Skip to content

Commit 16476da

Browse files
authored
Merge pull request #80 from nmirasch/GITOPS-5551_main
fix: CVE-2024-43799 upgrading transitive dep express to 4.21.0
2 parents 151b5c0 + f82c21f commit 16476da

File tree

2 files changed

+19
-45
lines changed

2 files changed

+19
-45
lines changed

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@
7373
"resolutions": {
7474
"glob-parent": "^5.1.2",
7575
"showdown": "^2.1.0",
76-
"express": "4.20.0"
76+
"express": "4.21.0"
7777
},
7878
"consolePlugin": {
7979
"name": "gitops-plugin",

yarn.lock

Lines changed: 18 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -3032,10 +3032,10 @@ execa@^5.0.0:
30323032
signal-exit "^3.0.3"
30333033
strip-final-newline "^2.0.0"
30343034

3035-
express@4.20.0, express@^4.17.3, express@^4.19.2:
3036-
version "4.20.0"
3037-
resolved "https://registry.yarnpkg.com/express/-/express-4.20.0.tgz#f1d08e591fcec770c07be4767af8eb9bcfd67c48"
3038-
integrity sha512-pLdae7I6QqShF5PnNTCVn4hI91Dx0Grkn2+IAsMTgMIKuQVte2dN9PeGSSAME2FR8anOhVA62QDIUaWVfEXVLw==
3035+
express@4.21.0, express@^4.17.3, express@^4.19.2:
3036+
version "4.21.0"
3037+
resolved "https://registry.yarnpkg.com/express/-/express-4.21.0.tgz#d57cb706d49623d4ac27833f1cbc466b668eb915"
3038+
integrity sha512-VqcNGcj/Id5ZT1LZ/cfihi3ttTn+NJmkli2eZADigjq29qTlWi/hAQ43t/VLPq8+UX06FCEx3ByOYet6ZFblng==
30393039
dependencies:
30403040
accepts "~1.3.8"
30413041
array-flatten "1.1.1"
@@ -3049,7 +3049,7 @@ [email protected], express@^4.17.3, express@^4.19.2:
30493049
encodeurl "~2.0.0"
30503050
escape-html "~1.0.3"
30513051
etag "~1.8.1"
3052-
finalhandler "1.2.0"
3052+
finalhandler "1.3.1"
30533053
fresh "0.5.2"
30543054
http-errors "2.0.0"
30553055
merge-descriptors "1.0.3"
@@ -3058,11 +3058,11 @@ [email protected], express@^4.17.3, express@^4.19.2:
30583058
parseurl "~1.3.3"
30593059
path-to-regexp "0.1.10"
30603060
proxy-addr "~2.0.7"
3061-
qs "6.11.0"
3061+
qs "6.13.0"
30623062
range-parser "~1.2.1"
30633063
safe-buffer "5.2.1"
30643064
send "0.19.0"
3065-
serve-static "1.16.0"
3065+
serve-static "1.16.2"
30663066
setprototypeof "1.2.0"
30673067
statuses "2.0.1"
30683068
type-is "~1.6.18"
@@ -3165,13 +3165,13 @@ fill-range@^7.1.1:
31653165
dependencies:
31663166
to-regex-range "^5.0.1"
31673167

3168-
finalhandler@1.2.0:
3169-
version "1.2.0"
3170-
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.2.0.tgz#7d23fe5731b207b4640e4fcd00aec1f9207a7b32"
3171-
integrity sha512-5uXcUVftlQMFnWC9qu/svkWv3GTd2PfUhK/3PLkYNAe7FbqJMt3515HaxE6eRL74GdsriiwujiawdaB1BpEISg==
3168+
finalhandler@1.3.1:
3169+
version "1.3.1"
3170+
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.3.1.tgz#0c575f1d1d324ddd1da35ad7ece3df7d19088019"
3171+
integrity sha512-6BN9trH7bp3qvnrRyzsBz+g3lZxTNZTbVO2EV1CS0WIcDbawYVdYvGflME/9QP0h0pYlCDBCTjYa9nZzMDpyxQ==
31723172
dependencies:
31733173
debug "2.6.9"
3174-
encodeurl "~1.0.2"
3174+
encodeurl "~2.0.0"
31753175
escape-html "~1.0.3"
31763176
on-finished "2.4.1"
31773177
parseurl "~1.3.3"
@@ -5056,13 +5056,6 @@ punycode@^2.1.0:
50565056
resolved "https://registry.yarnpkg.com/punycode/-/punycode-2.3.1.tgz#027422e2faec0b25e1549c3e1bd8309b9133b6e5"
50575057
integrity sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==
50585058

5059-
5060-
version "6.11.0"
5061-
resolved "https://registry.yarnpkg.com/qs/-/qs-6.11.0.tgz#fd0d963446f7a65e1367e01abd85429453f0c37a"
5062-
integrity sha512-MvjoMCJwEarSbUYk5O+nmoSzSutSsTwF85zcHPQ9OrlFoZOYIjaqBAJIqIXjptyD5vThxGq52Xu/MaJzRkIk4Q==
5063-
dependencies:
5064-
side-channel "^1.0.4"
5065-
50665059
50675060
version "6.13.0"
50685061
resolved "https://registry.yarnpkg.com/qs/-/qs-6.13.0.tgz#6ca3bd58439f7e245655798997787b0d88a51906"
@@ -5648,25 +5641,6 @@ semver@^7.2.1, semver@^7.3.2, semver@^7.3.4, semver@^7.3.5, semver@^7.3.7, semve
56485641
resolved "https://registry.yarnpkg.com/semver/-/semver-7.6.3.tgz#980f7b5550bc175fb4dc09403085627f9eb33143"
56495642
integrity sha512-oVekP1cKtI+CTDvHWYFUcMtsK/00wmAEfyqKfNdARm8u1wNVhSgaX7A8d4UuIlUI5e84iEwOhs7ZPYRmzU9U6A==
56505643

5651-
5652-
version "0.18.0"
5653-
resolved "https://registry.yarnpkg.com/send/-/send-0.18.0.tgz#670167cc654b05f5aa4a767f9113bb371bc706be"
5654-
integrity sha512-qqWzuOjSFOuqPjFe4NOsMLafToQQwBSOEpS+FwEt3A2V3vKubTquT3vmLTQpFgMXp8AlFWFuP1qKaJZOtPpVXg==
5655-
dependencies:
5656-
debug "2.6.9"
5657-
depd "2.0.0"
5658-
destroy "1.2.0"
5659-
encodeurl "~1.0.2"
5660-
escape-html "~1.0.3"
5661-
etag "~1.8.1"
5662-
fresh "0.5.2"
5663-
http-errors "2.0.0"
5664-
mime "1.6.0"
5665-
ms "2.1.3"
5666-
on-finished "2.4.1"
5667-
range-parser "~1.2.1"
5668-
statuses "2.0.1"
5669-
56705644
56715645
version "0.19.0"
56725646
resolved "https://registry.yarnpkg.com/send/-/send-0.19.0.tgz#bbc5a388c8ea6c048967049dbeac0e4a3f09d7f8"
@@ -5706,15 +5680,15 @@ serve-index@^1.9.1:
57065680
mime-types "~2.1.17"
57075681
parseurl "~1.3.2"
57085682

5709-
5710-
version "1.16.0"
5711-
resolved "https://registry.yarnpkg.com/serve-static/-/serve-static-1.16.0.tgz#2bf4ed49f8af311b519c46f272bf6ac3baf38a92"
5712-
integrity sha512-pDLK8zwl2eKaYrs8mrPZBJua4hMplRWJ1tIFksVC3FtBEBnl8dxgeHtsaMS8DhS9i4fLObaon6ABoc4/hQGdPA==
5683+
5684+
version "1.16.2"
5685+
resolved "https://registry.yarnpkg.com/serve-static/-/serve-static-1.16.2.tgz#b6a5343da47f6bdd2673848bf45754941e803296"
5686+
integrity sha512-VqpjJZKadQB/PEbEwvFdO43Ax5dFBZ2UECszz8bQ7pi7wt//PWe1P6MN7eCnjsatYtBT6EuiClbjSWP2WrIoTw==
57135687
dependencies:
5714-
encodeurl "~1.0.2"
5688+
encodeurl "~2.0.0"
57155689
escape-html "~1.0.3"
57165690
parseurl "~1.3.3"
5717-
send "0.18.0"
5691+
send "0.19.0"
57185692

57195693
set-function-length@^1.2.1:
57205694
version "1.2.2"

0 commit comments

Comments
 (0)