From 1c71004f4956f3114040b82ac000d24cc296d917 Mon Sep 17 00:00:00 2001 From: CatSkald Date: Sun, 5 Jun 2022 12:27:39 +0200 Subject: [PATCH] Fix vulnerability: Temp fix until https://github.com/expressjs/multer/pull/1097 is merged. --- package.json | 4 ++-- yarn.lock | 50 +++++++------------------------------------------- 2 files changed, 9 insertions(+), 45 deletions(-) diff --git a/package.json b/package.json index 69219891..a2acc405 100644 --- a/package.json +++ b/package.json @@ -29,10 +29,10 @@ "async": "^3.2.3", "autoprefixer": "^10.4.7", "browserslist": "^4.20.3", + "busboy": "^1.6.0", "codemirror": "^5.65.5", "cross-fetch": "^3.1.5", "devcert": "^1.2.1", - "dicer": "^0.3.1", "gatsby": "^4.15.2", "gatsby-image": "^3.11.0", "gatsby-plugin-catch-links": "^4.15.0", @@ -101,8 +101,8 @@ "ansi-html": "^0.0.9", "async": "^3.2.3", "browserslist": "^4.20.3", + "busboy": "^1.6.0", "devcert": "^1.2.1", - "dicer": "^0.3.1", "immer": "^9.0.14", "lodash": "^4.17.21", "node-fetch": "^2.6.7", diff --git a/yarn.lock b/yarn.lock index f3738f3d..6259b921 100644 --- a/yarn.lock +++ b/yarn.lock @@ -6299,13 +6299,12 @@ __metadata: languageName: node linkType: hard -"busboy@npm:^0.2.11": - version: 0.2.14 - resolution: "busboy@npm:0.2.14" +"busboy@npm:^1.6.0": + version: 1.6.0 + resolution: "busboy@npm:1.6.0" dependencies: - dicer: 0.2.5 - readable-stream: 1.1.x - checksum: 9df9fca6d96dab9edd03f568bde31f215794e6fabd73c75d2b39a4be2e8b73a45121d987dea5db881f3fb499737c261b372106fe72d08b8db92afaed8d751165 + streamsearch: ^1.1.0 + checksum: 32801e2c0164e12106bf236291a00795c3c4e4b709ae02132883fe8478ba2ae23743b11c5735a0aae8afe65ac4b6ca4568b91f0d9fed1fdbc32ede824a73746e languageName: node linkType: hard @@ -6534,11 +6533,11 @@ __metadata: babel-jest: ^28.1.0 babel-preset-gatsby: ^2.15.0 browserslist: ^4.20.3 + busboy: ^1.6.0 codemirror: ^5.65.5 core-js: ^3.22.8 cross-fetch: ^3.1.5 devcert: ^1.2.1 - dicer: ^0.3.1 eslint: ^8.17.0 eslint-config-prettier: ^8.5.0 eslint-config-react-app: ^7.0.1 @@ -8035,15 +8034,6 @@ __metadata: languageName: node linkType: hard -"dicer@npm:^0.3.1": - version: 0.3.1 - resolution: "dicer@npm:0.3.1" - dependencies: - streamsearch: ^1.1.0 - checksum: 9f3b11f8b7965f47624a9b09f96ba05e3bad2a0f3957a7ede07ae032eda16739ffa665c260e3eba20bd9751abf83202803e29df0f30ef4cbb164eef749a2a84d - languageName: node - linkType: hard - "diff-sequences@npm:^28.0.2": version: 28.0.2 resolution: "diff-sequences@npm:28.0.2" @@ -11838,7 +11828,7 @@ __metadata: languageName: node linkType: hard -"inherits@npm:2, inherits@npm:2.0.4, inherits@npm:^2.0.0, inherits@npm:^2.0.1, inherits@npm:^2.0.3, inherits@npm:^2.0.4, inherits@npm:~2.0.1, inherits@npm:~2.0.3": +"inherits@npm:2, inherits@npm:2.0.4, inherits@npm:^2.0.0, inherits@npm:^2.0.1, inherits@npm:^2.0.3, inherits@npm:^2.0.4, inherits@npm:~2.0.3": version: 2.0.4 resolution: "inherits@npm:2.0.4" checksum: 4a48a733847879d6cf6691860a6b1e3f0f4754176e4d71494c41f3475553768b10f84b5ce1d40fbd0e34e6bfbb864ee35858ad4dd2cf31e02fc4a154b724d7f1 @@ -12452,13 +12442,6 @@ __metadata: languageName: node linkType: hard -"isarray@npm:0.0.1": - version: 0.0.1 - resolution: "isarray@npm:0.0.1" - checksum: 49191f1425681df4a18c2f0f93db3adb85573bcdd6a4482539d98eac9e705d8961317b01175627e860516a2fc45f8f9302db26e5a380a97a520e272e2a40a8d4 - languageName: node - linkType: hard - "isarray@npm:~1.0.0": version: 1.0.0 resolution: "isarray@npm:1.0.0" @@ -16961,18 +16944,6 @@ __metadata: languageName: node linkType: hard -"readable-stream@npm:1.1.x": - version: 1.1.14 - resolution: "readable-stream@npm:1.1.14" - dependencies: - core-util-is: ~1.0.0 - inherits: ~2.0.1 - isarray: 0.0.1 - string_decoder: ~0.10.x - checksum: 17dfeae3e909945a4a1abc5613ea92d03269ef54c49288599507fc98ff4615988a1c39a999dcf9aacba70233d9b7040bc11a5f2bfc947e262dedcc0a8b32b5a0 - languageName: node - linkType: hard - "readable-stream@npm:^2.0.1, readable-stream@npm:^2.0.6, readable-stream@npm:^2.2.2": version: 2.3.7 resolution: "readable-stream@npm:2.3.7" @@ -18517,13 +18488,6 @@ resolve@^2.0.0-next.3: languageName: node linkType: hard -"string_decoder@npm:~0.10.x": - version: 0.10.31 - resolution: "string_decoder@npm:0.10.31" - checksum: fe00f8e303647e5db919948ccb5ce0da7dea209ab54702894dd0c664edd98e5d4df4b80d6fabf7b9e92b237359d21136c95bf068b2f7760b772ca974ba970202 - languageName: node - linkType: hard - "string_decoder@npm:~1.1.1": version: 1.1.1 resolution: "string_decoder@npm:1.1.1"