mirror of
https://github.com/react/react-native-devtools-frontend.git
synced 2026-09-29 05:34:21 +08:00
This change addresses 2 issues in uglify-js and socket.io-parser. See reports below for details: - https://www.mend.io/vulnerability-database/CVE-2022-37598 - https://nvd.nist.gov/vuln/detail/CVE-2022-2421 The socket.io-parser issue was addressed by running npm audit via the following command: `npm run install-deps audit fix --audit-level=critical` Since audit didn't recognize the uglify-js issue, I updated uglify-js to version 3.13.10 "manually" by adding an entry in manage_node_deps.py. running install-deps to update package-lock.json and then removing the entry from manage_node_deps.py. Bug: None Change-Id: I29238b14773a1b94b973886b0bb700f50e45cfa9 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4061168 Reviewed-by: Benedikt Meurer <bmeurer@chromium.org> Commit-Queue: Brandon Walderman <brwalder@microsoft.com>
43 lines
993 B
JSON
43 lines
993 B
JSON
{
|
|
"name": "negotiator",
|
|
"description": "HTTP content negotiation",
|
|
"version": "0.6.3",
|
|
"contributors": [
|
|
"Douglas Christopher Wilson <doug@somethingdoug.com>",
|
|
"Federico Romero <federico.romero@outboxlabs.com>",
|
|
"Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)"
|
|
],
|
|
"license": "MIT",
|
|
"keywords": [
|
|
"http",
|
|
"content negotiation",
|
|
"accept",
|
|
"accept-language",
|
|
"accept-encoding",
|
|
"accept-charset"
|
|
],
|
|
"repository": "jshttp/negotiator",
|
|
"devDependencies": {
|
|
"eslint": "7.32.0",
|
|
"eslint-plugin-markdown": "2.2.1",
|
|
"mocha": "9.1.3",
|
|
"nyc": "15.1.0"
|
|
},
|
|
"files": [
|
|
"lib/",
|
|
"HISTORY.md",
|
|
"LICENSE",
|
|
"index.js",
|
|
"README.md"
|
|
],
|
|
"engines": {
|
|
"node": ">= 0.6"
|
|
},
|
|
"scripts": {
|
|
"lint": "eslint .",
|
|
"test": "mocha --reporter spec --check-leaks --bail test/",
|
|
"test-ci": "nyc --reporter=lcov --reporter=text npm test",
|
|
"test-cov": "nyc --reporter=html --reporter=text npm test"
|
|
}
|
|
}
|