From ad59690fc115c0c35024170d82140e7a66c99aa2 Mon Sep 17 00:00:00 2001 From: Andrew Bastin Date: Tue, 27 May 2025 16:27:03 +0530 Subject: [PATCH] chore: bump vulnerable dependencies --- package.json | 3 ++- pnpm-lock.yaml | 12 ++++++------ 2 files changed, 8 insertions(+), 7 deletions(-) diff --git a/package.json b/package.json index 526dc647..cb608711 100644 --- a/package.json +++ b/package.json @@ -52,7 +52,8 @@ "execa@0.10.0": "2.0.0", "@babel/runtime@<7.26.10": "7.26.10", "apiconnect-wsdl": "2.0.36", - "@xmldom/xmldom": "0.8.10" + "@xmldom/xmldom": "0.8.10", + "multer@1.4.5-lts.2": "2.0.0" }, "packageExtensions": { "@hoppscotch/httpsnippet": { diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 90953025..949169ef 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -23,6 +23,7 @@ overrides: '@babel/runtime@<7.26.10': 7.26.10 apiconnect-wsdl: 2.0.36 '@xmldom/xmldom': 0.8.10 + multer@1.4.5-lts.2: 2.0.0 packageExtensionsChecksum: sha256-Qhsch/G1LLagBL1kRb8nf11C5HcyCWi8Px3h3uWxYUw= @@ -10935,10 +10936,9 @@ packages: muggle-string@0.4.1: resolution: {integrity: sha512-VNTrAak/KhO2i8dqqnqnAHOa3cYBwXEZe9h+D5h/1ZqFSTEFHdM65lR7RoIqq3tBBYavsOXV84NoHXZ0AkPyqQ==} - multer@1.4.5-lts.2: - resolution: {integrity: sha512-VzGiVigcG9zUAoCNU+xShztrlr1auZOlurXynNvO9GiWD1/mTBbUljOKY+qMeazBqXgRnjzeEgJI/wyjJUHg9A==} - engines: {node: '>= 6.0.0'} - deprecated: Multer 1.x is impacted by a number of vulnerabilities, which have been patched in 2.x. You should upgrade to the latest 2.x version. + multer@2.0.0: + resolution: {integrity: sha512-bS8rPZurbAuHGAnApbM9d4h1wSoYqrOqkE+6a64KLMK9yWU7gJXBDDVklKQ3TPi9DRb85cRs6yXaC0+cjxRtRg==} + engines: {node: '>= 10.16.0'} mute-stream@0.0.8: resolution: {integrity: sha512-nnbWWOkoWyUsTjKrhgD0dcz22mdkSnpYqbEjIm2nhwhuxlSkpywJmBo8h0ZqJdkp73mb90SssHkN4rsRaBAfAA==} @@ -19596,7 +19596,7 @@ snapshots: '@nestjs/core': 11.1.1(@nestjs/common@11.1.1(class-transformer@0.5.1)(class-validator@0.14.2)(reflect-metadata@0.2.2)(rxjs@7.8.2))(@nestjs/platform-express@11.1.1)(reflect-metadata@0.2.2)(rxjs@7.8.2) cors: 2.8.5 express: 5.1.0 - multer: 1.4.5-lts.2 + multer: 2.0.0 path-to-regexp: 8.2.0 tslib: 2.8.1 transitivePeerDependencies: @@ -27368,7 +27368,7 @@ snapshots: muggle-string@0.4.1: {} - multer@1.4.5-lts.2: + multer@2.0.0: dependencies: append-field: 1.0.0 busboy: 1.6.0