From 31b910dcb42dc6086422a3f067edc87784265d29 Mon Sep 17 00:00:00 2001 From: AWSHurneyt Date: Tue, 20 Jun 2023 16:20:32 -0700 Subject: [PATCH] Bumped decode-uri-component version to address CVE-2022-38900. (#400) (#403) (#578) Signed-off-by: AWSHurneyt --- package.json | 1 + yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/package.json b/package.json index 6f3ebe5b4..6160346ec 100644 --- a/package.json +++ b/package.json @@ -42,6 +42,7 @@ "react-vis": "^1.8.1" }, "resolutions": { + "decode-uri-component": "^0.2.1", "fstream": "1.0.12", "glob-parent": "^5.1.2" }, diff --git a/yarn.lock b/yarn.lock index 741d970e6..ede29a19b 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1335,10 +1335,10 @@ decamelize@^1.2.0: resolved "https://registry.yarnpkg.com/decamelize/-/decamelize-1.2.0.tgz#f6534d15148269b20352e7bee26f501f9a191290" integrity sha1-9lNNFRSCabIDUue+4m9QH5oZEpA= -decode-uri-component@^0.2.0: - version "0.2.0" - resolved "https://registry.yarnpkg.com/decode-uri-component/-/decode-uri-component-0.2.0.tgz#eb3913333458775cb84cd1a1fae062106bb87545" - integrity sha1-6zkTMzRYd1y4TNGh+uBiEGu4dUU= +decode-uri-component@^0.2.0, decode-uri-component@^0.2.1: + version "0.2.2" + resolved "https://registry.yarnpkg.com/decode-uri-component/-/decode-uri-component-0.2.2.tgz#e69dbe25d37941171dd540e024c444cd5188e1e9" + integrity sha512-FqUYQ+8o158GyGTrMFJms9qh3CqTKvAqgqsTnkLI8sKu0028orqBhxNMFkFen0zGyg6epACD32pjVk58ngIErQ== dedent@^0.7.0: version "0.7.0"