From 934de5325f8cb6aeab6f5bb253a5fa2eb14ec0c2 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 1 May 2020 13:29:04 +0800 Subject: [PATCH 1/2] fix: javascript/yarn/yarn-scopes/package.json & javascript/yarn/yarn-scopes/yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JQUERY-567880 --- javascript/yarn/yarn-scopes/package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/javascript/yarn/yarn-scopes/package.json b/javascript/yarn/yarn-scopes/package.json index b2879a6..7aa3d01 100755 --- a/javascript/yarn/yarn-scopes/package.json +++ b/javascript/yarn/yarn-scopes/package.json @@ -5,7 +5,7 @@ "author": "continuous-security ", "description": "An example project to test dependency analysis tools with different dependencies scopes specified in yarn.lock.", "dependencies": { - "jquery": "3.0.0-alpha1", + "jquery": "3.5.0", "boom": "", "console-io": "2.6.3", "cookie-signature": "1.0.2" From 4ae1abda9f292597c13baf387553923e8ca0ad8b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 1 May 2020 13:29:05 +0800 Subject: [PATCH 2/2] fix: javascript/yarn/yarn-scopes/package.json & javascript/yarn/yarn-scopes/yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JQUERY-567880 --- javascript/yarn/yarn-scopes/yarn.lock | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/javascript/yarn/yarn-scopes/yarn.lock b/javascript/yarn/yarn-scopes/yarn.lock index 156d23c..2ec4727 100755 --- a/javascript/yarn/yarn-scopes/yarn.lock +++ b/javascript/yarn/yarn-scopes/yarn.lock @@ -431,9 +431,10 @@ join-io@~1.4.0: minify "^2.0.0" ponse "^1.4.1" -jquery@3.0.0-alpha1: - version "3.0.0-alpha1" - resolved "https://registry.yarnpkg.com/jquery/-/jquery-3.0.0-alpha1.tgz#3493d672266e21c2dffb2714f935448edebe3c62" +jquery@3.5.0: + version "3.5.0" + resolved "https://registry.yarnpkg.com/jquery/-/jquery-3.5.0.tgz#9980b97d9e4194611c36530e7dc46a58d7340fc9" + integrity sha512-Xb7SVYMvygPxbFMpTFQiHh1J7HClEaThguL15N/Gg37Lri/qKyhRGZYzHRyLH8Stq3Aow0LsHO2O2ci86fCrNQ== json3@3.2.6: version "3.2.6"