From 24c2dbd3fb5ffea59151555819d83e4402a5d0a4 Mon Sep 17 00:00:00 2001 From: Peter Amstutz Date: Wed, 27 Nov 2019 15:44:12 -0500 Subject: [PATCH] Update 'set-value' package for CVE-2019-10747 no issue # Arvados-DCO-1.1-Signed-off-by: Peter Amstutz --- package.json | 5 +++-- yarn.lock | 10 ++++++++++ 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index e01351f5..1059a07d 100644 --- a/package.json +++ b/package.json @@ -53,6 +53,7 @@ "redux-form": "7.4.2", "redux-thunk": "2.3.0", "reselect": "4.0.0", + "set-value": "2.0.1", "shell-quote": "1.6.1", "sinon": "7.3", "ts-mock-imports": "1.2.6", @@ -84,6 +85,7 @@ "@types/react-router-dom": "4.3.1", "@types/react-router-redux": "5.0.16", "@types/redux-devtools": "3.0.44", + "@types/sinon": "7.5", "@types/uuid": "3.4.4", "axios-mock-adapter": "1.15.0", "enzyme": "3.6.0", @@ -92,8 +94,7 @@ "node-sass": "4.9.4", "node-sass-chokidar": "1.3.4", "redux-devtools": "3.4.1", - "typescript": "3.1.1", - "@types/sinon": "7.5" + "typescript": "3.1.1" }, "jest": { "moduleNameMapper": { diff --git a/yarn.lock b/yarn.lock index 559adb53..d33d165d 100644 --- a/yarn.lock +++ b/yarn.lock @@ -7601,6 +7601,16 @@ set-blocking@^2.0.0, set-blocking@~2.0.0: version "2.0.0" resolved "https://registry.yarnpkg.com/set-blocking/-/set-blocking-2.0.0.tgz#045f9782d011ae9a6803ddd382b24392b3d890f7" +set-value@2.0.1: + version "2.0.1" + resolved "https://registry.yarnpkg.com/set-value/-/set-value-2.0.1.tgz#a18d40530e6f07de4228c7defe4227af8cad005b" + integrity sha512-JxHc1weCN68wRY0fhCoXpyK55m/XPHafOmK4UWD7m2CI14GMcFypt4w/0+NV5f/ZMby2F6S2wwA7fgynh9gWSw== + dependencies: + extend-shallow "^2.0.1" + is-extendable "^0.1.1" + is-plain-object "^2.0.3" + split-string "^3.0.1" + set-value@^0.4.3: version "0.4.3" resolved "https://registry.yarnpkg.com/set-value/-/set-value-0.4.3.tgz#7db08f9d3d22dc7f78e53af3c3bf4666ecdfccf1" -- 2.30.2