From 23286e42dd00a763f38132958061317e33ec5baf Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 14 Apr 2023 13:02:43 +0000 Subject: [PATCH] Bump helmet from 5.0.2 to 6.1.5 Bumps [helmet](https://github.com/helmetjs/helmet) from 5.0.2 to 6.1.5. - [Release notes](https://github.com/helmetjs/helmet/releases) - [Changelog](https://github.com/helmetjs/helmet/blob/main/CHANGELOG.md) - [Commits](https://github.com/helmetjs/helmet/compare/v5.0.2...v6.1.5) --- updated-dependencies: - dependency-name: helmet dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- package.json | 2 +- yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index a31e2a6..527593b 100644 --- a/package.json +++ b/package.json @@ -75,7 +75,7 @@ "express": "^4.17.3", "express-formidable": "^1.2.0", "express-rate-limit": "^6.3.0", - "helmet": "^5.0.2", + "helmet": "^6.1.5", "jsonwebtoken": "^9.0.0", "morgan": "^1.10.0", "multer": "^1.4.4", diff --git a/yarn.lock b/yarn.lock index b0990ed..22882be 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3509,10 +3509,10 @@ has@^1.0.3: dependencies: function-bind "^1.1.1" -helmet@*, helmet@^5.0.2: - version "5.0.2" - resolved "https://registry.yarnpkg.com/helmet/-/helmet-5.0.2.tgz#3264ec6bab96c82deaf65e3403c369424cb2366c" - integrity sha512-QWlwUZZ8BtlvwYVTSDTBChGf8EOcQ2LkGMnQJxSzD1mUu8CCjXJZq/BXP8eWw4kikRnzlhtYo3lCk0ucmYA3Vg== +helmet@*, helmet@^6.1.5: + version "6.1.5" + resolved "https://registry.yarnpkg.com/helmet/-/helmet-6.1.5.tgz#2153387f6d73cce6efdfd85d3a65417cfb7db80c" + integrity sha512-UgAvdoG0BhF9vcCh/j0bWtElo2ZHHk6OzC98NLCM6zK03DEVSM0vUAtT7iR+oTo2Mi6sGelAH3tL6B/uUWxV4g== hexoid@^1.0.0: version "1.0.0"