From 4ebc3e1b05e92d0091d44337188d4e72803905f5 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 21 Jul 2024 21:16:10 +0000 Subject: [PATCH] fix: fixtures/packaging/rjs/prod/package.json & fixtures/packaging/rjs/prod/yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-REQUIREJS-7414192 - https://snyk.io/vuln/SNYK-JS-REQUIREJS-7417994 - https://snyk.io/vuln/SNYK-JS-REQUIREJS-5416713 --- fixtures/packaging/rjs/prod/package.json | 2 +- fixtures/packaging/rjs/prod/yarn.lock | 7 ++++--- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/fixtures/packaging/rjs/prod/package.json b/fixtures/packaging/rjs/prod/package.json index eaf76b1e3a0..2d2a2548516 100644 --- a/fixtures/packaging/rjs/prod/package.json +++ b/fixtures/packaging/rjs/prod/package.json @@ -2,7 +2,7 @@ "private": true, "name": "rjs-prod-fixture", "dependencies": { - "requirejs": "^2.3.2" + "requirejs": "^2.3.7" }, "scripts": { "build": "rm -f output.js && r.js -o config.js" diff --git a/fixtures/packaging/rjs/prod/yarn.lock b/fixtures/packaging/rjs/prod/yarn.lock index 1bebef2fdbc..6afaec817da 100644 --- a/fixtures/packaging/rjs/prod/yarn.lock +++ b/fixtures/packaging/rjs/prod/yarn.lock @@ -2,6 +2,7 @@ # yarn lockfile v1 -requirejs@^2.3.2: - version "2.3.5" - resolved "https://registry.yarnpkg.com/requirejs/-/requirejs-2.3.5.tgz#617b9acbbcb336540ef4914d790323a8d4b861b0" +requirejs@^2.3.7: + version "2.3.7" + resolved "https://registry.yarnpkg.com/requirejs/-/requirejs-2.3.7.tgz#0b22032e51a967900e0ae9f32762c23a87036bd0" + integrity sha512-DouTG8T1WanGok6Qjg2SXuCMzszOo0eHeH9hDZ5Y4x8Je+9JB38HdTLT4/VA8OaUhBa0JPVHJ0pyBkM1z+pDsw==