From 833f4b13ec6577c48255316d2fddc119c6832e8b Mon Sep 17 00:00:00 2001 From: Joe Lust Date: Thu, 7 Jan 2021 10:22:14 -0500 Subject: [PATCH] [IST-90] Upgrade Axios to address CVE-2020-28168 (#32) --- package-lock.json | 50 ++++++++++++++++++++++++++--------------------- package.json | 6 +++--- 2 files changed, 31 insertions(+), 25 deletions(-) diff --git a/package-lock.json b/package-lock.json index ee1508b5..acaf392e 100644 --- a/package-lock.json +++ b/package-lock.json @@ -443,9 +443,9 @@ } }, "axios": { - "version": "0.20.0", - "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/axios/-/axios-0.20.0.tgz", - "integrity": "sha1-BXujDwSIRpSZOozQf6OUz/EcUL0=", + "version": "0.21.1", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/axios/-/axios-0.21.1.tgz", + "integrity": "sha1-IlY0gZYvTWvemnbVFu8OXTwJsrg=", "requires": { "follow-redirects": "^1.10.0" } @@ -1098,9 +1098,9 @@ "dev": true }, "follow-redirects": { - "version": "1.13.0", - "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/follow-redirects/-/follow-redirects-1.13.0.tgz", - "integrity": "sha1-tC6Nk6Kn7qXtiGM2dtZZe8jjhNs=" + "version": "1.13.1", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/follow-redirects/-/follow-redirects-1.13.1.tgz", + "integrity": "sha1-X2m4Ezds7k/QR0o6uoNd8Eq3Y7c=" }, "fs.realpath": { "version": "1.0.0", @@ -1477,9 +1477,9 @@ } }, "mocha": { - "version": "8.2.0", - "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/mocha/-/mocha-8.2.0.tgz", - "integrity": "sha1-+Kp5EQtLWmWAxl1N2Ag8QlKCYk4=", + "version": "8.2.1", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/mocha/-/mocha-8.2.1.tgz", + "integrity": "sha1-8vpogX7Q5TND2YnfZczTWLw6Szk=", "dev": true, "requires": { "@ungap/promise-all-settled": "1.1.2", @@ -1649,12 +1649,12 @@ } }, "p-limit": { - "version": "3.0.2", - "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/p-limit/-/p-limit-3.0.2.tgz", - "integrity": "sha1-FmTgEK88rcaBuq/T4qQ3vnsPtf4=", + "version": "3.1.0", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/p-limit/-/p-limit-3.1.0.tgz", + "integrity": "sha1-4drMvnjQ0TiMoYxk/qOOPlfjcGs=", "dev": true, "requires": { - "p-try": "^2.0.0" + "yocto-queue": "^0.1.0" } }, "p-locate": { @@ -1964,9 +1964,9 @@ } }, "safe-buffer": { - "version": "5.2.0", - "resolved": "https://registry.npmjs.org/safe-buffer/-/safe-buffer-5.2.0.tgz", - "integrity": "sha512-fZEwUGbVl7kouZs1jCdMLdt95hdIv0ZeHg6L7qPeciMZhZ+/gdesW4wgTARkrFWEpspjEATAzUGPG8N2jJiwbg==", + "version": "5.2.1", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/safe-buffer/-/safe-buffer-5.2.1.tgz", + "integrity": "sha1-Hq+fqb2x/dTsdfWPnNtOa3gn7sY=", "dev": true }, "semver": { @@ -2434,9 +2434,9 @@ } }, "y18n": { - "version": "4.0.0", - "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/y18n/-/y18n-4.0.0.tgz", - "integrity": "sha1-le+U+F7MgdAHwmThkKEg8KPIVms=", + "version": "4.0.1", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/y18n/-/y18n-4.0.1.tgz", + "integrity": "sha1-jbK4PDHF11CZu4kLI/MJSJHiR9Q=", "dev": true }, "yargs": { @@ -2551,9 +2551,9 @@ }, "dependencies": { "camelcase": { - "version": "6.1.0", - "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/camelcase/-/camelcase-6.1.0.tgz", - "integrity": "sha1-J9wXYXNyX7Ct+KSLZH9NeHGUTXg=", + "version": "6.2.0", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/camelcase/-/camelcase-6.2.0.tgz", + "integrity": "sha1-kkr4gcnVJaydh/QNlk5c6pgqGAk=", "dev": true }, "decamelize": { @@ -2563,6 +2563,12 @@ "dev": true } } + }, + "yocto-queue": { + "version": "0.1.0", + "resolved": "https://longreen.jfrog.io/longreen/api/npm/npm/yocto-queue/-/yocto-queue-0.1.0.tgz", + "integrity": "sha1-ApTrPe4FAo0x7hpfosVWpqrxChs=", + "dev": true } } } diff --git a/package.json b/package.json index 5fa943ed..df953b7b 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "mabl-github-deployments-action", - "version": "1.6.0", + "version": "1.7.0", "description": "mabl github action for GitHub pipelines integration", "main": "lib/index.js", "scripts": { @@ -19,7 +19,7 @@ "@actions/core": "^1.2.6", "@actions/github": "^4.0.0", "async-retry": "^1.2.3", - "axios": "^0.20.0", + "axios": "^0.21.1", "cli-table3": "^0.5.1", "moment": "^2.24.0" }, @@ -33,7 +33,7 @@ "eslint-plugin-import": "^2.22.1", "eslint-plugin-jsdoc": "^30.7.3", "eslint-plugin-no-null": "^1.0.2", - "mocha": "^8.2.0", + "mocha": "^8.2.1", "prettier": "^2.1.2", "typescript": "^4.0.3" }