Skip to content

Commit 519c8c6

Browse files
committed
fix: package.json & yarn.lock to reduce vulnerabilities
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-1018905 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724 - https://snyk.io/vuln/SNYK-JS-LODASH-567746
1 parent 63df431 commit 519c8c6

File tree

2 files changed

+60
-71
lines changed

2 files changed

+60
-71
lines changed

package.json

+2-2
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@
2929
"graphql-resolve-batch": "^1.0.2",
3030
"graphql-subscriptions": "^1.0.0",
3131
"grpc": "^1.24.3",
32-
"js-xdr": "^1.1.0",
32+
"js-xdr": "^3.0.1",
3333
"minimist": "^1.2.3",
3434
"object-dig": "^0.1.3",
3535
"pg": "^8.2.1",
@@ -38,7 +38,7 @@
3838
"progress": "^2.0.3",
3939
"retry": "^0.12.0",
4040
"squel": "^5.12.2",
41-
"stellar-base": "^3.0.4",
41+
"stellar-base": "^10.0.0",
4242
"typeorm": "^0.2.17",
4343
"typescript-memoize": "^1.0.0-alpha.3",
4444
"winston": "^3.0.0"

yarn.lock

+58-69
Original file line numberDiff line numberDiff line change
@@ -455,6 +455,11 @@
455455
"@sentry/types" "5.7.1"
456456
tslib "^1.9.3"
457457

458+
"@stellar/js-xdr@^3.0.1":
459+
version "3.0.1"
460+
resolved "https://registry.yarnpkg.com/@stellar/js-xdr/-/js-xdr-3.0.1.tgz#d500f1e1332210cd56e0ef95e44c54506d9f48f3"
461+
integrity sha512-dp5Eh7Nr1YjiIeqpdkj2cQYxfoPudDAH3ck8MWggp48Htw66Z/hUssNYUQG/OftLjEmHT90Z/dtey2Y77DOxIw==
462+
458463
"@tootallnate/once@1":
459464
version "1.0.0"
460465
resolved "https://registry.yarnpkg.com/@tootallnate/once/-/once-1.0.0.tgz#9c13c2574c92d4503b005feca8f2e16cc1611506"
@@ -1457,6 +1462,11 @@ base64-js@^1.0.2:
14571462
resolved "https://registry.yarnpkg.com/base64-js/-/base64-js-1.3.1.tgz#58ece8cb75dd07e71ed08c736abc5fac4dbf8df1"
14581463
integrity sha512-mLQ4i2QO1ytvGWFWmcngKO//JXAQueZvwEKtjgQFM4jIK0kU+ytMfplL8j+n5mspOfjHwoAg+9yhb7BwAHm36g==
14591464

1465+
base64-js@^1.3.1:
1466+
version "1.5.1"
1467+
resolved "https://registry.yarnpkg.com/base64-js/-/base64-js-1.5.1.tgz#1b1b440160a5bf7ad40b650f095963481903930a"
1468+
integrity sha512-AKpaYlHn8t4SVbOHCy+b5+KKgvR4vrsD8vbvrbiQJps7fKDTkjkDry6ji0rUJjC0kzbNePLwzxq8iypo41qeWA==
1469+
14601470
base@^0.11.1:
14611471
version "0.11.2"
14621472
resolved "https://registry.yarnpkg.com/base/-/base-0.11.2.tgz#7bde5ced145b6d551a90db87f83c558b4eb48a8f"
@@ -1477,16 +1487,16 @@ bcrypt-pbkdf@^1.0.0:
14771487
dependencies:
14781488
tweetnacl "^0.14.3"
14791489

1480-
bignumber.js@^4.0.0:
1481-
version "4.1.0"
1482-
resolved "https://registry.yarnpkg.com/bignumber.js/-/bignumber.js-4.1.0.tgz#db6f14067c140bd46624815a7916c92d9b6c24b1"
1483-
integrity sha512-eJzYkFYy9L4JzXsbymsFn3p54D+llV27oTQ+ziJG7WFRheJcNZilgVXMG0LoZtlQSKBsJdWtLFqOD0u+U0jZKA==
1484-
14851490
bignumber.js@^8.0.1:
14861491
version "8.1.1"
14871492
resolved "https://registry.yarnpkg.com/bignumber.js/-/bignumber.js-8.1.1.tgz#4b072ae5aea9c20f6730e4e5d529df1271c4d885"
14881493
integrity sha512-QD46ppGintwPGuL1KqmwhR0O+N2cZUg8JG/VzwI2e28sM9TqHjQB10lI4QAaMHVbLzwVLLAwEglpKPViWX+5NQ==
14891494

1495+
bignumber.js@^9.1.2:
1496+
version "9.1.2"
1497+
resolved "https://registry.yarnpkg.com/bignumber.js/-/bignumber.js-9.1.2.tgz#b7c4242259c008903b13707983b5f4bbd31eda0c"
1498+
integrity sha512-2/mKyZH9K85bzOEfhXDBFZTGd1CTs+5IHpeFQo9luiBG7hghdC851Pj2WAhb6E3R6b9tZj/XKhbg4fum+Kepug==
1499+
14901500
binary-extensions@^1.0.0:
14911501
version "1.13.1"
14921502
resolved "https://registry.yarnpkg.com/binary-extensions/-/binary-extensions-1.13.1.tgz#598afe54755b2868a5330d2aff9d4ebb53209b65"
@@ -1594,6 +1604,14 @@ buffer@^5.1.0:
15941604
base64-js "^1.0.2"
15951605
ieee754 "^1.1.4"
15961606

1607+
buffer@^6.0.3:
1608+
version "6.0.3"
1609+
resolved "https://registry.yarnpkg.com/buffer/-/buffer-6.0.3.tgz#2ace578459cc8fbe2a70aaa8f52ee63b6a74c6c6"
1610+
integrity sha512-FTiCpNxtwiZZHEZbcbTIcZjERVICn9yq/pDFkTl95/AxzD1naBctN7YO68riM/gLSDY7sdrMby8hofADYuuqOA==
1611+
dependencies:
1612+
base64-js "^1.3.1"
1613+
ieee754 "^1.2.1"
1614+
15971615
builtin-modules@^1.1.1:
15981616
version "1.1.1"
15991617
resolved "https://registry.yarnpkg.com/builtin-modules/-/builtin-modules-1.1.1.tgz#270f076c5a72c02f5b65a47df94c5fe3a278892f"
@@ -1948,7 +1966,7 @@ [email protected]:
19481966
resolved "https://registry.yarnpkg.com/core-js/-/core-js-2.4.1.tgz#4de911e667b0eae9124e34254b53aea6fc618d3e"
19491967
integrity sha1-TekR5mew6ukSTjQlS1OupvxhjT4=
19501968

1951-
core-js@^2.4.0, core-js@^2.6.3:
1969+
core-js@^2.4.0:
19521970
version "2.6.9"
19531971
resolved "https://registry.yarnpkg.com/core-js/-/core-js-2.6.9.tgz#6b4b214620c834152e179323727fc19741b084f2"
19541972
integrity sha512-HOpZf6eXmnl7la+cUdMnLvUxKNqLUzJvgIziQ0DiF3JwSImNphIqdGqzj6hIKyX04MmV0poclQ7+wjWvxQyR2A==
@@ -1971,13 +1989,6 @@ cors@^2.8.4:
19711989
object-assign "^4"
19721990
vary "^1"
19731991

1974-
crc@^3.5.0:
1975-
version "3.8.0"
1976-
resolved "https://registry.yarnpkg.com/crc/-/crc-3.8.0.tgz#ad60269c2c856f8c299e2c4cc0de4556914056c6"
1977-
integrity sha512-iX3mfgcTMIq3ZKLIsVFAbv7+Mc10kxabAGQb8HvjA1o3T1PIYprbakQ65d3I+2HGHt6nSKkM9PYjgoJO2KcFBQ==
1978-
dependencies:
1979-
buffer "^5.1.0"
1980-
19811992
create-error-class@^3.0.0:
19821993
version "3.0.2"
19831994
resolved "https://registry.yarnpkg.com/create-error-class/-/create-error-class-3.0.2.tgz#06be7abef947a3f14a30fd610671d401bca8b7b6"
@@ -2022,11 +2033,6 @@ cssstyle@^1.0.0:
20222033
dependencies:
20232034
cssom "0.3.x"
20242035

2025-
cursor@^0.1.5:
2026-
version "0.1.5"
2027-
resolved "https://registry.yarnpkg.com/cursor/-/cursor-0.1.5.tgz#ea778c2b09d33c2e564fd92147076750483ebb2c"
2028-
integrity sha1-6neMKwnTPC5WT9khRwdnUEg+uyw=
2029-
20302036
d@1, d@^1.0.1:
20312037
version "1.0.1"
20322038
resolved "https://registry.yarnpkg.com/d/-/d-1.0.1.tgz#8698095372d58dbee346ffd0c7093f99f8f9eb5a"
@@ -3112,6 +3118,11 @@ ieee754@^1.1.4:
31123118
resolved "https://registry.yarnpkg.com/ieee754/-/ieee754-1.1.13.tgz#ec168558e95aa181fd87d37f55c32bbcb6708b84"
31133119
integrity sha512-4vf7I2LYV/HaWerSo3XmlMkp5eZ83i+/CDluXi/IGTs/O1sejBNhTtnxzmRZfvOUqj7lZjqHkeTvpgSFDlWZTg==
31143120

3121+
ieee754@^1.2.1:
3122+
version "1.2.1"
3123+
resolved "https://registry.yarnpkg.com/ieee754/-/ieee754-1.2.1.tgz#8eb7a10a63fff25d15a57b001586d177d1b0d352"
3124+
integrity sha512-dcyqhDvX1C46lXZcVqCpK+FtMRQVdIMN6/Df5js2zouUsqG7I6sFxitIC+7KYK29KdXOLHdu9zL4sFnoVQnqaA==
3125+
31153126
ignore-by-default@^1.0.1:
31163127
version "1.0.1"
31173128
resolved "https://registry.yarnpkg.com/ignore-by-default/-/ignore-by-default-1.0.1.tgz#48ca6d72f6c6a3af00a9ad4ae6876be3889e2b09"
@@ -3160,7 +3171,7 @@ [email protected]:
31603171
resolved "https://registry.yarnpkg.com/inherits/-/inherits-2.0.3.tgz#633c2c83e3da42a502f52466022480f4208261de"
31613172
integrity sha1-Yzwsg+PaQqUC9SRmAiSA9CCCYd4=
31623173

3163-
ini@^1.3.4, ini@^1.3.5, ini@~1.3.0:
3174+
ini@^1.3.4, ini@~1.3.0:
31643175
version "1.3.7"
31653176
resolved "https://registry.yarnpkg.com/ini/-/ini-1.3.7.tgz#a09363e1911972ea16d7a8851005d84cf09a9a84"
31663177
integrity sha512-iKpRpXP+CrP2jyrxvg1kMUpXDyRUFDWurxbnVT1vQPx+Wz9uCYsMIqYuSBLV+PAaZG/d7kRLKRFc9oDMsH+mFQ==
@@ -3871,24 +3882,10 @@ jest@^24.7.1:
38713882
resolved "https://registry.yarnpkg.com/js-tokens/-/js-tokens-4.0.0.tgz#19203fb59991df98e3a287050d4647cdeaf32499"
38723883
integrity sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==
38733884

3874-
js-xdr@^1.1.0:
3875-
version "1.1.2"
3876-
resolved "https://registry.yarnpkg.com/js-xdr/-/js-xdr-1.1.2.tgz#aba1f0952508c83f33dd7e774fa9231b3073992b"
3877-
integrity sha512-ipiz1CnsyjLsba+QQd5jezGXddNKGa4oO9EODy0kWr3G3R8MNslIxkhQFpyRfY3yoY7YplhRVfC3cmXb4AobZQ==
3878-
dependencies:
3879-
core-js "^2.6.3"
3880-
cursor "^0.1.5"
3881-
lodash "^4.17.5"
3882-
long "^2.2.3"
3883-
3884-
js-xdr@^1.1.3:
3885-
version "1.1.4"
3886-
resolved "https://registry.yarnpkg.com/js-xdr/-/js-xdr-1.1.4.tgz#678df4c6f8c7960de85bdf3bfa02b89df2730777"
3887-
integrity sha512-Xhwys9hyDZQDisxCKZi2nDhvGg6fKhsEgAUaJlzjwo32mZ2gZVIQl3+w4Le5SX5dsKDsboFdM2gnu5JALWetTg==
3888-
dependencies:
3889-
cursor "^0.1.5"
3890-
lodash "^4.17.5"
3891-
long "^2.2.3"
3885+
js-xdr@^3.0.1:
3886+
version "3.0.1"
3887+
resolved "https://registry.yarnpkg.com/js-xdr/-/js-xdr-3.0.1.tgz#e63637d3dec67830e20537c8bde8fc24a715fe18"
3888+
integrity sha512-U+myFf2xdgeXsCE4iKwt/j14BLvU0F/YZv9LJwJrQgqtKKwyetYP7LwJKbc9qUYYAsa6ixy57CrDMtg2x+01cA==
38923889

38933890
[email protected], js-yaml@^3.13.1:
38943891
version "3.13.1"
@@ -4079,7 +4076,7 @@ lodash.sortby@^4.7.0:
40794076
resolved "https://registry.yarnpkg.com/lodash.sortby/-/lodash.sortby-4.7.0.tgz#edd14c824e2cc9c1e0b0a1b42bb5210516a42438"
40804077
integrity sha1-7dFMgk4sycHgsKG0K7UhBRakJDg=
40814078

4082-
lodash@^4.17.11, lodash@^4.17.13, lodash@^4.17.14, lodash@^4.17.5:
4079+
lodash@^4.17.11, lodash@^4.17.13, lodash@^4.17.14:
40834080
version "4.17.19"
40844081
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.19.tgz#e48ddedbe30b3321783c5b4301fbd353bc1e4a4b"
40854082
integrity sha512-JNvd8XER9GQX0v2qJgsaN/mzFCNA5BRe/j8JN9d+tWyGLSodKQHKFicdwNYzWwI3wjRnaKPsGj1XkBjx/F96DQ==
@@ -4100,11 +4097,6 @@ loglevel@^1.6.7:
41004097
resolved "https://registry.yarnpkg.com/loglevel/-/loglevel-1.6.8.tgz#8a25fb75d092230ecd4457270d80b54e28011171"
41014098
integrity sha512-bsU7+gc9AJ2SqpzxwU3+1fedl8zAntbtC5XYlt3s2j1hJcn2PsXSmgN8TaLG/J1/2mod4+cE/3vNL70/c1RNCA==
41024099

4103-
long@^2.2.3:
4104-
version "2.4.0"
4105-
resolved "https://registry.yarnpkg.com/long/-/long-2.4.0.tgz#9fa180bb1d9500cdc29c4156766a1995e1f4524f"
4106-
integrity sha1-n6GAux2VAM3CnEFWdmoZleH0Uk8=
4107-
41084100
long@^4.0.0:
41094101
version "4.0.0"
41104102
resolved "https://registry.yarnpkg.com/long/-/long-4.0.0.tgz#9a7b71cfb7d361a194ea555241c92f7468d5bf28"
@@ -4368,7 +4360,7 @@ mz@^2.4.0:
43684360
object-assign "^4.0.1"
43694361
thenify-all "^1.0.0"
43704362

4371-
nan@^2.12.1, nan@^2.13.2, nan@^2.14.0:
4363+
nan@^2.12.1, nan@^2.13.2:
43724364
version "2.14.0"
43734365
resolved "https://registry.yarnpkg.com/nan/-/nan-2.14.0.tgz#7818f722027b2459a86f0295d434d1fc2336c52c"
43744366
integrity sha512-INOFj37C7k3AfaNTtX8RhsTw7qRy7eLET14cROi9+5HAVbbHuIWUHEauBv5qT4Av2tWasiTY1Jw6puUNqRJXQg==
@@ -4438,10 +4430,10 @@ node-fetch@^2.1.2, node-fetch@^2.2.0:
44384430
resolved "https://registry.yarnpkg.com/node-fetch/-/node-fetch-2.6.1.tgz#045bd323631f76ed2e2b55573394416b639a0052"
44394431
integrity sha512-V4aYg89jEoVRxRb2fJdAg8FHvI7cEyYdVAh94HH0UIK8oJxUfkjlDQN9RbMx+bEjP7+ggMiFRprSti032Oipxw==
44404432

4441-
node-gyp-build@^4.1.0:
4442-
version "4.1.1"
4443-
resolved "https://registry.yarnpkg.com/node-gyp-build/-/node-gyp-build-4.1.1.tgz#d7270b5d86717068d114cc57fff352f96d745feb"
4444-
integrity sha512-dSq1xmcPDKPZ2EED2S6zw/b9NKsqzXRE6dVr8TVQnI3FJOTteUMuqF3Qqs6LZg+mLGYJWqQzMbIjMtJqTv87nQ==
4433+
node-gyp-build@^4.6.0:
4434+
version "4.7.1"
4435+
resolved "https://registry.yarnpkg.com/node-gyp-build/-/node-gyp-build-4.7.1.tgz#cd7d2eb48e594874053150a9418ac85af83ca8f7"
4436+
integrity sha512-wTSrZ+8lsRRa3I3H8Xr65dLWSgCvY2l4AOnaeKdPA9TB/WYMPaTcrzf3rXvFoVvjKNVnu0CcWSx54qq9GKRUYg==
44454437

44464438
node-int64@^0.4.0:
44474439
version "0.4.0"
@@ -5581,14 +5573,12 @@ snapdragon@^0.8.1:
55815573
source-map-resolve "^0.5.0"
55825574
use "^3.1.0"
55835575

5584-
sodium-native@^2.3.0:
5585-
version "2.4.6"
5586-
resolved "https://registry.yarnpkg.com/sodium-native/-/sodium-native-2.4.6.tgz#8a8173095e8cf4f997de393a2ba106c34870cac2"
5587-
integrity sha512-Ro9lhTjot8M01nwKLXiqLSmjR7B8o+Wg4HmJUjEShw/q6XPlNMzjPkA1VJKaMH8SO8fJ/sggAKVwreTaFszS2Q==
5576+
sodium-native@^4.0.1:
5577+
version "4.0.4"
5578+
resolved "https://registry.yarnpkg.com/sodium-native/-/sodium-native-4.0.4.tgz#561b7c39c97789f8202d6fd224845fe2e8cd6879"
5579+
integrity sha512-faqOKw4WQKK7r/ybn6Lqo1F9+L5T6NlBJJYvpxbZPetpWylUVqz449mvlwIBKBqxEHbWakWuOlUt8J3Qpc4sWw==
55885580
dependencies:
5589-
ini "^1.3.5"
5590-
nan "^2.14.0"
5591-
node-gyp-build "^4.1.0"
5581+
node-gyp-build "^4.6.0"
55925582

55935583
source-map-resolve@^0.5.0:
55945584
version "0.5.2"
@@ -5722,20 +5712,19 @@ stealthy-require@^1.1.1:
57225712
resolved "https://registry.yarnpkg.com/stealthy-require/-/stealthy-require-1.1.1.tgz#35b09875b4ff49f26a777e509b3090a3226bf24b"
57235713
integrity sha1-NbCYdbT/SfJqd35QmzCQoyJr8ks=
57245714

5725-
stellar-base@^3.0.4:
5726-
version "3.0.4"
5727-
resolved "https://registry.yarnpkg.com/stellar-base/-/stellar-base-3.0.4.tgz#9f9b183921886c326609c37b701a725320e5e004"
5728-
integrity sha512-aSa5T7/y+jYmgdpyZKwvc13u1pR4MLI7yaDMaVV7tGp98lFcvd1F37QlZXf0j5QS7NVVpXWZ5iDmftZcjx2Euw==
5715+
stellar-base@^10.0.0:
5716+
version "10.0.1"
5717+
resolved "https://registry.yarnpkg.com/stellar-base/-/stellar-base-10.0.1.tgz#583986f5107376cf1a60f9fdf7c72f4352a2620a"
5718+
integrity sha512-SL7nzip0Vq5rFWAqodjGN7a1xe4rGfw5fU1CT7N0S4XQOIBC+vLRH5C1KD0XSjITDAk+F4HX6yLpbNORRX3/Zw==
57295719
dependencies:
5720+
"@stellar/js-xdr" "^3.0.1"
57305721
base32.js "^0.1.0"
5731-
bignumber.js "^4.0.0"
5732-
crc "^3.5.0"
5733-
js-xdr "^1.1.3"
5734-
lodash "^4.17.11"
5722+
bignumber.js "^9.1.2"
5723+
buffer "^6.0.3"
57355724
sha.js "^2.3.6"
5736-
tweetnacl "^1.0.0"
5725+
tweetnacl "^1.0.3"
57375726
optionalDependencies:
5738-
sodium-native "^2.3.0"
5727+
sodium-native "^4.0.1"
57395728

57405729
stream-events@^1.0.5:
57415730
version "1.0.5"
@@ -6182,10 +6171,10 @@ tweetnacl@^0.14.3, tweetnacl@~0.14.0:
61826171
resolved "https://registry.yarnpkg.com/tweetnacl/-/tweetnacl-0.14.5.tgz#5ae68177f192d4456269d108afa93ff8743f4f64"
61836172
integrity sha1-WuaBd/GS1EViadEIr6k/+HQ/T2Q=
61846173

6185-
tweetnacl@^1.0.0:
6186-
version "1.0.1"
6187-
resolved "https://registry.yarnpkg.com/tweetnacl/-/tweetnacl-1.0.1.tgz#2594d42da73cd036bd0d2a54683dd35a6b55ca17"
6188-
integrity sha512-kcoMoKTPYnoeS50tzoqjPY3Uv9axeuuFAZY9M/9zFnhoVvRfxz9K29IMPD7jGmt2c8SW7i3gT9WqDl2+nV7p4A==
6174+
tweetnacl@^1.0.3:
6175+
version "1.0.3"
6176+
resolved "https://registry.yarnpkg.com/tweetnacl/-/tweetnacl-1.0.3.tgz#ac0af71680458d8a6378d0d0d050ab1407d35596"
6177+
integrity sha512-6rt+RN7aOi1nGMyC4Xa5DdYiukl2UWCbcJft7YhxReBGQD7OAM8Pbxw6YMo4r2diNEA8FEmu32YOn9rhaiE5yw==
61896178

61906179
type-check@~0.3.2:
61916180
version "0.3.2"

0 commit comments

Comments
 (0)