From 093915e6134e39e366fc8cccea6947582a068eb2 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 19 Dec 2024 05:18:24 +0000 Subject: [PATCH] fix: package.json & package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-TRIX-8492396 --- package-lock.json | 30 +++++++++++++++++++++++++----- package.json | 2 +- 2 files changed, 26 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index 5522e99..cc14dd4 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,17 +1,37 @@ { - "name": "projet-tuttoPasta", + "name": "relock-npm-lock-v2-xRB29u", "lockfileVersion": 3, "requires": true, "packages": { "": { "dependencies": { - "trix": "^2.1.2" + "trix": "^2.1.9" + } + }, + "node_modules/@types/trusted-types": { + "version": "2.0.7", + "resolved": "https://registry.npmjs.org/@types/trusted-types/-/trusted-types-2.0.7.tgz", + "integrity": "sha512-ScaPdn1dQczgbl0QFTeTOmVHFULt394XJgOQNoyVhZ6r2vLnMLJfBPd53SB52T/3G36VI1/g2MZaX0cwDuXsfw==", + "license": "MIT", + "optional": true + }, + "node_modules/dompurify": { + "version": "3.2.3", + "resolved": "https://registry.npmjs.org/dompurify/-/dompurify-3.2.3.tgz", + "integrity": "sha512-U1U5Hzc2MO0oW3DF+G9qYN0aT7atAou4AgI0XjWz061nyBPbdxkfdhfy5uMgGn6+oLFCfn44ZGbdDqCzVmlOWA==", + "license": "(MPL-2.0 OR Apache-2.0)", + "optionalDependencies": { + "@types/trusted-types": "^2.0.7" } }, "node_modules/trix": { - "version": "2.1.2", - "resolved": "https://registry.npmjs.org/trix/-/trix-2.1.2.tgz", - "integrity": "sha512-PsQC4qn1Ub0djn7FZ9KLzEC2whE1J27JiRycn5WddlVT8JgwKq5PtlXo6rRfjc7Qj2aSzIdjkApai9zAW7/IRA==" + "version": "2.1.9", + "resolved": "https://registry.npmjs.org/trix/-/trix-2.1.9.tgz", + "integrity": "sha512-Hm02gmsFLjQ+gcFNUW0iwGibYpQpklBCnBUj4z5013W+q6eiZPA9d9HmeJK8jd+BMbqMq7OsVEGclrBrbl4MJw==", + "license": "MIT", + "dependencies": { + "dompurify": "^3.2.0" + } } } } diff --git a/package.json b/package.json index 377c0b6..f83a043 100644 --- a/package.json +++ b/package.json @@ -1,5 +1,5 @@ { "dependencies": { - "trix": "^2.1.2" + "trix": "^2.1.9" } }