mirror of
https://github.com/react/react-native-devtools-frontend.git
synced 2026-09-28 21:24:26 +08:00
This change addresses 2 issues in uglify-js and socket.io-parser. See reports below for details: - https://www.mend.io/vulnerability-database/CVE-2022-37598 - https://nvd.nist.gov/vuln/detail/CVE-2022-2421 The socket.io-parser issue was addressed by running npm audit via the following command: `npm run install-deps audit fix --audit-level=critical` Since audit didn't recognize the uglify-js issue, I updated uglify-js to version 3.13.10 "manually" by adding an entry in manage_node_deps.py. running install-deps to update package-lock.json and then removing the entry from manage_node_deps.py. Bug: None Change-Id: I29238b14773a1b94b973886b0bb700f50e45cfa9 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4061168 Reviewed-by: Benedikt Meurer <bmeurer@chromium.org> Commit-Queue: Brandon Walderman <brwalder@microsoft.com>
51 lines
1.5 KiB
JavaScript
51 lines
1.5 KiB
JavaScript
const withNativeArrayBuffer = typeof ArrayBuffer === "function";
|
|
const isView = (obj) => {
|
|
return typeof ArrayBuffer.isView === "function"
|
|
? ArrayBuffer.isView(obj)
|
|
: obj.buffer instanceof ArrayBuffer;
|
|
};
|
|
const toString = Object.prototype.toString;
|
|
const withNativeBlob = typeof Blob === "function" ||
|
|
(typeof Blob !== "undefined" &&
|
|
toString.call(Blob) === "[object BlobConstructor]");
|
|
const withNativeFile = typeof File === "function" ||
|
|
(typeof File !== "undefined" &&
|
|
toString.call(File) === "[object FileConstructor]");
|
|
/**
|
|
* Returns true if obj is a Buffer, an ArrayBuffer, a Blob or a File.
|
|
*
|
|
* @private
|
|
*/
|
|
export function isBinary(obj) {
|
|
return ((withNativeArrayBuffer && (obj instanceof ArrayBuffer || isView(obj))) ||
|
|
(withNativeBlob && obj instanceof Blob) ||
|
|
(withNativeFile && obj instanceof File));
|
|
}
|
|
export function hasBinary(obj, toJSON) {
|
|
if (!obj || typeof obj !== "object") {
|
|
return false;
|
|
}
|
|
if (Array.isArray(obj)) {
|
|
for (let i = 0, l = obj.length; i < l; i++) {
|
|
if (hasBinary(obj[i])) {
|
|
return true;
|
|
}
|
|
}
|
|
return false;
|
|
}
|
|
if (isBinary(obj)) {
|
|
return true;
|
|
}
|
|
if (obj.toJSON &&
|
|
typeof obj.toJSON === "function" &&
|
|
arguments.length === 1) {
|
|
return hasBinary(obj.toJSON(), true);
|
|
}
|
|
for (const key in obj) {
|
|
if (Object.prototype.hasOwnProperty.call(obj, key) && hasBinary(obj[key])) {
|
|
return true;
|
|
}
|
|
}
|
|
return false;
|
|
}
|