Commit faf367c
authored
chore(security): close 9 dependabot alerts (Jun-23 triage wave) (#1342)
Closes 9 of 14 open Dependabot alerts on this repo. Two floor bumps on
existing `pnpm.overrides` entries + one new entry; lockfile regenerated.
The remaining 5 alerts are cryptography (#191/#192/#193 — handled in
the #1290/#1291 PR pair and a follow-up for text_output) and nltk
(#202/#203 — patched=null, tracked upstream).
Alerts closed:
#204 HIGH undici >=7.24.0 → >=7.28.0
#205 MED undici (same line)
#209 LOW undici (same line)
#210 HIGH undici (same line)
#211 HIGH undici (same line)
#212 MED undici (same line)
#213 LOW undici (same line)
#206 MED webpack-dev-server >=5.2.4 → >=5.2.5
#214 MED http-proxy-middleware new entry: >=2.0.10 <3
Lockfile-verified single resolutions post-edit:
undici@7.28.0
webpack-dev-server@5.2.5
http-proxy-middleware@2.0.101 parent 1b1c70b commit faf367c
2 files changed
Lines changed: 20 additions & 18 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
| 71 | + | |
71 | 72 | | |
72 | 73 | | |
73 | 74 | | |
| |||
96 | 97 | | |
97 | 98 | | |
98 | 99 | | |
99 | | - | |
| 100 | + | |
100 | 101 | | |
101 | | - | |
| 102 | + | |
102 | 103 | | |
103 | 104 | | |
104 | 105 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments