawn@npm:7.0.6"
18231823
dependencies:
18241824
path-key: "npm:^3.1.0"
18251825
shebang-command: "npm:^2.0.0"
18261826
which: "npm:^2.0.1"
1827-
checksum: 10/e1a13869d2f57d974de0d9ef7acbf69dc6937db20b918525a01dacb5032129bd552d290d886d981e99f1b624cb03657084cc87bd40f115c07ecf376821c729ce
1827+
checksum: 10/0d52657d7ae36eb130999dffff1168ec348687b48dd38e2ff59992ed916c88d328cf1d07ff4a4a10bc78de5e1c23f04b306d569e42f7a2293915c081e4dfee86
18281828
languageName: node
18291829
linkType: hard
18301830

test_apps/yarn-pnp/yarn.lock

+3-3
Original file line numberDiff line numberDiff line change
@@ -1795,13 +1795,13 @@ __metadata:
17951795
linkType: hard
17961796

17971797
"cross-spawn@npm:^7.0.3":
1798-
version: 7.0.3
1799-
resolution: "cross-spawn@npm:7.0.3"
1798+
version: 7.0.6
1799+
resolution: "cross-spawn@npm:7.0.6"
18001800
dependencies:
18011801
path-key: "npm:^3.1.0"
18021802
shebang-command: "npm:^2.0.0"
18031803
which: "npm:^2.0.1"
1804-
checksum: 10/e1a13869d2f57d974de0d9ef7acbf69dc6937db20b918525a01dacb5032129bd552d290d886d981e99f1b624cb03657084cc87bd40f115c07ecf376821c729ce
1804+
checksum: 10/0d52657d7ae36eb130999dffff1168ec348687b48dd38e2ff59992ed916c88d328cf1d07ff4a4a10bc78de5e1c23f04b306d569e42f7a2293915c081e4dfee86
18051805
languageName: node
18061806
linkType: hard
18071807

yarn.lock

+29-55
Original file line numberDiff line numberDiff line change
@@ -2648,10 +2648,10 @@ cookie-signature@1.0.6:
26482648
resolved "https://registry.yarnpkg.com/cookie-signature/-/cookie-signature-1.0.6.tgz#e303a882b342cc3ee8ca513a79999734dab3ae2c"
26492649
integrity sha512-QADzlaHc8icV8I7vbaJXJwod9HWYp8uCqf1xa4OfNu1T7JVxQIrUgOWtHdNDtPiywmFbiS12VjotIXLrKM3orQ==
26502650

2651-
cookie@0.6.0:
2652-
version "0.6.0"
2653-
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.6.0.tgz#2798b04b071b0ecbff0dbb62a505a8efa4e19051"
2654-
integrity sha512-U71cyTamuh1CRNCfpGY6to28lxvNwPG4Guz/EVjgf3Jmzv0vlDp1atT9eS5dDjMYHucpHbWns6Lwf3BKz6svdw==
2651+
cookie@0.7.1:
2652+
version "0.7.1"
2653+
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.7.1.tgz#2f73c42142d5d5cf71310a74fc4ae61670e5dbc9"
2654+
integrity sha512-6DnInpx7SJ2AK3+CTUE/ZM0vWTUboZCegxhC2xiIydHR9jNuTAASBrfEpHhiGOZw/nX51bHt6YQl8jsGo4y/0w==
26552655

26562656
copy-anything@^2.0.1:
26572657
version "2.0.6"
@@ -2703,9 +2703,9 @@ cosmiconfig@^9.0.0:
27032703
parse-json "^5.2.0"
27042704

27052705
cross-spawn@^7.0.2, cross-spawn@^7.0.3:
2706-
version "7.0.3"
2707-
resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.3.tgz#f73a85b9d5d41d045551c177e2882d4ac85728a6"
2708-
integrity sha512-iRDPJKUPVEND7dHPO8rkbOnPpyDygcDFtWjpeWNCgy8WP2rXcxXL8TskReQl6OrB2G7+UJrags1q15Fudc7G6w==
2706+
version "7.0.6"
2707+
resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.6.tgz#8a58fe78f00dcd70c370451759dfbfaf03e8ee9f"
2708+
integrity sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA==
27092709
dependencies:
27102710
path-key "^3.1.0"
27112711
shebang-command "^2.0.0"
@@ -3561,23 +3561,23 @@ events@^3.2.0:
35613561
integrity sha512-mQw+2fkQbALzQ7V0MY0IqdnXNOeTtP4r0lN9z7AAawCXgqea7bDii20AYrIBrFd/Hx0M2Ocz6S111CaFkUcb0Q==
35623562

35633563
express@^4.19.2:
3564-
version "4.20.0"
3565-
resolved "https://registry.yarnpkg.com/express/-/express-4.20.0.tgz#f1d08e591fcec770c07be4767af8eb9bcfd67c48"
3566-
integrity sha512-pLdae7I6QqShF5PnNTCVn4hI91Dx0Grkn2+IAsMTgMIKuQVte2dN9PeGSSAME2FR8anOhVA62QDIUaWVfEXVLw==
3564+
version "4.21.1"
3565+
resolved "https://registry.yarnpkg.com/express/-/express-4.21.1.tgz#9dae5dda832f16b4eec941a4e44aa89ec481b281"
3566+
integrity sha512-YSFlK1Ee0/GC8QaO91tHcDxJiE/X4FbpAyQWkxAvG6AXCuR65YzK8ua6D9hvi/TzUfZMpc+BwuM1IPw8fmQBiQ==
35673567
dependencies:
35683568
accepts "~1.3.8"
35693569
array-flatten "1.1.1"
35703570
body-parser "1.20.3"
35713571
content-disposition "0.5.4"
35723572
content-type "~1.0.4"
3573-
cookie "0.6.0"
3573+
cookie "0.7.1"
35743574
cookie-signature "1.0.6"
35753575
debug "2.6.9"
35763576
depd "2.0.0"
35773577
encodeurl "~2.0.0"
35783578
escape-html "~1.0.3"
35793579
etag "~1.8.1"
3580-
finalhandler "1.2.0"
3580+
finalhandler "1.3.1"
35813581
fresh "0.5.2"
35823582
http-errors "2.0.0"
35833583
merge-descriptors "1.0.3"
@@ -3586,11 +3586,11 @@ express@^4.19.2:
35863586
parseurl "~1.3.3"
35873587
path-to-regexp "0.1.10"
35883588
proxy-addr "~2.0.7"
3589-
qs "6.11.0"
3589+
qs "6.13.0"
35903590
range-parser "~1.2.1"
35913591
safe-buffer "5.2.1"
35923592
send "0.19.0"
3593-
serve-static "1.16.0"
3593+
serve-static "1.16.2"
35943594
setprototypeof "1.2.0"
35953595
statuses "2.0.1"
35963596
type-is "~1.6.18"
@@ -3704,13 +3704,13 @@ fill-range@^7.1.1:
37043704
dependencies:
37053705
to-regex-range "^5.0.1"
37063706

3707-
finalhandler@1.2.0:
3708-
version "1.2.0"
3709-
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.2.0.tgz#7d23fe5731b207b4640e4fcd00aec1f9207a7b32"
3710-
integrity sha512-5uXcUVftlQMFnWC9qu/svkWv3GTd2PfUhK/3PLkYNAe7FbqJMt3515HaxE6eRL74GdsriiwujiawdaB1BpEISg==
3707+
finalhandler@1.3.1:
3708+
version "1.3.1"
3709+
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.3.1.tgz#0c575f1d1d324ddd1da35ad7ece3df7d19088019"
3710+
integrity sha512-6BN9trH7bp3qvnrRyzsBz+g3lZxTNZTbVO2EV1CS0WIcDbawYVdYvGflME/9QP0h0pYlCDBCTjYa9nZzMDpyxQ==
37113711
dependencies:
37123712
debug "2.6.9"
3713-
encodeurl "~1.0.2"
3713+
encodeurl "~2.0.0"
37143714
escape-html "~1.0.3"
37153715
on-finished "2.4.1"
37163716
parseurl "~1.3.3"
@@ -4172,9 +4172,9 @@ http-proxy-agent@^7.0.0, http-proxy-agent@^7.0.1:
41724172
debug "^4.3.4"
41734173

41744174
http-proxy-middleware@^2.0.3:
4175-
version "2.0.6"
4176-
resolved "https://registry.yarnpkg.com/http-proxy-middleware/-/http-proxy-middleware-2.0.6.tgz#e1a4dd6979572c7ab5a4e4b55095d1f32a74963f"
4177-
integrity sha512-ya/UeJ6HVBYxrgYotAZo1KvPWlgB48kUJLDePFeneHsVujFaW5WNj2NgWCAE//B1Dl02BIfYlpNgBy8Kf8Rjmw==
4175+
version "2.0.7"
4176+
resolved "https://registry.yarnpkg.com/http-proxy-middleware/-/http-proxy-middleware-2.0.7.tgz#915f236d92ae98ef48278a95dedf17e991936ec6"
4177+
integrity sha512-fgVY8AV7qU7z/MmXJ/rxwbrtQH4jBQ9m7kp3llF0liB7glmFeVZFBepQb32T3y8n8k2+AEYuMPCpinYW+/CuRA==
41784178
dependencies:
41794179
"@types/http-proxy" "^1.17.8"
41804180
http-proxy "^1.18.1"
@@ -5872,13 +5872,6 @@ puppeteer@^23.2.2:
58725872
puppeteer-core "23.3.0"
58735873
typed-query-selector "^2.12.0"
58745874

5875-
qs@6.11.0:
5876-
version "6.11.0"
5877-
resolved "https://registry.yarnpkg.com/qs/-/qs-6.11.0.tgz#fd0d963446f7a65e1367e01abd85429453f0c37a"
5878-
integrity sha512-MvjoMCJwEarSbUYk5O+nmoSzSutSsTwF85zcHPQ9OrlFoZOYIjaqBAJIqIXjptyD5vThxGq52Xu/MaJzRkIk4Q==
5879-
dependencies:
5880-
side-channel "^1.0.4"
5881-
58825875
qs@6.13.0, qs@^6.4.0:
58835876
version "6.13.0"
58845877
resolved "https://registry.yarnpkg.com/qs/-/qs-6.13.0.tgz#6ca3bd58439f7e245655798997787b0d88a51906"
@@ -6257,25 +6250,6 @@ semver@^7.3.2, semver@^7.3.4, semver@^7.3.5, semver@^7.5.4, semver@^7.6.3:
62576250
resolved "https://registry.yarnpkg.com/semver/-/semver-7.6.3.tgz#980f7b5550bc175fb4dc09403085627f9eb33143"
62586251
integrity sha512-oVekP1cKtI+CTDvHWYFUcMtsK/00wmAEfyqKfNdARm8u1wNVhSgaX7A8d4UuIlUI5e84iEwOhs7ZPYRmzU9U6A==
62596252

6260-
send@0.18.0:
6261-
version "0.18.0"
6262-
resolved "https://registry.yarnpkg.com/send/-/send-0.18.0.tgz#670167cc654b05f5aa4a767f9113bb371bc706be"
6263-
integrity sha512-qqWzuOjSFOuqPjFe4NOsMLafToQQwBSOEpS+FwEt3A2V3vKubTquT3vmLTQpFgMXp8AlFWFuP1qKaJZOtPpVXg==
6264-
dependencies:
6265-
debug "2.6.9"
6266-
depd "2.0.0"
6267-
destroy "1.2.0"
6268-
encodeurl "~1.0.2"
6269-
escape-html "~1.0.3"
6270-
etag "~1.8.1"
6271-
fresh "0.5.2"
6272-
http-errors "2.0.0"
6273-
mime "1.6.0"
6274-
ms "2.1.3"
6275-
on-finished "2.4.1"
6276-
range-parser "~1.2.1"
6277-
statuses "2.0.1"
6278-
62796253
send@0.19.0:
62806254
version "0.19.0"
62816255
resolved "https://registry.yarnpkg.com/send/-/send-0.19.0.tgz#bbc5a388c8ea6c048967049dbeac0e4a3f09d7f8"
@@ -6315,15 +6289,15 @@ serve-index@^1.9.1:
63156289
mime-types "~2.1.17"
63166290
parseurl "~1.3.2"
63176291

6318-
serve-static@1.16.0:
6319-
version "1.16.0"
6320-
resolved "https://registry.yarnpkg.com/serve-static/-/serve-static-1.16.0.tgz#2bf4ed49f8af311b519c46f272bf6ac3baf38a92"
6321-
integrity sha512-pDLK8zwl2eKaYrs8mrPZBJua4hMplRWJ1tIFksVC3FtBEBnl8dxgeHtsaMS8DhS9i4fLObaon6ABoc4/hQGdPA==
6292+
serve-static@1.16.2:
6293+
version "1.16.2"
6294+
resolved "https://registry.yarnpkg.com/serve-static/-/serve-static-1.16.2.tgz#b6a5343da47f6bdd2673848bf45754941e803296"
6295+
integrity sha512-VqpjJZKadQB/PEbEwvFdO43Ax5dFBZ2UECszz8bQ7pi7wt//PWe1P6MN7eCnjsatYtBT6EuiClbjSWP2WrIoTw==
63226296
dependencies:
6323-
encodeurl "~1.0.2"
6297+
encodeurl "~2.0.0"
63246298
escape-html "~1.0.3"
63256299
parseurl "~1.3.3"
6326-
send "0.18.0"
6300+
send "0.19.0"
63276301

63286302
set-function-length@^1.2.1:
63296303
version "1.2.2"
@@ -7134,7 +7108,7 @@ webpack-dev-middleware@^7.4.2:
71347108
range-parser "^1.2.1"
71357109
schema-utils "^4.0.0"
71367110

7137-
webpack-dev-server@^5.0.4:
7111+
webpack-dev-server@^5.1.0:
71387112
version "5.1.0"
71397113
resolved "https://registry.yarnpkg.com/webpack-dev-server/-/webpack-dev-server-5.1.0.tgz#8f44147402b4d8ab99bfeb9b6880daa1411064e5"
71407114
integrity sha512-aQpaN81X6tXie1FoOB7xlMfCsN19pSvRAeYUHOdFWOlhpQ/LlbfTqYwwmEDFV0h8GGuqmCmKmT+pxcUV/Nt2gQ==

0 commit comments

Comments
 (0)