From 99f13d846877ba1bae42bf050206a22dc246260f Mon Sep 17 00:00:00 2001 From: Xaala Date: Fri, 8 Nov 2024 10:48:02 -0500 Subject: [PATCH 1/2] Security Issue Fix Adding override to correct security vulnerability in cross-spawn package included as decendant of express-hbs --- package.json | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/package.json b/package.json index 9103b98..f26e66d 100644 --- a/package.json +++ b/package.json @@ -45,5 +45,10 @@ }, "optionalDependencies": { "js-beautify": "^1.13.11" + }, + "overrides": { + "express-hbs": { + "cross-spawn": "7.0.5" + } } } From b84654933b3ecdbcf08c984464ba125070077942 Mon Sep 17 00:00:00 2001 From: Xaala Date: Fri, 8 Nov 2024 10:51:33 -0500 Subject: [PATCH 2/2] Update package.json Corrected package name, had this repo's name as that's how I fixed it in a different project. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index f26e66d..430cf2d 100644 --- a/package.json +++ b/package.json @@ -47,7 +47,7 @@ "js-beautify": "^1.13.11" }, "overrides": { - "express-hbs": { + "js-beautify": { "cross-spawn": "7.0.5" } }