Upgrade vulnerable transient dependency parse-path (#327)

* upgrade backfill-hasher and backfill

* Change files
This commit is contained in:
Max 2022-08-24 12:19:12 -04:00 коммит произвёл GitHub
Родитель 4ab17de5b8
Коммит 70f7aecc6b
Не найден ключ, соответствующий данной подписи
Идентификатор ключа GPG: 4AEE18F83AFDEB23
5 изменённых файлов: 46 добавлений и 25 удалений

Просмотреть файл

@ -0,0 +1,7 @@
{
"type": "patch",
"comment": "Update backfill & backfill-hasher",
"packageName": "@lage-run/cache",
"email": "mhuan13@gmail.com",
"dependentChangeType": "patch"
}

Просмотреть файл

@ -0,0 +1,7 @@
{
"type": "patch",
"comment": "update backfill & backfill-hasher",
"packageName": "lage",
"email": "mhuan13@gmail.com",
"dependentChangeType": "patch"
}

2
packages/cache/package.json поставляемый
Просмотреть файл

@ -19,7 +19,7 @@
"@lage-run/logger": "^1.1.2",
"backfill-config": "^6.3.0",
"backfill-cache": "^5.6.1",
"backfill-hasher": "^6.4.1",
"backfill-hasher": "^6.4.2",
"backfill-logger": "^5.1.3",
"fast-glob": "^3.2.11",
"workspace-tools": "^0.26.0"

Просмотреть файл

@ -33,7 +33,7 @@
"@lage-run/logger": "*",
"@xmldom/xmldom": "^0.8.0",
"abort-controller": "^3.0.0",
"backfill": "^6.1.20",
"backfill": "^6.1.21",
"backfill-cache": "^5.6.1",
"backfill-config": "^6.3.0",
"backfill-logger": "^5.1.3",
@ -42,7 +42,6 @@
"cosmiconfig": "^6.0.0",
"execa": "^4.0.3",
"fast-glob": "^3.2.2",
"git-url-parse": "^11.1.2",
"ioredis": "^4.28.0",
"npmlog": "^4.1.2",
"p-graph": "^1.1.1",
@ -56,7 +55,6 @@
"@types/chalk": "2.2.0",
"@types/cosmiconfig": "6.0.0",
"@types/execa": "2.0.0",
"@types/git-url-parse": "9.0.1",
"@types/ioredis": "4.28.10",
"@types/jest": "^27.0.1",
"@types/node": "^14.0.0",

Просмотреть файл

@ -2073,21 +2073,6 @@
"@jridgewell/resolve-uri" "^3.0.3"
"@jridgewell/sourcemap-codec" "^1.4.10"
"@lage-run/logger@^1.1.2":
version "1.1.2"
resolved "https://registry.yarnpkg.com/@lage-run/logger/-/logger-1.1.2.tgz#8fe60cb919260fa019a78f576ee3eb639fc9a289"
integrity sha512-izh1wWSYpvILrEk35lCnubYiJPOx+725DysFtk/EW6jk9mERzROAfei7MN1P4lz0nrt1V0PW4/acjVI9Jrzp0Q==
"@lage-run/reporters@^0.1.2":
version "0.1.2"
resolved "https://registry.yarnpkg.com/@lage-run/reporters/-/reporters-0.1.2.tgz#907bb755d33ae56b49301dcc3dc025acbaf4088a"
integrity sha512-NQvuZu0dHUMjsFf67PdMv5yXBDzm44TZaXckjmoFfW7xEQzFDIq/Q5uNmCr77JZr6eCKJlFwoKeF0rLhDDhcWQ==
dependencies:
"@lage-run/logger" "^1.1.2"
"@lage-run/scheduler" "^0.1.3"
"@lage-run/target-graph" "^0.2.0"
chalk "^4.0.0"
"@leichtgewicht/ip-codec@^2.0.1":
version "2.0.4"
resolved "https://registry.npmjs.org/@leichtgewicht/ip-codec/-/ip-codec-2.0.4.tgz"
@ -2606,11 +2591,6 @@
"@types/qs" "*"
"@types/serve-static" "*"
"@types/git-url-parse@9.0.1":
version "9.0.1"
resolved "https://registry.npmjs.org/@types/git-url-parse/-/git-url-parse-9.0.1.tgz"
integrity sha512-Zf9mY4Mz7N3Nyi341nUkOtgVUQn4j6NS4ndqEha/lOgEbTkHzpD7wZuRagYKzrXNtvawWfsrojoC1nhsQexvNA==
"@types/graceful-fs@^4.1.2", "@types/graceful-fs@^4.1.3":
version "4.1.5"
resolved "https://registry.npmjs.org/@types/graceful-fs/-/graceful-fs-4.1.5.tgz"
@ -3659,6 +3639,18 @@ backfill-hasher@^6.4.1:
fs-extra "^8.1.0"
workspace-tools "^0.18.2"
backfill-hasher@^6.4.2:
version "6.4.2"
resolved "https://registry.yarnpkg.com/backfill-hasher/-/backfill-hasher-6.4.2.tgz#bb037506d7c3197cb4a2beef29316e1c58e5ac06"
integrity sha512-nWJyk6M9ufWaJXjmeSpshK0/m0sXxWymZC4r2S/lJ35uoEfp1F4O0A3TBO5twlBp3kc6/jPiXsC2EVLmAQ5ZJA==
dependencies:
"@rushstack/package-deps-hash" "^3.2.4"
backfill-config "^6.3.0"
backfill-logger "^5.1.3"
find-up "^5.0.0"
fs-extra "^8.1.0"
workspace-tools "^0.26.3"
backfill-logger@^5.1.3:
version "5.1.3"
resolved "https://registry.npmjs.org/backfill-logger/-/backfill-logger-5.1.3.tgz"
@ -3693,6 +3685,23 @@ backfill@^6.1.20:
globby "^11.0.0"
yargs "^16.1.1"
backfill@^6.1.21:
version "6.1.21"
resolved "https://registry.yarnpkg.com/backfill/-/backfill-6.1.21.tgz#faf1151781f6a1a53c60a308645e327c96db11cd"
integrity sha512-RjY77n2zkwJJ+jjeqCA08+Kwd9C61HsBo/WDLlEstL4KKxu7WMQ2xSN7RYQMIoA4ui5MRFJsFz8QSEcewlWOtw==
dependencies:
anymatch "^3.0.3"
backfill-cache "^5.6.1"
backfill-config "^6.3.0"
backfill-hasher "^6.4.2"
backfill-logger "^5.1.3"
backfill-utils-dotenv "^5.1.1"
chokidar "^3.2.1"
execa "^4.0.0"
fs-extra "^8.1.0"
globby "^11.0.0"
yargs "^16.1.1"
bail@^1.0.0:
version "1.0.5"
resolved "https://registry.npmjs.org/bail/-/bail-1.0.5.tgz"
@ -12248,7 +12257,7 @@ workspace-tools@^0.24.0:
multimatch "^4.0.0"
read-yaml-file "^2.0.0"
workspace-tools@^0.26.0:
workspace-tools@^0.26.0, workspace-tools@^0.26.3:
version "0.26.3"
resolved "https://registry.yarnpkg.com/workspace-tools/-/workspace-tools-0.26.3.tgz#521ff930e889873eab5d223289d7136d1e9a1b42"
integrity sha512-aNnxt0rBh8CwQ6DfYn/CU1xNTKu+dwoNjZ9oddEAOogvIOMQGJ57OQ3XI7+iRZu1XfO+HK2xsQLMbZGjmAJ8UA==