Browse Source

Fix jpeg-js vulnerability reported by Dependabot (#24638)

Ondřej Španěl 2 years ago
parent
commit
177e15f0f7
3 changed files with 26 additions and 21 deletions
  1. 2 2
      package-lock.json
  2. 19 19
      test/package-lock.json
  3. 5 0
      test/package.json

+ 2 - 2
package-lock.json

@@ -1,12 +1,12 @@
 {
 {
   "name": "three",
   "name": "three",
-  "version": "0.143.0",
+  "version": "0.144.0",
   "lockfileVersion": 2,
   "lockfileVersion": 2,
   "requires": true,
   "requires": true,
   "packages": {
   "packages": {
     "": {
     "": {
       "name": "three",
       "name": "three",
-      "version": "0.143.0",
+      "version": "0.144.0",
       "license": "MIT",
       "license": "MIT",
       "devDependencies": {
       "devDependencies": {
         "@babel/core": "^7.18.9",
         "@babel/core": "^7.18.9",

+ 19 - 19
test/package-lock.json

@@ -22,26 +22,26 @@
     },
     },
     "..": {
     "..": {
       "name": "three",
       "name": "three",
-      "version": "0.142.0",
+      "version": "0.144.0",
       "license": "MIT",
       "license": "MIT",
       "devDependencies": {
       "devDependencies": {
-        "@babel/core": "^7.18.2",
-        "@babel/eslint-parser": "^7.18.2",
-        "@babel/plugin-proposal-class-properties": "^7.17.12",
-        "@babel/preset-env": "^7.18.2",
+        "@babel/core": "^7.18.9",
+        "@babel/eslint-parser": "^7.18.9",
+        "@babel/plugin-proposal-class-properties": "^7.18.6",
+        "@babel/preset-env": "^7.18.9",
         "@rollup/plugin-babel": "^5.3.1",
         "@rollup/plugin-babel": "^5.3.1",
         "@rollup/plugin-node-resolve": "^13.3.0",
         "@rollup/plugin-node-resolve": "^13.3.0",
         "chalk": "^5.0.1",
         "chalk": "^5.0.1",
-        "concurrently": "^7.2.1",
-        "eslint": "^8.16.0",
+        "concurrently": "^7.3.0",
+        "eslint": "^8.20.0",
         "eslint-config-mdcs": "^5.0.0",
         "eslint-config-mdcs": "^5.0.0",
         "eslint-plugin-compat": "^4.0.2",
         "eslint-plugin-compat": "^4.0.2",
-        "eslint-plugin-html": "^6.2.0",
+        "eslint-plugin-html": "^7.1.0",
         "eslint-plugin-import": "^2.26.0",
         "eslint-plugin-import": "^2.26.0",
-        "rollup": "^2.75.0",
+        "rollup": "^2.77.2",
         "rollup-plugin-filesize": "^9.1.2",
         "rollup-plugin-filesize": "^9.1.2",
         "rollup-plugin-terser": "^7.0.2",
         "rollup-plugin-terser": "^7.0.2",
-        "rollup-plugin-visualizer": "^5.6.0",
+        "rollup-plugin-visualizer": "^5.7.1",
         "servez": "^1.14.1"
         "servez": "^1.14.1"
       }
       }
     },
     },
@@ -2905,23 +2905,23 @@
     "three": {
     "three": {
       "version": "file:..",
       "version": "file:..",
       "requires": {
       "requires": {
-        "@babel/core": "^7.18.2",
-        "@babel/eslint-parser": "^7.18.2",
-        "@babel/plugin-proposal-class-properties": "^7.17.12",
-        "@babel/preset-env": "^7.18.2",
+        "@babel/core": "^7.18.9",
+        "@babel/eslint-parser": "^7.18.9",
+        "@babel/plugin-proposal-class-properties": "^7.18.6",
+        "@babel/preset-env": "^7.18.9",
         "@rollup/plugin-babel": "^5.3.1",
         "@rollup/plugin-babel": "^5.3.1",
         "@rollup/plugin-node-resolve": "^13.3.0",
         "@rollup/plugin-node-resolve": "^13.3.0",
         "chalk": "^5.0.1",
         "chalk": "^5.0.1",
-        "concurrently": "^7.2.1",
-        "eslint": "^8.16.0",
+        "concurrently": "^7.3.0",
+        "eslint": "^8.20.0",
         "eslint-config-mdcs": "^5.0.0",
         "eslint-config-mdcs": "^5.0.0",
         "eslint-plugin-compat": "^4.0.2",
         "eslint-plugin-compat": "^4.0.2",
-        "eslint-plugin-html": "^6.2.0",
+        "eslint-plugin-html": "^7.1.0",
         "eslint-plugin-import": "^2.26.0",
         "eslint-plugin-import": "^2.26.0",
-        "rollup": "^2.75.0",
+        "rollup": "^2.77.2",
         "rollup-plugin-filesize": "^9.1.2",
         "rollup-plugin-filesize": "^9.1.2",
         "rollup-plugin-terser": "^7.0.2",
         "rollup-plugin-terser": "^7.0.2",
-        "rollup-plugin-visualizer": "^5.6.0",
+        "rollup-plugin-visualizer": "^5.7.1",
         "servez": "^1.14.1"
         "servez": "^1.14.1"
       }
       }
     },
     },

+ 5 - 0
test/package.json

@@ -18,5 +18,10 @@
   },
   },
   "dependencies": {
   "dependencies": {
     "three": "file:.."
     "three": "file:.."
+  },
+  "overrides": {
+    "jimp": {
+      "jpeg-js": "^0.4.4"
+    }
   }
   }
 }
 }