Skip to content
This repository was archived by the owner on Sep 25, 2024. It is now read-only.

Commit a42c560

Browse files
committed
chore: upgrade package versions for security patches.
1 parent ca0af12 commit a42c560

File tree

6 files changed

+37
-93
lines changed

6 files changed

+37
-93
lines changed

THIRDPARTY_LICENSES.txt

Lines changed: 15 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -10336,6 +10336,20 @@ SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
1033610336

1033710337
-----
1033810338

10339+
The following software may be included in this product: http-cache-semantics. A copy of the source code may be downloaded from https://github.com/kornelski/http-cache-semantics.git. This software contains the following license and notice below:
10340+
10341+
Copyright 2016-2018 Kornel Lesiński
10342+
10343+
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
10344+
10345+
1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
10346+
10347+
2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
10348+
10349+
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
10350+
10351+
-----
10352+
1033910353
The following software may be included in this product: http-errors. A copy of the source code may be downloaded from https://github.com/jshttp/http-errors.git. This software contains the following license and notice below:
1034010354

1034110355
The MIT License (MIT)
@@ -11280,7 +11294,7 @@ terms above.
1128011294

1128111295
-----
1128211296

11283-
The following software may be included in this product: lodash.debounce, lodash.get, lodash.includes, lodash.isinteger, lodash.isplainobject, lodash.once, lodash.throttle. A copy of the source code may be downloaded from https://github.com/lodash/lodash.git (lodash.debounce), https://github.com/lodash/lodash.git (lodash.get), https://github.com/lodash/lodash.git (lodash.includes), https://github.com/lodash/lodash.git (lodash.isinteger), https://github.com/lodash/lodash.git (lodash.isplainobject), https://github.com/lodash/lodash.git (lodash.once), https://github.com/lodash/lodash.git (lodash.throttle). This software contains the following license and notice below:
11297+
The following software may be included in this product: lodash.debounce, lodash.get, lodash.throttle. A copy of the source code may be downloaded from https://github.com/lodash/lodash.git (lodash.debounce), https://github.com/lodash/lodash.git (lodash.get), https://github.com/lodash/lodash.git (lodash.throttle). This software contains the following license and notice below:
1128411298

1128511299
Copyright jQuery Foundation and other contributors <https://jquery.org/>
1128611300

@@ -11332,33 +11346,6 @@ terms above.
1133211346

1133311347
-----
1133411348

11335-
The following software may be included in this product: lodash.isboolean, lodash.isnumber, lodash.isstring. A copy of the source code may be downloaded from https://github.com/lodash/lodash.git (lodash.isboolean), https://github.com/lodash/lodash.git (lodash.isnumber), https://github.com/lodash/lodash.git (lodash.isstring). This software contains the following license and notice below:
11336-
11337-
Copyright 2012-2016 The Dojo Foundation <http://dojofoundation.org/>
11338-
Based on Underscore.js, copyright 2009-2016 Jeremy Ashkenas,
11339-
DocumentCloud and Investigative Reporters & Editors <http://underscorejs.org/>
11340-
11341-
Permission is hereby granted, free of charge, to any person obtaining
11342-
a copy of this software and associated documentation files (the
11343-
"Software"), to deal in the Software without restriction, including
11344-
without limitation the rights to use, copy, modify, merge, publish,
11345-
distribute, sublicense, and/or sell copies of the Software, and to
11346-
permit persons to whom the Software is furnished to do so, subject to
11347-
the following conditions:
11348-
11349-
The above copyright notice and this permission notice shall be
11350-
included in all copies or substantial portions of the Software.
11351-
11352-
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
11353-
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
11354-
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
11355-
NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
11356-
LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
11357-
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
11358-
WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
11359-
11360-
-----
11361-
1136211349
The following software may be included in this product: lodash.isequal. A copy of the source code may be downloaded from https://github.com/lodash/lodash.git. This software contains the following license and notice below:
1136311350

1136411351
Copyright JS Foundation and other contributors <https://js.foundation/>

source/package.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@
5858
"@aws-cdk/aws-kinesisfirehose-destinations-alpha": "^2.53.0-alpha.0",
5959
"@aws-cdk/aws-lambda-python-alpha": "^2.53.0-alpha.0",
6060
"find-up": "^6.0.0",
61-
"json5": "^2.2.0",
61+
"json5": "^2.2.2",
6262
"lodash": "^4.17.21",
6363
"openapi-types": "^9.3.0",
6464
"short-unique-id": "^4.4.0",
@@ -155,7 +155,9 @@
155155
"minimatch": "^3.0.5",
156156
"decode-uri-component": "0.2.1",
157157
"qs": "^6.7.3",
158-
"express": "^4.17.3"
158+
"express": "^4.17.3",
159+
"http-cache-semantics": "^4.1.1",
160+
"json5": "~2.2.2"
159161
},
160162
"workspaces": {
161163
"packages": [

source/packages/@ada/infra/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@
8181
"esbuild": "0",
8282
"http-status-codes": "^2.1.4",
8383
"isomorphic-fetch": "^3.0.0",
84-
"jsonwebtoken": "^8.5.1",
84+
"jsonwebtoken": "^9.0.0",
8585
"jwk-to-pem": "^2.0.5",
8686
"jwt-decode": "^3.1.2",
8787
"lambda-log": "^3.1.0",

source/packages/@ada/infra/src/common/constructs/api/lambda-layer/code/nodejs/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
"isomorphic-fetch": "^3.0.0",
88
"lodash": "^4.17.21",
99
"pluralize": "^8.0.0",
10-
"jsonwebtoken": "^8.5.1",
10+
"jsonwebtoken": "^9.0.0",
1111
"aws-xray-sdk-core": "^3.3.6",
1212
"verror": "^1.10.1"
1313
},

source/packages/@ada/query-parse-render-lambdas/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@
5252
<dependency>
5353
<groupId>com.fasterxml.jackson.core</groupId>
5454
<artifactId>jackson-databind</artifactId>
55-
<version>2.12.4</version>
55+
<version>2.12.7.1</version>
5656
</dependency>
5757

5858
<dependency>

source/yarn.lock

Lines changed: 15 additions & 60 deletions
Original file line numberDiff line numberDiff line change
@@ -16329,10 +16329,10 @@ htmlparser2@^6.1.0:
1632916329
domutils "^2.5.2"
1633016330
entities "^2.0.0"
1633116331

16332-
http-cache-semantics@^4.0.0, http-cache-semantics@^4.1.0:
16333-
version "4.1.0"
16334-
resolved "https://registry.yarnpkg.com/http-cache-semantics/-/http-cache-semantics-4.1.0.tgz#49e91c5cbf36c9b94bcfcd71c23d5249ec74e390"
16335-
integrity sha512-carPklcUh7ROWRK7Cv27RPtdhYhUsela/ue5/jKzjegVvXDqM2ILE9Q2BGn9JZJh1g87cp56su/FgQSzcWS8cQ==
16332+
http-cache-semantics@^4.0.0, http-cache-semantics@^4.1.0, http-cache-semantics@^4.1.1:
16333+
version "4.1.1"
16334+
resolved "https://registry.yarnpkg.com/http-cache-semantics/-/http-cache-semantics-4.1.1.tgz#abe02fcb2985460bf0323be664436ec3476a6d5a"
16335+
integrity sha512-er295DKPVsV82j5kw1Gjt+ADA/XYHsajl82cGNQG2eyoPkvgUhX+nDIyelzhIWbbsXP39EHcI6l5tYs2FYqYXQ==
1633616336

1633716337
http-deceiver@^1.2.7:
1633816338
version "1.2.7"
@@ -18425,24 +18425,10 @@ json3@^3.3.3:
1842518425
resolved "https://registry.yarnpkg.com/json3/-/json3-3.3.3.tgz#7fc10e375fc5ae42c4705a5cc0aa6f62be305b81"
1842618426
integrity sha512-c7/8mbUsKigAbLkD5B010BK4D9LZm7A1pNItkEwiUZRpIN66exu/e7YQWysGun+TRKaJp8MhemM+VkfWv42aCA==
1842718427

18428-
json5@*, json5@2.x, json5@^2.1.2, json5@^2.1.3, json5@^2.2.0, json5@^2.x:
18429-
version "2.2.0"
18430-
resolved "https://registry.yarnpkg.com/json5/-/json5-2.2.0.tgz#2dfefe720c6ba525d9ebd909950f0515316c89a3"
18431-
integrity sha512-f+8cldu7X/y7RAJurMEJmdoKXGB/X550w2Nr3tTbezL6RwEE/iMcm+tZnXeoZtKuOq6ft8+CqzEkrIgx1fPoQA==
18432-
dependencies:
18433-
minimist "^1.2.5"
18434-
18435-
json5@^1.0.1:
18436-
version "1.0.1"
18437-
resolved "https://registry.yarnpkg.com/json5/-/json5-1.0.1.tgz#779fb0018604fa854eacbf6252180d83543e3dbe"
18438-
integrity sha512-aKS4WQjPenRxiQsC93MNfjx+nbF4PAdYzmd/1JIj8HYzqfbu86beTuNgXDzPknWk0n0uARlyewZo4s++ES36Ow==
18439-
dependencies:
18440-
minimist "^1.2.0"
18441-
18442-
json5@^2.2.1:
18443-
version "2.2.1"
18444-
resolved "https://registry.yarnpkg.com/json5/-/json5-2.2.1.tgz#655d50ed1e6f95ad1a3caababd2b0efda10b395c"
18445-
integrity sha512-1hqLFMSrGHRHxav9q9gNjJ5EXznIxGVO09xQRrwplcS8qs28pZ8s8hupZAmqDwZUmVZ2Qb2jnyPOWcDH8m8dlA==
18428+
json5@*, json5@2.x, json5@^1.0.1, json5@^2.1.2, json5@^2.1.3, json5@^2.2.0, json5@^2.2.1, json5@^2.2.2, json5@^2.x, json5@~2.2.2:
18429+
version "2.2.3"
18430+
resolved "https://registry.yarnpkg.com/json5/-/json5-2.2.3.tgz#78cd6f1a19bdc12b73db5ad0c61efd66c1e29283"
18431+
integrity sha512-XmOWe7eyHYH14cLdVPoyg+GOH3rYX++KpzrylJwSW98t3Nk+U8XOl8FWKOgwtzdb8lXGf6zYwDUzeHMWfxasyg==
1844618432

1844718433
jsonc-parser@3.0.0:
1844818434
version "3.0.0"
@@ -18492,21 +18478,15 @@ jsonschema@^1.4.1:
1849218478
resolved "https://registry.yarnpkg.com/jsonschema/-/jsonschema-1.4.1.tgz#cc4c3f0077fb4542982973d8a083b6b34f482dab"
1849318479
integrity sha512-S6cATIPVv1z0IlxdN+zUk5EPjkGCdnhN4wVSBlvoUO1tOLJootbo9CquNJmbIh4yikWHiUedhRYrNPn1arpEmQ==
1849418480

18495-
jsonwebtoken@^8.5.1:
18496-
version "8.5.1"
18497-
resolved "https://registry.yarnpkg.com/jsonwebtoken/-/jsonwebtoken-8.5.1.tgz#00e71e0b8df54c2121a1f26137df2280673bcc0d"
18498-
integrity sha512-XjwVfRS6jTMsqYs0EsuJ4LGxXV14zQybNd4L2r0UvbVnSF9Af8x7p5MzbJ90Ioz/9TI41/hTCvznF/loiSzn8w==
18481+
jsonwebtoken@^9.0.0:
18482+
version "9.0.0"
18483+
resolved "https://registry.yarnpkg.com/jsonwebtoken/-/jsonwebtoken-9.0.0.tgz#d0faf9ba1cc3a56255fe49c0961a67e520c1926d"
18484+
integrity sha512-tuGfYXxkQGDPnLJ7SibiQgVgeDgfbPq2k2ICcbgqW8WxWLBAxKQM/ZCu/IT8SOSwmaYl4dpTFCW5xZv7YbbWUw==
1849918485
dependencies:
1850018486
jws "^3.2.2"
18501-
lodash.includes "^4.3.0"
18502-
lodash.isboolean "^3.0.3"
18503-
lodash.isinteger "^4.0.4"
18504-
lodash.isnumber "^3.0.3"
18505-
lodash.isplainobject "^4.0.6"
18506-
lodash.isstring "^4.0.1"
18507-
lodash.once "^4.0.0"
18487+
lodash "^4.17.21"
1850818488
ms "^2.1.1"
18509-
semver "^5.6.0"
18489+
semver "^7.3.8"
1851018490

1851118491
jsprim@^1.2.2:
1851218492
version "1.4.1"
@@ -19107,16 +19087,6 @@ lodash.get@^4.4.2:
1910719087
resolved "https://registry.yarnpkg.com/lodash.get/-/lodash.get-4.4.2.tgz#2d177f652fa31e939b4438d5341499dfa3825e99"
1910819088
integrity sha1-LRd/ZS+jHpObRDjVNBSZ36OCXpk=
1910919089

19110-
lodash.includes@^4.3.0:
19111-
version "4.3.0"
19112-
resolved "https://registry.yarnpkg.com/lodash.includes/-/lodash.includes-4.3.0.tgz#60bb98a87cb923c68ca1e51325483314849f553f"
19113-
integrity sha1-YLuYqHy5I8aMoeUTJUgzFISfVT8=
19114-
19115-
lodash.isboolean@^3.0.3:
19116-
version "3.0.3"
19117-
resolved "https://registry.yarnpkg.com/lodash.isboolean/-/lodash.isboolean-3.0.3.tgz#6c2e171db2a257cd96802fd43b01b20d5f5870f6"
19118-
integrity sha1-bC4XHbKiV82WgC/UOwGyDV9YcPY=
19119-
1912019090
lodash.isequal@^4.5.0:
1912119091
version "4.5.0"
1912219092
resolved "https://registry.yarnpkg.com/lodash.isequal/-/lodash.isequal-4.5.0.tgz#415c4478f2bcc30120c22ce10ed3226f7d3e18e0"
@@ -19127,11 +19097,6 @@ lodash.isfunction@3.0.8:
1912719097
resolved "https://registry.yarnpkg.com/lodash.isfunction/-/lodash.isfunction-3.0.8.tgz#4db709fc81bc4a8fd7127a458a5346c5cdce2c6b"
1912819098
integrity sha1-TbcJ/IG8So/XEnpFilNGxc3OLGs=
1912919099

19130-
lodash.isinteger@^4.0.4:
19131-
version "4.0.4"
19132-
resolved "https://registry.yarnpkg.com/lodash.isinteger/-/lodash.isinteger-4.0.4.tgz#619c0af3d03f8b04c31f5882840b77b11cd68343"
19133-
integrity sha1-YZwK89A/iwTDH1iChAt3sRzWg0M=
19134-
1913519100
lodash.ismatch@^4.4.0:
1913619101
version "4.4.0"
1913719102
resolved "https://registry.yarnpkg.com/lodash.ismatch/-/lodash.ismatch-4.4.0.tgz#756cb5150ca3ba6f11085a78849645f188f85f37"
@@ -19142,21 +19107,11 @@ lodash.isnil@4.0.0:
1914219107
resolved "https://registry.yarnpkg.com/lodash.isnil/-/lodash.isnil-4.0.0.tgz#49e28cd559013458c814c5479d3c663a21bfaa6c"
1914319108
integrity sha1-SeKM1VkBNFjIFMVHnTxmOiG/qmw=
1914419109

19145-
lodash.isnumber@^3.0.3:
19146-
version "3.0.3"
19147-
resolved "https://registry.yarnpkg.com/lodash.isnumber/-/lodash.isnumber-3.0.3.tgz#3ce76810c5928d03352301ac287317f11c0b1ffc"
19148-
integrity sha1-POdoEMWSjQM1IwGsKHMX8RwLH/w=
19149-
1915019110
lodash.isplainobject@^4.0.6:
1915119111
version "4.0.6"
1915219112
resolved "https://registry.yarnpkg.com/lodash.isplainobject/-/lodash.isplainobject-4.0.6.tgz#7c526a52d89b45c45cc690b88163be0497f550cb"
1915319113
integrity sha1-fFJqUtibRcRcxpC4gWO+BJf1UMs=
1915419114

19155-
lodash.isstring@^4.0.1:
19156-
version "4.0.1"
19157-
resolved "https://registry.yarnpkg.com/lodash.isstring/-/lodash.isstring-4.0.1.tgz#d527dfb5456eca7cc9bb95d5daeaf88ba54a5451"
19158-
integrity sha1-1SfftUVuynzJu5XV2ur4i6VKVFE=
19159-
1916019115
lodash.isundefined@3.0.1:
1916119116
version "3.0.1"
1916219117
resolved "https://registry.yarnpkg.com/lodash.isundefined/-/lodash.isundefined-3.0.1.tgz#23ef3d9535565203a66cefd5b830f848911afb48"
@@ -19182,7 +19137,7 @@ lodash.omitby@4.6.0:
1918219137
resolved "https://registry.yarnpkg.com/lodash.omitby/-/lodash.omitby-4.6.0.tgz#5c15ff4754ad555016b53c041311e8f079204791"
1918319138
integrity sha1-XBX/R1StVVAWtTwEExHo8HkgR5E=
1918419139

19185-
lodash.once@^4.0.0, lodash.once@^4.1.1:
19140+
lodash.once@^4.1.1:
1918619141
version "4.1.1"
1918719142
resolved "https://registry.yarnpkg.com/lodash.once/-/lodash.once-4.1.1.tgz#0dd3971213c7c56df880977d504c88fb471a97ac"
1918819143
integrity sha1-DdOXEhPHxW34gJd9UEyI+0cal6w=

0 commit comments

Comments
 (0)