From 62482331326abbf0cf956076a0a6d63e20edad79 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 25 Apr 2023 07:27:13 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-YAML-5458867 --- package.json | 2 +- yarn.lock | 10 ++++++++++ 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/package.json b/package.json index 6908942..dbb458c 100644 --- a/package.json +++ b/package.json @@ -25,7 +25,7 @@ } ], "dependencies": { - "cosmiconfig": "^7.0.1", + "cosmiconfig": "^8.0.0", "debug": "^4.3.4", "execa": "^6.1.0", "fs-extra": "^10.1.0", diff --git a/yarn.lock b/yarn.lock index fd98dd3..ca7e0f8 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1588,6 +1588,16 @@ cosmiconfig@^7, cosmiconfig@^7.0.0, cosmiconfig@^7.0.1: path-type "^4.0.0" yaml "^1.10.0" +cosmiconfig@^8.0.0: + version "8.1.3" + resolved "https://registry.yarnpkg.com/cosmiconfig/-/cosmiconfig-8.1.3.tgz#0e614a118fcc2d9e5afc2f87d53cd09931015689" + integrity sha512-/UkO2JKI18b5jVMJUp0lvKFMpa/Gye+ZgZjKD+DGEN9y7NRcf/nK1A0sp67ONmKtnDCNMS44E6jrk0Yc3bDuUw== + dependencies: + import-fresh "^3.2.1" + js-yaml "^4.1.0" + parse-json "^5.0.0" + path-type "^4.0.0" + create-require@^1.1.0: version "1.1.1" resolved "https://registry.yarnpkg.com/create-require/-/create-require-1.1.1.tgz#c1d7e8f1e5f6cfc9ff65f9cd352d37348756c333"