From 313acf9c2f1441987770e2820486255978c6ba6a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 27 Dec 2023 19:39:35 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AXIOS-6124857 --- package-lock.json | 83 ++++++++++++----------------------------------- package.json | 4 +-- 2 files changed, 22 insertions(+), 65 deletions(-) diff --git a/package-lock.json b/package-lock.json index 13af43c..81ff0fc 100644 --- a/package-lock.json +++ b/package-lock.json @@ -11,10 +11,10 @@ "dependencies": { "@google-cloud/pubsub": "^3.7.1", "@google-cloud/storage": "^6.11.0", - "@googlemaps/google-maps-services-js": "^3.3.33", + "@googlemaps/google-maps-services-js": "^3.3.40", "@hokify/agenda": "^6.3.0", "@types/morgan": "^1.9.4", - "axios": "^1.4.0", + "axios": "^1.6.3", "bcryptjs": "^2.4.3", "clean-deep": "^3.4.0", "compression": "^1.7.4", @@ -2135,37 +2135,15 @@ } }, "node_modules/@googlemaps/google-maps-services-js": { - "version": "3.3.33", - "resolved": "https://registry.npmjs.org/@googlemaps/google-maps-services-js/-/google-maps-services-js-3.3.33.tgz", - "integrity": "sha512-+2RLUbJVTUicx+Ky0Qr/fi02t6KvdhLgjnFtEc1mGefoKNnhEYGYZWcfne/aqozGkH0Ybe2IcxvUR0w+l5OgDw==", + "version": "3.3.40", + "resolved": "https://registry.npmjs.org/@googlemaps/google-maps-services-js/-/google-maps-services-js-3.3.40.tgz", + "integrity": "sha512-hLDt3zp3WD1Vc4ZcZF64FxiYnGo9BakGst7891PBJd+9Hifv8IWOlbwIhBedzj8hPk0LEe+DOR2CEP+WwK4Gjg==", "dependencies": { "@googlemaps/url-signature": "^1.0.4", "agentkeepalive": "^4.1.0", - "axios": "^0.27.2", - "query-string": "^7.1.3", - "retry-axios": "^2.6.0" - } - }, - "node_modules/@googlemaps/google-maps-services-js/node_modules/axios": { - "version": "0.27.2", - "resolved": "https://registry.npmjs.org/axios/-/axios-0.27.2.tgz", - "integrity": "sha512-t+yRIyySRTp/wua5xEr+z1q60QmLq8ABsS5O9Me1AsE5dfKqgnCFzwiCZZ/cGNd1lq4/7akDWMxdhVlucjmnOQ==", - "dependencies": { - "follow-redirects": "^1.14.9", - "form-data": "^4.0.0" - } - }, - "node_modules/@googlemaps/google-maps-services-js/node_modules/form-data": { - "version": "4.0.0", - "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.0.tgz", - "integrity": "sha512-ETEklSGi5t0QMZuiXoA/Q6vcnxcLQP5vdugSpuAyi6SVGi2clPPp+xgEhuMaHC+zGgn31Kd235W35f7Hykkaww==", - "dependencies": { - "asynckit": "^0.4.0", - "combined-stream": "^1.0.8", - "mime-types": "^2.1.12" - }, - "engines": { - "node": ">= 6" + "axios": "^1.5.1", + "query-string": "<8.x", + "retry-axios": "<3.x" } }, "node_modules/@googlemaps/url-signature": { @@ -3998,9 +3976,9 @@ "integrity": "sha512-NmWvPnx0F1SfrQbYwOi7OeaNGokp9XhzNioJ/CSBs8Qa4vxug81mhJEAVZwxXuBmYB5KDRfMq/F3RR0BIU7sWg==" }, "node_modules/axios": { - "version": "1.4.0", - "resolved": "https://registry.npmjs.org/axios/-/axios-1.4.0.tgz", - "integrity": "sha512-S4XCWMEmzvo64T9GfvQDOXgYRDJ/wsSZc7Jvdgx5u1sd0JwsuPLqb3SYmusag+edF6ziyMensPVqLTSc1PiSEA==", + "version": "1.6.3", + "resolved": "https://registry.npmjs.org/axios/-/axios-1.6.3.tgz", + "integrity": "sha512-fWyNdeawGam70jXSVlKl+SUNVcL6j6W79CuSIPfi6HnDUmSCH6gyUys/HrqHeA/wU0Az41rRgean494d0Jb+ww==", "dependencies": { "follow-redirects": "^1.15.0", "form-data": "^4.0.0", @@ -15262,36 +15240,15 @@ } }, "@googlemaps/google-maps-services-js": { - "version": "3.3.33", - "resolved": "https://registry.npmjs.org/@googlemaps/google-maps-services-js/-/google-maps-services-js-3.3.33.tgz", - "integrity": "sha512-+2RLUbJVTUicx+Ky0Qr/fi02t6KvdhLgjnFtEc1mGefoKNnhEYGYZWcfne/aqozGkH0Ybe2IcxvUR0w+l5OgDw==", + "version": "3.3.40", + "resolved": "https://registry.npmjs.org/@googlemaps/google-maps-services-js/-/google-maps-services-js-3.3.40.tgz", + "integrity": "sha512-hLDt3zp3WD1Vc4ZcZF64FxiYnGo9BakGst7891PBJd+9Hifv8IWOlbwIhBedzj8hPk0LEe+DOR2CEP+WwK4Gjg==", "requires": { "@googlemaps/url-signature": "^1.0.4", "agentkeepalive": "^4.1.0", - "axios": "^0.27.2", - "query-string": "^7.1.3", - "retry-axios": "^2.6.0" - }, - "dependencies": { - "axios": { - "version": "0.27.2", - "resolved": "https://registry.npmjs.org/axios/-/axios-0.27.2.tgz", - "integrity": "sha512-t+yRIyySRTp/wua5xEr+z1q60QmLq8ABsS5O9Me1AsE5dfKqgnCFzwiCZZ/cGNd1lq4/7akDWMxdhVlucjmnOQ==", - "requires": { - "follow-redirects": "^1.14.9", - "form-data": "^4.0.0" - } - }, - "form-data": { - "version": "4.0.0", - "resolved": "https://registry.npmjs.org/form-data/-/form-data-4.0.0.tgz", - "integrity": "sha512-ETEklSGi5t0QMZuiXoA/Q6vcnxcLQP5vdugSpuAyi6SVGi2clPPp+xgEhuMaHC+zGgn31Kd235W35f7Hykkaww==", - "requires": { - "asynckit": "^0.4.0", - "combined-stream": "^1.0.8", - "mime-types": "^2.1.12" - } - } + "axios": "^1.5.1", + "query-string": "<8.x", + "retry-axios": "<3.x" } }, "@googlemaps/url-signature": { @@ -16800,9 +16757,9 @@ "integrity": "sha512-NmWvPnx0F1SfrQbYwOi7OeaNGokp9XhzNioJ/CSBs8Qa4vxug81mhJEAVZwxXuBmYB5KDRfMq/F3RR0BIU7sWg==" }, "axios": { - "version": "1.4.0", - "resolved": "https://registry.npmjs.org/axios/-/axios-1.4.0.tgz", - "integrity": "sha512-S4XCWMEmzvo64T9GfvQDOXgYRDJ/wsSZc7Jvdgx5u1sd0JwsuPLqb3SYmusag+edF6ziyMensPVqLTSc1PiSEA==", + "version": "1.6.3", + "resolved": "https://registry.npmjs.org/axios/-/axios-1.6.3.tgz", + "integrity": "sha512-fWyNdeawGam70jXSVlKl+SUNVcL6j6W79CuSIPfi6HnDUmSCH6gyUys/HrqHeA/wU0Az41rRgean494d0Jb+ww==", "requires": { "follow-redirects": "^1.15.0", "form-data": "^4.0.0", diff --git a/package.json b/package.json index 2619157..038869f 100644 --- a/package.json +++ b/package.json @@ -57,10 +57,10 @@ "dependencies": { "@google-cloud/pubsub": "^3.7.1", "@google-cloud/storage": "^6.11.0", - "@googlemaps/google-maps-services-js": "^3.3.33", + "@googlemaps/google-maps-services-js": "^3.3.40", "@hokify/agenda": "^6.3.0", "@types/morgan": "^1.9.4", - "axios": "^1.4.0", + "axios": "^1.6.3", "bcryptjs": "^2.4.3", "clean-deep": "^3.4.0", "compression": "^1.7.4",