Files
Brandon Walderman f64f77e749 Update node_modules to address security vulnerabilities
This change addresses 2 issues in uglify-js and socket.io-parser. See
reports below for details:
- https://www.mend.io/vulnerability-database/CVE-2022-37598
- https://nvd.nist.gov/vuln/detail/CVE-2022-2421

The socket.io-parser issue was addressed by running npm audit via the
following command:

`npm run install-deps audit fix --audit-level=critical`

Since audit didn't recognize the uglify-js issue, I updated uglify-js
to version 3.13.10 "manually" by adding an entry in
manage_node_deps.py. running install-deps to update package-lock.json
and then removing the entry from manage_node_deps.py.

Bug: None
Change-Id: I29238b14773a1b94b973886b0bb700f50e45cfa9
Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4061168
Reviewed-by: Benedikt Meurer <bmeurer@chromium.org>
Commit-Queue: Brandon Walderman <brwalder@microsoft.com>
2022-11-30 15:19:46 +00:00

43 lines
993 B
JSON

{
"name": "negotiator",
"description": "HTTP content negotiation",
"version": "0.6.3",
"contributors": [
"Douglas Christopher Wilson <doug@somethingdoug.com>",
"Federico Romero <federico.romero@outboxlabs.com>",
"Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
],
"license": "MIT",
"keywords": [
"http",
"content negotiation",
"accept",
"accept-language",
"accept-encoding",
"accept-charset"
],
"repository": "jshttp/negotiator",
"devDependencies": {
"eslint": "7.32.0",
"eslint-plugin-markdown": "2.2.1",
"mocha": "9.1.3",
"nyc": "15.1.0"
},
"files": [
"lib/",
"HISTORY.md",
"LICENSE",
"index.js",
"README.md"
],
"engines": {
"node": ">= 0.6"
},
"scripts": {
"lint": "eslint .",
"test": "mocha --reporter spec --check-leaks --bail test/",
"test-ci": "nyc --reporter=lcov --reporter=text npm test",
"test-cov": "nyc --reporter=html --reporter=text npm test"
}
}