From 74b74344f363a95e2916bf6bd21665acdbedeba6 Mon Sep 17 00:00:00 2001 From: John Williams Metservice <83933275+jwilliams-met@users.noreply.github.com> Date: Wed, 27 Mar 2024 17:58:57 +1300 Subject: [PATCH 1/2] Bump webpack-dev-middleware to patch high security issue webpack-dev-middleware 6.1.1 contains logged high risk, https://github.com/webpack/webpack-dev-middleware/security/advisories/GHSA-wr3j-pwj9-hqq6 --- code/builders/builder-webpack5/package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/code/builders/builder-webpack5/package.json b/code/builders/builder-webpack5/package.json index 00f9c9c1b5e9..5b767dc9389a 100644 --- a/code/builders/builder-webpack5/package.json +++ b/code/builders/builder-webpack5/package.json @@ -94,7 +94,7 @@ "util": "^0.12.4", "util-deprecate": "^1.0.2", "webpack": "5", - "webpack-dev-middleware": "^6.1.1", + "webpack-dev-middleware": "^6.1.2", "webpack-hot-middleware": "^2.25.1", "webpack-virtual-modules": "^0.5.0" }, From e7e74423f440970b8b87f2703a773bac2519b505 Mon Sep 17 00:00:00 2001 From: Valentin Palkovic Date: Wed, 27 Mar 2024 07:53:15 +0100 Subject: [PATCH 2/2] Update yarn.lock --- code/yarn.lock | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/code/yarn.lock b/code/yarn.lock index f4deb1517325..1b022371574c 100644 --- a/code/yarn.lock +++ b/code/yarn.lock @@ -5348,7 +5348,7 @@ __metadata: util: "npm:^0.12.4" util-deprecate: "npm:^1.0.2" webpack: "npm:5" - webpack-dev-middleware: "npm:^6.1.1" + webpack-dev-middleware: "npm:^6.1.2" webpack-hot-middleware: "npm:^2.25.1" webpack-virtual-modules: "npm:^0.5.0" peerDependenciesMeta: @@ -28914,7 +28914,7 @@ __metadata: languageName: node linkType: hard -"webpack-dev-middleware@npm:6.1.1, webpack-dev-middleware@npm:^6.1.1": +"webpack-dev-middleware@npm:6.1.1": version: 6.1.1 resolution: "webpack-dev-middleware@npm:6.1.1" dependencies: @@ -28947,6 +28947,24 @@ __metadata: languageName: node linkType: hard +"webpack-dev-middleware@npm:^6.1.2": + version: 6.1.2 + resolution: "webpack-dev-middleware@npm:6.1.2" + dependencies: + colorette: "npm:^2.0.10" + memfs: "npm:^3.4.12" + mime-types: "npm:^2.1.31" + range-parser: "npm:^1.2.1" + schema-utils: "npm:^4.0.0" + peerDependencies: + webpack: ^5.0.0 + peerDependenciesMeta: + webpack: + optional: true + checksum: 10c0/90c415a770c7db493f4a7d8f3308d761ff63249f628fa8a133eac5a61e849cdf658398e189fc2d95ce0ea884641363f964db6b269c6cea877765321dd7f14b9a + languageName: node + linkType: hard + "webpack-dev-server@npm:4.15.1": version: 4.15.1 resolution: "webpack-dev-server@npm:4.15.1"