From 7d4c6312d2ae1a963e4e148d8635333d0a6c80a6 Mon Sep 17 00:00:00 2001 From: "Peter A. Jonsson" Date: Thu, 2 May 2024 22:44:37 +0200 Subject: [PATCH] Update to node-notifier 10.0.1 This fixes CVE-2020-7789. --- package.json | 2 +- yarn.lock | 17 +++++++++-------- 2 files changed, 10 insertions(+), 9 deletions(-) diff --git a/package.json b/package.json index cda8c8144..f1753a6ff 100644 --- a/package.json +++ b/package.json @@ -63,7 +63,7 @@ "husky": "^8.0.3", "json5": "^2.1.0", "minimist": "^1.2.8", - "node-notifier": "^5.1.2", + "node-notifier": "^10.0.1", "plugin-error": "^1.0.1", "prettier": "2.7.1", "pretty-quick": "^1.10.0", diff --git a/yarn.lock b/yarn.lock index b114c393e..7a39ce9d0 100644 --- a/yarn.lock +++ b/yarn.lock @@ -8128,16 +8128,17 @@ node-libs-browser@^2.2.1: util "^0.11.0" vm-browserify "^1.0.1" -node-notifier@^5.1.2: - version "5.4.5" - resolved "https://registry.yarnpkg.com/node-notifier/-/node-notifier-5.4.5.tgz#0cbc1a2b0f658493b4025775a13ad938e96091ef" - integrity sha512-tVbHs7DyTLtzOiN78izLA85zRqB9NvEXkAf014Vx3jtSvn/xBl6bR8ZYifj+dFcFrKI21huSQgJZ6ZtL3B4HfQ== +node-notifier@^10.0.1: + version "10.0.1" + resolved "https://registry.yarnpkg.com/node-notifier/-/node-notifier-10.0.1.tgz#0e82014a15a8456c4cfcdb25858750399ae5f1c7" + integrity sha512-YX7TSyDukOZ0g+gmzjB6abKu+hTGvO8+8+gIFDsRCU2t8fLV/P2unmt+LGFaIa4y64aX98Qksa97rgz4vMNeLQ== dependencies: growly "^1.3.0" - is-wsl "^1.1.0" - semver "^5.5.0" + is-wsl "^2.2.0" + semver "^7.3.5" shellwords "^0.1.1" - which "^1.3.0" + uuid "^8.3.2" + which "^2.0.2" node-notifier@^8.0.2: version "8.0.2" @@ -12108,7 +12109,7 @@ which-typed-array@^1.1.14, which-typed-array@^1.1.15, which-typed-array@^1.1.2, gopd "^1.0.1" has-tostringtag "^1.0.2" -which@^1.2.14, which@^1.2.9, which@^1.3.0, which@^1.3.1: +which@^1.2.14, which@^1.2.9, which@^1.3.1: version "1.3.1" resolved "https://registry.yarnpkg.com/which/-/which-1.3.1.tgz#a45043d54f5805316da8d62f9f50918d3da70b0a" integrity sha512-HxJdYWq1MTIQbJ3nw0cqssHoTNU267KlrDuGZ1WYlxDStUtKUhOaJmh112/TZmHxxUfuJqPXSOm7tDyas0OSIQ==