From d6a5463e6130b454d2deaf0138fb52e72c95809c Mon Sep 17 00:00:00 2001 From: Michael Nelson Date: Tue, 6 Feb 2024 15:02:51 -0800 Subject: [PATCH] Update follow-redirects dependency This addresses https://nvd.nist.gov/vuln/detail/CVE-2023-26159. --- package-lock.json | 14 +++++++------- package.json | 3 +++ 2 files changed, 10 insertions(+), 7 deletions(-) diff --git a/package-lock.json b/package-lock.json index 4adf180..30a2e7a 100644 --- a/package-lock.json +++ b/package-lock.json @@ -115,9 +115,9 @@ "integrity": "sha512-8guHBZCwKnFhYdHr2ysuRWErTwhoN2X8XELRlrRwpmfeY2jjuUN4taQMsULKUVo1K4DvZl+0pgfyoysHxvmvEw==" }, "node_modules/follow-redirects": { - "version": "1.15.2", - "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.2.tgz", - "integrity": "sha512-VQLG33o04KaQ8uYi2tVNbdrWp1QWxNNea+nmIB4EVM28v0hmP17z7aG1+wAkNzVq4KeXTq3221ye5qTJP91JwA==", + "version": "1.15.5", + "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.5.tgz", + "integrity": "sha512-vSFWUON1B+yAw1VN4xMfxgn5fTUiaOzAJCKBwIIgT/+7CuGy9+r+5gITvP62j3RmaD5Ph65UaERdOSRGUzZtgw==", "funding": [ { "type": "individual", @@ -485,9 +485,9 @@ "integrity": "sha512-8guHBZCwKnFhYdHr2ysuRWErTwhoN2X8XELRlrRwpmfeY2jjuUN4taQMsULKUVo1K4DvZl+0pgfyoysHxvmvEw==" }, "follow-redirects": { - "version": "1.15.2", - "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.2.tgz", - "integrity": "sha512-VQLG33o04KaQ8uYi2tVNbdrWp1QWxNNea+nmIB4EVM28v0hmP17z7aG1+wAkNzVq4KeXTq3221ye5qTJP91JwA==" + "version": "1.15.5", + "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.15.5.tgz", + "integrity": "sha512-vSFWUON1B+yAw1VN4xMfxgn5fTUiaOzAJCKBwIIgT/+7CuGy9+r+5gITvP62j3RmaD5Ph65UaERdOSRGUzZtgw==" }, "function-bind": { "version": "1.1.1", @@ -541,7 +541,7 @@ "integrity": "sha512-7mz/721AbnJwIVbnaSv1Cz3Am0ZLT/UBwkC92VlxhXv/k/BBQfM2fXElQNC27BVGr0uwUpplYPQM9LnaBMR5NQ==", "requires": { "eventemitter3": "^4.0.0", - "follow-redirects": "^1.0.0", + "follow-redirects": ">=1.15.5", "requires-port": "^1.0.0" } }, diff --git a/package.json b/package.json index f14d13c..bf0a6ba 100644 --- a/package.json +++ b/package.json @@ -7,6 +7,9 @@ "@bcgov/smk": "1.2.1", "http-server": "^14.1.1" }, + "overrides": { + "follow-redirects": ">=1.15.5" + }, "scripts": { "view": "http-server -o -c-1" }