5 Commits
Author SHA1 Message Date
Alex Rudenko 537c631ab8 Bump vulnerable deps
Drive-by: fixing the presubmit

Fixed: 343248814
Change-Id: I3ec86edbe2ce3d6e7b6a310827b5b5fb0b09c626
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/5720898
Commit-Queue: Alex Rudenko <alexrudenko@chromium.org>
Reviewed-by: Simon Zünd <szuend@chromium.org>
2024-07-19 07:12:02 +00:00
Guangyue Xu bffee6084d npm pakage security updates
Ran the following script to update engine.io and socket.io packages
to address the security issue tracked in crbug.com/1447254:

`npm run install-deps audit fix --audit-level=critical`

Bug: 1447254
Change-Id: Ia617b76882259bdab5259855029353701ff0bc1e
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4551951
Reviewed-by: Danil Somsikov <dsv@chromium.org>
Reviewed-by: Brandon Walderman <brwalder@microsoft.com>
Commit-Queue: Guangyue Xu <guangyue.xu@microsoft.com>
2023-05-23 16:50:12 +00:00
Brandon Walderman f64f77e749 Update node_modules to address security vulnerabilities
This change addresses 2 issues in uglify-js and socket.io-parser. See
reports below for details:
- https://www.mend.io/vulnerability-database/CVE-2022-37598
- https://nvd.nist.gov/vuln/detail/CVE-2022-2421

The socket.io-parser issue was addressed by running npm audit via the
following command:

`npm run install-deps audit fix --audit-level=critical`

Since audit didn't recognize the uglify-js issue, I updated uglify-js
to version 3.13.10 "manually" by adding an entry in
manage_node_deps.py. running install-deps to update package-lock.json
and then removing the entry from manage_node_deps.py.

Bug: None
Change-Id: I29238b14773a1b94b973886b0bb700f50e45cfa9
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4061168
Reviewed-by: Benedikt Meurer <bmeurer@chromium.org>
Commit-Queue: Brandon Walderman <brwalder@microsoft.com>
2022-11-30 15:19:46 +00:00
Brandon Walderman 110d5929d1 Upgrade minimist to 1.2.6
This CL updates minimist to 1.2.6 to fix a critical security
vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2021-44906

The fix was made by running:
`npm run install-deps audit fix --audit-level=critical`

Bug: none
Change-Id: I51103b525d9969e03000d55af86cebdabc7e0366
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/3591079
Reviewed-by: Mathias Bynens <mathias@chromium.org>
Commit-Queue: Brandon Walderman <brwalder@microsoft.com>
2022-04-20 06:33:45 +00:00
Tim van der Lippe d3425b95d0 Update unit test NPM dependencies
Updates Karma, Mocha and Sinon.

R=jacktfranklin@chromium.org

Bug: none
Change-Id: Ia93cdafc646e4d3277e7ce869a7a8b5e66a13f0d
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/3372928
Auto-Submit: Tim Van der Lippe <tvanderlippe@chromium.org>
Reviewed-by: Jack Franklin <jacktfranklin@chromium.org>
Commit-Queue: Tim Van der Lippe <tvanderlippe@chromium.org>
2022-01-07 14:26:50 +00:00