From c37d30f5cf7e2c9259f4b3d2525cca6bb1e2bebc Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 13 Aug 2024 04:17:34 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AXIOS-6144788 --- package.json | 2 +- yarn.lock | 11 ++++++++++- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index beaa1981..355a70d8 100644 --- a/package.json +++ b/package.json @@ -44,7 +44,7 @@ "@neutron-org/neutronjs": "4.2.0", "@neutron-org/neutronjsplus": "0.5.0", "@types/lodash": "^4.14.182", - "axios": "1.6.0", + "axios": "1.6.4", "commander": "^10.0.0", "cosmjs-types": "^0.9.0", "date-fns": "^2.16.1", diff --git a/yarn.lock b/yarn.lock index 862ec492..ac2020a0 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1909,6 +1909,15 @@ axios@1.6.0: form-data "^4.0.0" proxy-from-env "^1.1.0" +axios@1.6.4: + version "1.6.4" + resolved "https://registry.yarnpkg.com/axios/-/axios-1.6.4.tgz#184ee1f63d412caffcf30d2c50982253c3ee86e0" + integrity sha512-heJnIs6N4aa1eSthhN9M5ioILu8Wi8vmQW9iHQ9NUvfkJb0lEEDUiIdQNAuBtfUt3FxReaKdpQA5DbmMOqzF/A== + dependencies: + follow-redirects "^1.15.4" + form-data "^4.0.0" + proxy-from-env "^1.1.0" + axios@^1.6.0: version "1.7.3" resolved "https://registry.yarnpkg.com/axios/-/axios-1.7.3.tgz#a1125f2faf702bc8e8f2104ec3a76fab40257d85" @@ -2761,7 +2770,7 @@ flatted@^3.2.9, flatted@^3.3.1: resolved "https://registry.yarnpkg.com/flatted/-/flatted-3.3.1.tgz#21db470729a6734d4997002f439cb308987f567a" integrity sha512-X8cqMLLie7KsNUDSdzeN8FYK9rEt4Dt67OsG/DNGnYTSDBG4uFAJFBnUeiV+zCVAvwFy56IjM9sH51jVaEhNxw== -follow-redirects@^1.15.0, follow-redirects@^1.15.6: +follow-redirects@^1.15.0, follow-redirects@^1.15.4, follow-redirects@^1.15.6: version "1.15.6" resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.15.6.tgz#7f815c0cda4249c74ff09e95ef97c23b5fd0399b" integrity sha512-wWN62YITEaOpSK584EZXJafH1AGpO8RVgElfkuXbTOrPX4fIfOyEpW/CsiNd8JdYrAoOvafRTOEnvsO++qCqFA==