Skip to content

Commit 347143d

Browse files
[release-1.16] Pin xml-crypto to 2.1.6 (#183)
Pin xml-crypto to 2.1.6 due to a CVE Signed-off-by: Ali Ok <aliok@redhat.com> Co-authored-by: Ali Ok <aliok@redhat.com>
1 parent 61ba03e commit 347143d

File tree

2 files changed

+9
-33
lines changed

2 files changed

+9
-33
lines changed

backstage/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,8 @@
4646
"@types/react-dom": "^17",
4747
"dompurify": "^3.2.4",
4848
"@octokit/plugin-paginate-rest": "11.4.1",
49-
"@octokit/endpoint": "10.1.3"
49+
"@octokit/endpoint": "10.1.3",
50+
"xml-crypto": "2.1.6"
5051
},
5152
"prettier": "@spotify/prettier-config",
5253
"lint-staged": {

backstage/yarn.lock

Lines changed: 7 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -23606,16 +23606,7 @@ string-length@^4.0.1:
2360623606
char-regex "^1.0.2"
2360723607
strip-ansi "^6.0.0"
2360823608

23609-
"string-width-cjs@npm:string-width@^4.2.0":
23610-
version "4.2.3"
23611-
resolved "https://registry.yarnpkg.com/string-width/-/string-width-4.2.3.tgz#269c7117d27b05ad2e536830a8ec895ef9c6d010"
23612-
integrity sha512-wKyQRQpjJ0sIp62ErSZdGsjMJWsap5oRNihHhu6G7JVO/9jIB6UyevL+tXuOqrng8j/cxKTWyWUwvSTriiZz/g==
23613-
dependencies:
23614-
emoji-regex "^8.0.0"
23615-
is-fullwidth-code-point "^3.0.0"
23616-
strip-ansi "^6.0.1"
23617-
23618-
"string-width@^1.0.2 || 2 || 3 || 4", string-width@^4.1.0, string-width@^4.2.0, string-width@^4.2.3:
23609+
"string-width-cjs@npm:string-width@^4.2.0", "string-width@^1.0.2 || 2 || 3 || 4", string-width@^4.1.0, string-width@^4.2.0, string-width@^4.2.3:
2361923610
version "4.2.3"
2362023611
resolved "https://registry.yarnpkg.com/string-width/-/string-width-4.2.3.tgz#269c7117d27b05ad2e536830a8ec895ef9c6d010"
2362123612
integrity sha512-wKyQRQpjJ0sIp62ErSZdGsjMJWsap5oRNihHhu6G7JVO/9jIB6UyevL+tXuOqrng8j/cxKTWyWUwvSTriiZz/g==
@@ -23689,7 +23680,7 @@ string_decoder@~1.1.1:
2368923680
dependencies:
2369023681
safe-buffer "~5.1.0"
2369123682

23692-
"strip-ansi-cjs@npm:strip-ansi@^6.0.1":
23683+
"strip-ansi-cjs@npm:strip-ansi@^6.0.1", strip-ansi@^6.0.0, strip-ansi@^6.0.1:
2369323684
version "6.0.1"
2369423685
resolved "https://registry.yarnpkg.com/strip-ansi/-/strip-ansi-6.0.1.tgz#9e26c63d30f53443e9489495b2105d37b67a85d9"
2369523686
integrity sha512-Y38VPSHcqkFrCpFnQ9vuSXmquuv5oXOKpGeT6aGrr3o3Gc9AlVa6JBfUSOCnbxGGZF+/0ooI7KrPuUSztUdU5A==
@@ -23703,13 +23694,6 @@ strip-ansi@5.2.0:
2370323694
dependencies:
2370423695
ansi-regex "^4.1.0"
2370523696

23706-
strip-ansi@^6.0.0, strip-ansi@^6.0.1:
23707-
version "6.0.1"
23708-
resolved "https://registry.yarnpkg.com/strip-ansi/-/strip-ansi-6.0.1.tgz#9e26c63d30f53443e9489495b2105d37b67a85d9"
23709-
integrity sha512-Y38VPSHcqkFrCpFnQ9vuSXmquuv5oXOKpGeT6aGrr3o3Gc9AlVa6JBfUSOCnbxGGZF+/0ooI7KrPuUSztUdU5A==
23710-
dependencies:
23711-
ansi-regex "^5.0.1"
23712-
2371323697
strip-ansi@^7.0.1:
2371423698
version "7.1.0"
2371523699
resolved "https://registry.yarnpkg.com/strip-ansi/-/strip-ansi-7.1.0.tgz#d5b6568ca689d8561370b0707685d22434faff45"
@@ -25622,7 +25606,7 @@ wordwrap@^1.0.0:
2562225606
resolved "https://registry.yarnpkg.com/wordwrap/-/wordwrap-1.0.0.tgz#27584810891456a4171c8d0226441ade90cbcaeb"
2562325607
integrity sha512-gvVzJFlPycKc5dZN4yPkP8w7Dc37BtP1yczEneOb4uq34pXZcvrtRTmWV8W+Ume+XCxKgbjM+nevkyFPMybd4Q==
2562425608

25625-
"wrap-ansi-cjs@npm:wrap-ansi@^7.0.0":
25609+
"wrap-ansi-cjs@npm:wrap-ansi@^7.0.0", wrap-ansi@^7.0.0:
2562625610
version "7.0.0"
2562725611
resolved "https://registry.yarnpkg.com/wrap-ansi/-/wrap-ansi-7.0.0.tgz#67e145cff510a6a6984bdf1152911d69d2eb9e43"
2562825612
integrity sha512-YVGIj2kamLSTxw6NsZjoBxfSwsn0ycdesmc4p+Q21c5zPuZ1pl+NfxVdxPtdHvmNVOQ6XSYG4AUtyt/Fi7D16Q==
@@ -25640,15 +25624,6 @@ wrap-ansi@^6.0.1:
2564025624
string-width "^4.1.0"
2564125625
strip-ansi "^6.0.0"
2564225626

25643-
wrap-ansi@^7.0.0:
25644-
version "7.0.0"
25645-
resolved "https://registry.yarnpkg.com/wrap-ansi/-/wrap-ansi-7.0.0.tgz#67e145cff510a6a6984bdf1152911d69d2eb9e43"
25646-
integrity sha512-YVGIj2kamLSTxw6NsZjoBxfSwsn0ycdesmc4p+Q21c5zPuZ1pl+NfxVdxPtdHvmNVOQ6XSYG4AUtyt/Fi7D16Q==
25647-
dependencies:
25648-
ansi-styles "^4.0.0"
25649-
string-width "^4.1.0"
25650-
strip-ansi "^6.0.0"
25651-
2565225627
wrap-ansi@^8.1.0:
2565325628
version "8.1.0"
2565425629
resolved "https://registry.yarnpkg.com/wrap-ansi/-/wrap-ansi-8.1.0.tgz#56dc22368ee570face1b49819975d9b9a5ead214"
@@ -25731,10 +25706,10 @@ xml-but-prettier@^1.0.1:
2573125706
dependencies:
2573225707
repeat-string "^1.5.2"
2573325708

25734-
xml-crypto@^2.1.3:
25735-
version "2.1.5"
25736-
resolved "https://registry.yarnpkg.com/xml-crypto/-/xml-crypto-2.1.5.tgz#e201ee51dca18dd9ae158ac101b6e995c983dca8"
25737-
integrity sha512-xOSJmGFm+BTXmaPYk8pPV3duKo6hJuZ5niN4uMzoNcTlwYs0jAu/N3qY+ud9MhE4N7eMRuC1ayC7Yhmb7MmAWg==
25709+
xml-crypto@2.1.6, xml-crypto@^2.1.3:
25710+
version "2.1.6"
25711+
resolved "https://registry.yarnpkg.com/xml-crypto/-/xml-crypto-2.1.6.tgz#c51a016cc8391fc1d9ebd9abc589e4c08b62d652"
25712+
integrity sha512-jjvpO8vHNV8QFhW5bMypP+k4BjBqHe/HrpIwpPcdUnUTIJakSIuN96o3Sdah4tKu2z64kM/JHEH8iEHGCc6Gyw==
2573825713
dependencies:
2573925714
"@xmldom/xmldom" "^0.7.9"
2574025715
xpath "0.0.32"

0 commit comments

Comments
 (0)