From 1b72c1eb365061f8f187515debc11733a6faa2c1 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 6 Nov 2023 11:49:09 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-CRYPTOJS-6028119 --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index cc093488e..673613525 100644 --- a/package-lock.json +++ b/package-lock.json @@ -25,7 +25,7 @@ "base32-encode": "^1.2.0", "bulma": "^0.9.4", "core-js": "^3.33.1", - "crypto-js": "4.1.1", + "crypto-js": "^4.2.0", "ethers": "^5.7.2", "hashconnect": "^0.1.10", "vue": "^3.3.4", @@ -7056,9 +7056,9 @@ "integrity": "sha512-UUqiVJ2gUuZFmbFsKmud3uuLcNP2+Opt+5ysmljycFCyhA0+T16XJmo1ev/t5kMChMqWh7IEvURNCqsg+SjZGQ==" }, "node_modules/crypto-js": { - "version": "4.1.1", - "resolved": "https://registry.npmjs.org/crypto-js/-/crypto-js-4.1.1.tgz", - "integrity": "sha512-o2JlM7ydqd3Qk9CA0L4NL6mTzU2sdx96a+oOfPu8Mkl/PK51vSyoi8/rQ8NknZtk44vq15lmhAj9CIAGwgeWKw==" + "version": "4.2.0", + "resolved": "https://registry.npmjs.org/crypto-js/-/crypto-js-4.2.0.tgz", + "integrity": "sha512-KALDyEYgpY+Rlob/iriUtjV6d5Eq+Y191A5g4UqLAi8CyGP9N1+FdVbkc1SxKc2r4YAYqG8JzO2KGL+AizD70Q==" }, "node_modules/cssesc": { "version": "3.0.0", diff --git a/package.json b/package.json index 419e50dfe..f1d798bf2 100644 --- a/package.json +++ b/package.json @@ -36,7 +36,7 @@ "base32-encode": "^1.2.0", "bulma": "^0.9.4", "core-js": "^3.33.1", - "crypto-js": "4.1.1", + "crypto-js": "4.2.0", "ethers": "^5.7.2", "hashconnect": "^0.1.10", "vue": "^3.3.4",