From ef3bf91d71796b0e9e8dbc7c0104d18261aa13ae Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Tue, 22 Mar 2022 13:48:44 +0000 Subject: [PATCH 1/2] chore(deps): update dependency nanoid to v3.1.31 [security] --- packages/runner-ct/package.json | 2 +- packages/runner-shared/package.json | 2 +- yarn.lock | 5 +++++ 3 files changed, 7 insertions(+), 2 deletions(-) diff --git a/packages/runner-ct/package.json b/packages/runner-ct/package.json index e9a7001d3539..d141eb17e82f 100644 --- a/packages/runner-ct/package.json +++ b/packages/runner-ct/package.json @@ -45,7 +45,7 @@ "mobx": "5.15.4", "mobx-react": "6.1.8", "mocha": "^8.1.3", - "nanoid": "3.1.20", + "nanoid": "3.1.31", "react": "16.8.6", "react-devtools-inline": "^4.10.1", "react-dom": "16.8.6", diff --git a/packages/runner-shared/package.json b/packages/runner-shared/package.json index f7d21035d09c..af36b0b19daf 100644 --- a/packages/runner-shared/package.json +++ b/packages/runner-shared/package.json @@ -25,7 +25,7 @@ "mobx": "5.15.4", "mobx-react": "6.1.8", "mocha": "7.0.1", - "nanoid": "3.1.20", + "nanoid": "3.1.31", "react": "16.8.6", "react-dom": "16.8.6", "react-popper": "2.2.5", diff --git a/yarn.lock b/yarn.lock index 51c354b751de..a8943a01c054 100644 --- a/yarn.lock +++ b/yarn.lock @@ -28741,6 +28741,11 @@ nanoid@3.1.20: resolved "https://registry.yarnpkg.com/nanoid/-/nanoid-3.1.20.tgz#badc263c6b1dcf14b71efaa85f6ab4c1d6cfc788" integrity sha512-a1cQNyczgKbLX9jwbS/+d7W8fX/RfgYR7lVWwWOGIPNgK2m0MWvrGF6/m4kk6U3QcFMnZf3RIhL0v2Jgh/0Uxw== +nanoid@3.1.31: + version "3.1.31" + resolved "https://registry.yarnpkg.com/nanoid/-/nanoid-3.1.31.tgz#f5b58a1ce1b7604da5f0605757840598d8974dc6" + integrity sha512-ZivnJm0o9bb13p2Ot5CpgC2rQdzB9Uxm/mFZweqm5eMViqOJe3PV6LU2E30SiLgheesmcPrjquqraoolONSA0A== + nanoid@3.2.0, nanoid@^3.1.16, nanoid@^3.1.22, nanoid@^3.1.23: version "3.2.0" resolved "https://registry.yarnpkg.com/nanoid/-/nanoid-3.2.0.tgz#62667522da6673971cca916a6d3eff3f415ff80c" From bf85d7cdae6395d11fcd5b4445e9f3f55e86bc85 Mon Sep 17 00:00:00 2001 From: Lachlan Miller Date: Wed, 23 Mar 2022 08:02:07 +1000 Subject: [PATCH 2/2] try using non secure nanoid --- packages/runner-shared/src/store.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/runner-shared/src/store.ts b/packages/runner-shared/src/store.ts index 567994a0ad18..26d11220ad2a 100644 --- a/packages/runner-shared/src/store.ts +++ b/packages/runner-shared/src/store.ts @@ -1,5 +1,5 @@ import { action, observable } from 'mobx' -import { nanoid } from 'nanoid' +import { nanoid } from 'nanoid/non-secure' export type RunMode = 'single' | 'multi'