Skip to content

Commit 8a1c129

Browse files
authored
Merge pull request #4129 from cdr/jsjoeio-fix-vulnerabilities
fix(security): address dependency vulnerabilities
2 parents 7a73501 + 458474f commit 8a1c129

File tree

4 files changed

+37
-41
lines changed

4 files changed

+37
-41
lines changed

lib/vscode/extensions/github-authentication/package.json

+3
Original file line numberDiff line numberDiff line change
@@ -96,6 +96,9 @@
9696
"@types/node-fetch": "^2.5.7",
9797
"@types/uuid": "8.0.0"
9898
},
99+
"resolutions": {
100+
"axios": "^0.21.2"
101+
},
99102
"repository": {
100103
"type": "git",
101104
"url": "https://github.com/microsoft/vscode.git"

lib/vscode/extensions/github-authentication/yarn.lock

+9-9
Original file line numberDiff line numberDiff line change
@@ -55,12 +55,12 @@ asynckit@^0.4.0:
5555
resolved "https://registry.yarnpkg.com/asynckit/-/asynckit-0.4.0.tgz#c79ed97f7f34cb8f2ba1bc9790bcc366474b4b79"
5656
integrity sha1-x57Zf380y48robyXkLzDZkdLS3k=
5757

58-
axios@^0.21.1:
59-
version "0.21.1"
60-
resolved "https://registry.yarnpkg.com/axios/-/axios-0.21.1.tgz#22563481962f4d6bde9a76d516ef0e5d3c09b2b8"
61-
integrity sha512-dKQiRHxGD9PPRIUNIWvZhPTPpl1rf/OxTYKsqKUDjBwYylTvV7SjSHJb9ratfyzM6wCdLCOYLzs73qpg5c4iGA==
58+
axios@^0.21.1, axios@^0.21.2:
59+
version "0.21.4"
60+
resolved "https://registry.yarnpkg.com/axios/-/axios-0.21.4.tgz#c67b90dc0568e5c1cf2b0b858c43ba28e2eda575"
61+
integrity sha512-ut5vewkiu8jjGBdqpM44XxjuCjq9LAKeHVmoVfHVzy8eHgxxq8SbAVQNovDA8mVi05kP0Ea/n/UzcSHcTJQfNg==
6262
dependencies:
63-
follow-redirects "^1.10.0"
63+
follow-redirects "^1.14.0"
6464

6565
cls-hooked@^4.2.2:
6666
version "4.2.2"
@@ -110,10 +110,10 @@ emitter-listener@^1.0.1, emitter-listener@^1.1.1:
110110
dependencies:
111111
shimmer "^1.2.0"
112112

113-
follow-redirects@^1.10.0:
114-
version "1.13.3"
115-
resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.13.3.tgz#e5598ad50174c1bc4e872301e82ac2cd97f90267"
116-
integrity sha512-DUgl6+HDzB0iEptNQEXLx/KhTmDb8tZUHSeLqpnjpknR70H0nC2t9N73BK6fN4hOvJ84pKlIQVQ4k5FFlBedKA==
113+
follow-redirects@^1.14.0:
114+
version "1.14.3"
115+
resolved "https://registry.yarnpkg.com/follow-redirects/-/follow-redirects-1.14.3.tgz#6ada78118d8d24caee595595accdc0ac6abd022e"
116+
integrity sha512-3MkHxknWMUtb23apkgz/83fDoe+y+qr0TdgacGIA7bew+QLBo3vdgEN2xEsuXNivpFy4CyDhBBZnNZOtalmenw==
117117

118118
form-data@^3.0.0:
119119
version "3.0.0"

lib/vscode/package.json

+4-1
Original file line numberDiff line numberDiff line change
@@ -219,6 +219,9 @@
219219
"nwmatcher": "^1.4.4",
220220
"chrome-remote-interface": "^0.30.0",
221221
"glob-parent": "^5.1.2",
222-
"tar": "^6.1.9"
222+
"tar": "^6.1.9",
223+
"pac-resolver": "^5.0.0",
224+
"path-parse": "^1.0.7",
225+
"yargs-parser": "^13.1.2"
223226
}
224227
}

lib/vscode/yarn.lock

+21-31
Original file line numberDiff line numberDiff line change
@@ -2466,14 +2466,15 @@ define-property@^2.0.2:
24662466
is-descriptor "^1.0.2"
24672467
isobject "^3.0.1"
24682468

2469-
degenerator@^2.2.0:
2470-
version "2.2.0"
2471-
resolved "https://registry.yarnpkg.com/degenerator/-/degenerator-2.2.0.tgz#49e98c11fa0293c5b26edfbb52f15729afcdb254"
2472-
integrity sha512-aiQcQowF01RxFI4ZLFMpzyotbQonhNpBao6dkI8JPk5a+hmSjR5ErHp2CQySmQe8os3VBqLCIh87nDBgZXvsmg==
2469+
degenerator@^3.0.1:
2470+
version "3.0.1"
2471+
resolved "https://registry.yarnpkg.com/degenerator/-/degenerator-3.0.1.tgz#7ef78ec0c8577a544477308ddf1d2d6e88d51f5b"
2472+
integrity sha512-LFsIFEeLPlKvAKXu7j3ssIG6RT0TbI7/GhsqrI0DnHASEQjXQ0LUSYcjJteGgRGmZbl1TnMSxpNQIAiJ7Du5TQ==
24732473
dependencies:
24742474
ast-types "^0.13.2"
24752475
escodegen "^1.8.1"
24762476
esprima "^4.0.0"
2477+
vm2 "^3.9.3"
24772478

24782479
delayed-stream@~1.0.0:
24792480
version "1.0.0"
@@ -5901,7 +5902,7 @@ object-visit@^1.0.0:
59015902
dependencies:
59025903
isobject "^3.0.0"
59035904

5904-
object.assign@^4.0.4, object.assign@^4.1.0, object.assign@^4.1.1:
5905+
object.assign@^4.0.4, object.assign@^4.1.1:
59055906
version "4.1.2"
59065907
resolved "https://registry.yarnpkg.com/object.assign/-/object.assign-4.1.2.tgz#0ed54a342eceb37b38ff76eb831a0e788cb63940"
59075908
integrity sha512-ixT2L5THXsApyiUPYKmW+2EHpXXe5Ii3M+f4e+aJFAHao5amFRW6J0OO6c/LU8Be47utCx2GL89hxGB6XSmKuQ==
@@ -6131,12 +6132,12 @@ pac-proxy-agent@^4.1.0:
61316132
raw-body "^2.2.0"
61326133
socks-proxy-agent "5"
61336134

6134-
pac-resolver@^4.1.0:
6135-
version "4.2.0"
6136-
resolved "https://registry.yarnpkg.com/pac-resolver/-/pac-resolver-4.2.0.tgz#b82bcb9992d48166920bc83c7542abb454bd9bdd"
6137-
integrity sha512-rPACZdUyuxT5Io/gFKUeeZFfE5T7ve7cAkE5TUZRRfuKP0u5Hocwe48X7ZEm6mYB+bTB0Qf+xlVlA/RM/i6RCQ==
6135+
pac-resolver@^4.1.0, pac-resolver@^5.0.0:
6136+
version "5.0.0"
6137+
resolved "https://registry.yarnpkg.com/pac-resolver/-/pac-resolver-5.0.0.tgz#1d717a127b3d7a9407a16d6e1b012b13b9ba8dc0"
6138+
integrity sha512-H+/A6KitiHNNW+bxBKREk2MCGSxljfqRX76NjummWEYIat7ldVXRU3dhRIE3iXZ0nvGBk6smv3nntxKkzRL8NA==
61386139
dependencies:
6139-
degenerator "^2.2.0"
6140+
degenerator "^3.0.1"
61406141
ip "^1.1.5"
61416142
netmask "^2.0.1"
61426143

@@ -6263,10 +6264,10 @@ path-key@^2.0.0, path-key@^2.0.1:
62636264
resolved "https://registry.yarnpkg.com/path-key/-/path-key-2.0.1.tgz#411cadb574c5a140d3a4b1910d40d80cc9f40b40"
62646265
integrity sha1-QRyttXTFoUDTpLGRDUDYDMn0C0A=
62656266

6266-
path-parse@^1.0.6:
6267-
version "1.0.6"
6268-
resolved "https://registry.yarnpkg.com/path-parse/-/path-parse-1.0.6.tgz#d62dbb5679405d72c4737ec58600e9ddcf06d24c"
6269-
integrity sha512-GSmOT2EbHrINBf9SR7CDELwlJ8AENk3Qn7OikK4nFYAu3Ote2+JYNVvkpAEQm3/TLNEJFD/xZJjzyxg3KBWOzw==
6267+
path-parse@^1.0.6, path-parse@^1.0.7:
6268+
version "1.0.7"
6269+
resolved "https://registry.yarnpkg.com/path-parse/-/path-parse-1.0.7.tgz#fbc114b60ca42b30d9daf5858e4bd68bbedb6735"
6270+
integrity sha512-LDJzPVEEEPR+y48z93A0Ed0yXb8pAByGWo/k5YYdYgpY2/2EsOsksJrq7lOHxryrVOn1ejG6oAp8ahvOIQD8sw==
62706271

62716272
path-root-regex@^0.1.0:
62726273
version "0.1.2"
@@ -8640,6 +8641,11 @@ vm-browserify@^1.0.1:
86408641
resolved "https://registry.yarnpkg.com/vm-browserify/-/vm-browserify-1.1.2.tgz#78641c488b8e6ca91a75f511e7a3b32a86e5dda0"
86418642
integrity sha512-2ham8XPWTONajOR0ohOKOHXkm3+gaBmGut3SRuu75xLd/RRaY6vqgh8NBYYk7+RW3u5AtzPQZG8F10LHkl0lAQ==
86428643

8644+
vm2@^3.9.3:
8645+
version "3.9.3"
8646+
resolved "https://registry.yarnpkg.com/vm2/-/vm2-3.9.3.tgz#29917f6cc081cc43a3f580c26c5b553fd3c91f40"
8647+
integrity sha512-smLS+18RjXYMl9joyJxMNI9l4w7biW8ilSDaVRvFBDwOH8P0BK1ognFQTpg0wyQ6wIKLTblHJvROW692L/E53Q==
8648+
86438649
86448650
version "1.47.0"
86458651
resolved "https://registry.yarnpkg.com/vscode-debugprotocol/-/vscode-debugprotocol-1.47.0.tgz#700055bea38633a9530a5a552fb3ea314d76b73f"
@@ -9049,30 +9055,14 @@ yaml@^1.10.0:
90499055
resolved "https://registry.yarnpkg.com/yaml/-/yaml-1.10.2.tgz#2301c5ffbf12b467de8da2333a459e29e7920e4b"
90509056
integrity sha512-r3vXyErRCYJ7wg28yvBY5VSoAF8ZvlcW9/BwUzEtUsjvX/DKs24dIkuwjtuprwJJHsbyUbLApepYTR1BN4uHrg==
90519057

9052-
[email protected], yargs-parser@^13.1.2:
9058+
[email protected], yargs-parser@5.0.0-security.0, yargs-parser@^13.1.0, yargs-parser@^13.1.2:
90539059
version "13.1.2"
90549060
resolved "https://registry.yarnpkg.com/yargs-parser/-/yargs-parser-13.1.2.tgz#130f09702ebaeef2650d54ce6e3e5706f7a4fb38"
90559061
integrity sha512-3lbsNRf/j+A4QuSZfDRA7HRSfWrzO0YjqTJd5kjAq37Zep1CEgaYmrH9Q3GwPiB9cHyd1Y1UwggGhJGoxipbzg==
90569062
dependencies:
90579063
camelcase "^5.0.0"
90589064
decamelize "^1.2.0"
90599065

9060-
9061-
version "5.0.0-security.0"
9062-
resolved "https://registry.yarnpkg.com/yargs-parser/-/yargs-parser-5.0.0-security.0.tgz#4ff7271d25f90ac15643b86076a2ab499ec9ee24"
9063-
integrity sha512-T69y4Ps64LNesYxeYGYPvfoMTt/7y1XtfpIslUeK4um+9Hu7hlGoRtaDLvdXb7+/tfq4opVa2HRY5xGip022rQ==
9064-
dependencies:
9065-
camelcase "^3.0.0"
9066-
object.assign "^4.1.0"
9067-
9068-
yargs-parser@^13.1.0:
9069-
version "13.1.1"
9070-
resolved "https://registry.yarnpkg.com/yargs-parser/-/yargs-parser-13.1.1.tgz#d26058532aa06d365fe091f6a1fc06b2f7e5eca0"
9071-
integrity sha512-oVAVsHz6uFrg3XQheFII8ESO2ssAf9luWuAd6Wexsu4F3OtIW0o8IribPXYrD4WC24LWtPrJlGy87y5udK+dxQ==
9072-
dependencies:
9073-
camelcase "^5.0.0"
9074-
decamelize "^1.2.0"
9075-
90769066
90779067
version "2.0.0"
90789068
resolved "https://registry.yarnpkg.com/yargs-unparser/-/yargs-unparser-2.0.0.tgz#f131f9226911ae5d9ad38c432fe809366c2325eb"

0 commit comments

Comments
 (0)