Skip to content

Commit e13ac36

Browse files
andres-valdesjaredpalmer
authored andcommitted
upgrade nodemon to address flatmap-stream vulnerability (#153)
1 parent 32d151d commit e13ac36

File tree

2 files changed

+14
-67
lines changed

2 files changed

+14
-67
lines changed

packages/backpack-core/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,10 +18,10 @@
1818
"cross-spawn": "^5.0.1",
1919
"friendly-errors-webpack-plugin": "^1.7.0",
2020
"json-loader": "^0.5.7",
21-
"nodemon": "^1.11.0",
21+
"nodemon": "^1.18.7",
2222
"ramda": "^0.23.0",
2323
"source-map-support": "^0.4.15",
2424
"webpack": "^4.23.1",
2525
"webpack-node-externals": "^1.7.2"
2626
}
27-
}
27+
}

yarn.lock

Lines changed: 12 additions & 65 deletions
Original file line numberDiff line numberDiff line change
@@ -2469,7 +2469,7 @@ duplexer3@^0.1.4:
24692469
resolved "https://registry.yarnpkg.com/duplexer3/-/duplexer3-0.1.4.tgz#ee01dd1cac0ed3cbc7fdbea37dc0a8f1ce002ce2"
24702470
integrity sha1-7gHdHKwO08vH/b6jfcCo8c4ALOI=
24712471

2472-
duplexer@^0.1.1, duplexer@~0.1.1:
2472+
duplexer@^0.1.1:
24732473
version "0.1.1"
24742474
resolved "https://registry.yarnpkg.com/duplexer/-/duplexer-0.1.1.tgz#ace6ff808c1ce66b57d1ebf97977acb02334cfc1"
24752475
integrity sha1-rOb/gIwc5mtX0ev5eXessCM0z8E=
@@ -2654,20 +2654,6 @@ etag@~1.8.1:
26542654
resolved "https://registry.yarnpkg.com/etag/-/etag-1.8.1.tgz#41ae2eeb65efa62268aebfea83ac7d79299b0887"
26552655
integrity sha1-Qa4u62XvpiJorr/qg6x9eSmbCIc=
26562656

2657-
event-stream@~3.3.0:
2658-
version "3.3.6"
2659-
resolved "https://registry.yarnpkg.com/event-stream/-/event-stream-3.3.6.tgz#cac1230890e07e73ec9cacd038f60a5b66173eef"
2660-
integrity sha512-dGXNg4F/FgVzlApjzItL+7naHutA3fDqbV/zAZqDDlXTjiMnQmZKu+prImWKszeBM5UQeGvAl3u1wBiKeDh61g==
2661-
dependencies:
2662-
duplexer "^0.1.1"
2663-
flatmap-stream "^0.1.0"
2664-
from "^0.1.7"
2665-
map-stream "0.0.7"
2666-
pause-stream "^0.0.11"
2667-
split "^1.0.1"
2668-
stream-combiner "^0.2.2"
2669-
through "^2.3.8"
2670-
26712657
events@^1.0.0:
26722658
version "1.1.1"
26732659
resolved "https://registry.yarnpkg.com/events/-/events-1.1.1.tgz#9ebdb7635ad099c70dcc4c2a1f5004288e8bd924"
@@ -2959,11 +2945,6 @@ find-up@^2.0.0, find-up@^2.1.0:
29592945
dependencies:
29602946
locate-path "^2.0.0"
29612947

2962-
flatmap-stream@^0.1.0:
2963-
version "0.1.1"
2964-
resolved "https://registry.yarnpkg.com/flatmap-stream/-/flatmap-stream-0.1.1.tgz#d34f39ef3b9aa5a2fc225016bd3adf28ac5ae6ea"
2965-
integrity sha512-lAq4tLbm3sidmdCN8G3ExaxH7cUCtP5mgDvrYowsx84dcYkJJ4I28N7gkxA6+YlSXzaGLJYIDEi9WGfXzMiXdw==
2966-
29672948
flow-bin@^0.37.4:
29682949
version "0.37.4"
29692950
resolved "https://registry.yarnpkg.com/flow-bin/-/flow-bin-0.37.4.tgz#3d8da2ef746e80e730d166e09040f4198969b76b"
@@ -3051,11 +3032,6 @@ from2@^2.1.0:
30513032
inherits "^2.0.1"
30523033
readable-stream "^2.0.0"
30533034

3054-
from@^0.1.7:
3055-
version "0.1.7"
3056-
resolved "https://registry.yarnpkg.com/from/-/from-0.1.7.tgz#83c60afc58b9c56997007ed1a768b3ab303a44fe"
3057-
integrity sha1-g8YK/Fi5xWmXAH7Rp2izqzA6RP4=
3058-
30593035
fs-extra@^4.0.1:
30603036
version "4.0.3"
30613037
resolved "https://registry.yarnpkg.com/fs-extra/-/fs-extra-4.0.3.tgz#0d852122e5bc5beb453fb028e9c0c9bf36340c94"
@@ -4652,11 +4628,6 @@ map-obj@^2.0.0:
46524628
resolved "https://registry.yarnpkg.com/map-obj/-/map-obj-2.0.0.tgz#a65cd29087a92598b8791257a523e021222ac1f9"
46534629
integrity sha1-plzSkIepJZi4eRJXpSPgISIqwfk=
46544630

4655-
map-stream@0.0.7:
4656-
version "0.0.7"
4657-
resolved "https://registry.yarnpkg.com/map-stream/-/map-stream-0.0.7.tgz#8a1f07896d82b10926bd3744a2420009f88974a8"
4658-
integrity sha1-ih8HiW2CsQkmvTdEokIACfiJdKg=
4659-
46604631
map-visit@^1.0.0:
46614632
version "1.0.0"
46624633
resolved "https://registry.yarnpkg.com/map-visit/-/map-visit-1.0.0.tgz#ecdca8f13144e660f1b5bd41f12f3479d98dfb8f"
@@ -5065,16 +5036,16 @@ node-releases@^1.0.1:
50655036
dependencies:
50665037
semver "^5.3.0"
50675038

5068-
nodemon@^1.11.0:
5069-
version "1.18.5"
5070-
resolved "https://registry.yarnpkg.com/nodemon/-/nodemon-1.18.5.tgz#3d3924df23d06806952e8b6d3de052f2a3351807"
5071-
integrity sha512-8806dC8dfBlbxQmqNOSEeay/qlbddKvFzxIGNxnPtxUlTtH77xsrC66RnA3M47HCSgMgE5bj+U586o50RowXBg==
5039+
nodemon@^1.18.7:
5040+
version "1.18.7"
5041+
resolved "https://registry.yarnpkg.com/nodemon/-/nodemon-1.18.7.tgz#716b66bf3e89ac4fcfb38a9e61887a03fc82efbb"
5042+
integrity sha512-xuC1V0F5EcEyKQ1VhHYD13owznQbUw29JKvZ8bVH7TmuvVNHvvbp9pLgE4PjTMRJVe0pJ8fGRvwR2nMiosIsPQ==
50725043
dependencies:
50735044
chokidar "^2.0.4"
50745045
debug "^3.1.0"
50755046
ignore-by-default "^1.0.1"
50765047
minimatch "^3.0.4"
5077-
pstree.remy "^1.1.0"
5048+
pstree.remy "^1.1.2"
50785049
semver "^5.5.0"
50795050
supports-color "^5.2.0"
50805051
touch "^3.1.0"
@@ -5454,13 +5425,6 @@ path-type@^3.0.0:
54545425
dependencies:
54555426
pify "^3.0.0"
54565427

5457-
pause-stream@^0.0.11:
5458-
version "0.0.11"
5459-
resolved "https://registry.yarnpkg.com/pause-stream/-/pause-stream-0.0.11.tgz#fe5a34b0cbce12b5aa6a2b403ee2e73b602f1445"
5460-
integrity sha1-/lo0sMvOErWqaitAPuLnO2AvFEU=
5461-
dependencies:
5462-
through "~2.3"
5463-
54645428
pbkdf2@^3.0.3:
54655429
version "3.0.17"
54665430
resolved "https://registry.yarnpkg.com/pbkdf2/-/pbkdf2-3.0.17.tgz#976c206530617b14ebb32114239f7b09336e93a6"
@@ -5580,13 +5544,6 @@ prr@~1.0.1:
55805544
resolved "https://registry.yarnpkg.com/prr/-/prr-1.0.1.tgz#d3fc114ba06995a45ec6893f484ceb1d78f5f476"
55815545
integrity sha1-0/wRS6BplaRexok/SEzrHXj19HY=
55825546

5583-
ps-tree@^1.1.0:
5584-
version "1.1.0"
5585-
resolved "https://registry.yarnpkg.com/ps-tree/-/ps-tree-1.1.0.tgz#b421b24140d6203f1ed3c76996b4427b08e8c014"
5586-
integrity sha1-tCGyQUDWID8e08dplrRCewjowBQ=
5587-
dependencies:
5588-
event-stream "~3.3.0"
5589-
55905547
pseudomap@^1.0.2:
55915548
version "1.0.2"
55925549
resolved "https://registry.yarnpkg.com/pseudomap/-/pseudomap-1.0.2.tgz#f052a28da70e618917ef0a8ac34c1ae5a68286b3"
@@ -5597,12 +5554,10 @@ psl@^1.1.24:
55975554
resolved "https://registry.yarnpkg.com/psl/-/psl-1.1.29.tgz#60f580d360170bb722a797cc704411e6da850c67"
55985555
integrity sha512-AeUmQ0oLN02flVHXWh9sSJF7mcdFq0ppid/JkErufc3hGIV/AMa8Fo9VgDo/cT2jFdOWoFvHp90qqBH54W+gjQ==
55995556

5600-
pstree.remy@^1.1.0:
5601-
version "1.1.0"
5602-
resolved "https://registry.yarnpkg.com/pstree.remy/-/pstree.remy-1.1.0.tgz#f2af27265bd3e5b32bbfcc10e80bac55ba78688b"
5603-
integrity sha512-q5I5vLRMVtdWa8n/3UEzZX7Lfghzrg9eG2IKk2ENLSofKRCXVqMvMUHxCKgXNaqH/8ebhBxrqftHWnyTFweJ5Q==
5604-
dependencies:
5605-
ps-tree "^1.1.0"
5557+
pstree.remy@^1.1.2:
5558+
version "1.1.2"
5559+
resolved "https://registry.yarnpkg.com/pstree.remy/-/pstree.remy-1.1.2.tgz#4448bbeb4b2af1fed242afc8dc7416a6f504951a"
5560+
integrity sha512-vL6NLxNHzkNTjGJUpMm5PLC+94/0tTlC1vkP9bdU0pOHih+EujMjgMTwfZopZvHWRFbqJ5Y73OMoau50PewDDA==
56065561

56075562
public-encrypt@^4.0.0:
56085563
version "4.0.3"
@@ -6365,7 +6320,7 @@ split2@^2.0.0:
63656320
dependencies:
63666321
through2 "^2.0.2"
63676322

6368-
split@^1.0.0, split@^1.0.1:
6323+
split@^1.0.0:
63696324
version "1.0.1"
63706325
resolved "https://registry.yarnpkg.com/split/-/split-1.0.1.tgz#605bd9be303aa59fb35f9229fbea0ddec9ea07d9"
63716326
integrity sha512-mTyOoPbrivtXnwnIxZRFYRrPNtEFKlpB2fvjSnCQUiAA6qAZzqwna5envK4uk6OIeP17CsdF3rSBGYVBsU0Tkg==
@@ -6440,14 +6395,6 @@ stream-browserify@^2.0.1:
64406395
inherits "~2.0.1"
64416396
readable-stream "^2.0.2"
64426397

6443-
stream-combiner@^0.2.2:
6444-
version "0.2.2"
6445-
resolved "https://registry.yarnpkg.com/stream-combiner/-/stream-combiner-0.2.2.tgz#aec8cbac177b56b6f4fa479ced8c1912cee52858"
6446-
integrity sha1-rsjLrBd7Vrb0+kec7YwZEs7lKFg=
6447-
dependencies:
6448-
duplexer "~0.1.1"
6449-
through "~2.3.4"
6450-
64516398
stream-each@^1.1.0:
64526399
version "1.2.3"
64536400
resolved "https://registry.yarnpkg.com/stream-each/-/stream-each-1.2.3.tgz#ebe27a0c389b04fbcc233642952e10731afa9bae"
@@ -6695,7 +6642,7 @@ through2@^2.0.0, through2@^2.0.2:
66956642
readable-stream "^2.1.5"
66966643
xtend "~4.0.1"
66976644

6698-
through@2, "through@>=2.2.7 <3", through@^2.3.4, through@^2.3.6, through@^2.3.8, through@~2.3, through@~2.3.4:
6645+
through@2, "through@>=2.2.7 <3", through@^2.3.4, through@^2.3.6:
66996646
version "2.3.8"
67006647
resolved "https://registry.yarnpkg.com/through/-/through-2.3.8.tgz#0dd4c9ffaabc357960b1b724115d7e0e86a2e1f5"
67016648
integrity sha1-DdTJ/6q8NXlgsbckEV1+Doai4fU=

0 commit comments

Comments
 (0)