From 6619b9a60d3f1adafa504b8edf094320a01fc7f8 Mon Sep 17 00:00:00 2001 From: Nick Muerdter <12112+GUI@users.noreply.github.com> Date: Mon, 9 Mar 2020 09:59:50 -0600 Subject: [PATCH] Update acorn dependency for security updates. es-check pins the acorn dependency to 6.1.1, which has a security issue: https://www.npmjs.com/advisories/1488 This updates and loosens the version constraint to a patched version. --- package.json | 2 +- yarn.lock | 9 +++++---- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index e934995..53cafe0 100644 --- a/package.json +++ b/package.json @@ -43,7 +43,7 @@ "nyc": "^14.1.1" }, "dependencies": { - "acorn": "6.1.1", + "acorn": "^6.4.1", "caporal": "1.3.0", "glob": "^7.1.2" }, diff --git a/yarn.lock b/yarn.lock index c85ea53..98ad49e 100644 --- a/yarn.lock +++ b/yarn.lock @@ -102,14 +102,15 @@ acorn-jsx@^4.1.1: dependencies: acorn "^5.0.3" -acorn@6.1.1: - version "6.1.1" - resolved "https://registry.yarnpkg.com/acorn/-/acorn-6.1.1.tgz#7d25ae05bb8ad1f9b699108e1094ecd7884adc1f" - acorn@^5.0.3, acorn@^5.6.0: version "5.7.3" resolved "https://registry.yarnpkg.com/acorn/-/acorn-5.7.3.tgz#67aa231bf8812974b85235a96771eb6bd07ea279" +acorn@^6.4.1: + version "6.4.1" + resolved "https://registry.yarnpkg.com/acorn/-/acorn-6.4.1.tgz#531e58ba3f51b9dacb9a6646ca4debf5b14ca474" + integrity sha512-ZVA9k326Nwrj3Cj9jlh3wGFutC2ZornPNARZwsNYqQYgN0EsV2d53w5RN/co65Ohn4sUAUtb1rSUAOD6XN9idA== + add-stream@^1.0.0: version "1.0.0" resolved "https://registry.yarnpkg.com/add-stream/-/add-stream-1.0.0.tgz#6a7990437ca736d5e1288db92bd3266d5f5cb2aa"