Skip to content

Commit 5a82bae

Browse files
authored
Merge pull request #8809 from BitGo/wcn-567
fix: bump vulnerable transitive dependencies
2 parents f450bda + d69ae10 commit 5a82bae

8 files changed

Lines changed: 82 additions & 51 deletions

File tree

modules/abstract-cosmos/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@
5050
"bignumber.js": "^9.1.1",
5151
"cosmjs-types": "^0.6.1",
5252
"lodash": "^4.18.0",
53-
"protobufjs": "^7.4.0",
53+
"protobufjs": "^7.5.8",
5454
"superagent": "^9.0.1"
5555
},
5656
"devDependencies": {

modules/sdk-api/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@
5353
"io-ts": "npm:@bitgo-forks/io-ts@2.1.4",
5454
"lodash": "^4.18.0",
5555
"proxy-agent": "6.4.0",
56-
"sanitize-html": "^2.11",
56+
"sanitize-html": "^2.17.4",
5757
"secp256k1": "5.0.1",
5858
"secrets.js-grempe": "^1.1.0",
5959
"superagent": "^9.0.1"

modules/sdk-coin-hbar/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@
4949
"bignumber.js": "^9.0.0",
5050
"lodash": "^4.18.0",
5151
"long": "^5.2.3",
52-
"protobufjs": "7.2.5",
52+
"protobufjs": "^7.5.8",
5353
"stellar-sdk": "^10.0.1",
5454
"tweetnacl": "^1.0.3"
5555
},

modules/sdk-coin-icp/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@
5555
"ic0": "^0.3.2",
5656
"js-sha256": "^0.9.0",
5757
"long": "^5.3.2",
58-
"protobufjs": "^7.5.0"
58+
"protobufjs": "^7.5.8"
5959
},
6060
"devDependencies": {
6161
"@bitgo/sdk-api": "^1.79.2",

modules/sdk-coin-islm/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@
5151
"cosmjs-types": "^0.6.1",
5252
"ethers": "^5.7.2",
5353
"keccak": "3.0.3",
54-
"protobufjs": "7.2.5"
54+
"protobufjs": "^7.5.8"
5555
},
5656
"devDependencies": {
5757
"@bitgo/sdk-api": "^1.79.2",

modules/sdk-coin-trx/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@
5555
"ethers": "^5.7.2",
5656
"lodash": "^4.18.0",
5757
"long": "^5.3.2",
58-
"protobufjs": "7.2.5",
58+
"protobufjs": "^7.5.8",
5959
"secp256k1": "5.0.1",
6060
"superagent": "^9.0.1",
6161
"tronweb": "5.1.0"

package.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@
7171
"**/cacache/glob": "11.1.0",
7272
"**/pacote/glob": "11.1.0",
7373
"**/sha.js": ">=2.4.12",
74-
"**/serialize-javascript": "7.0.3",
74+
"**/serialize-javascript": "7.0.5",
7575
"jspdf": ">=4.2.1",
7676
"@ethereumjs/util": "8.0.3",
7777
"@types/keyv": "3.1.4",
@@ -115,7 +115,7 @@
115115
"**/ethers/**/ws": "7.5.10",
116116
"**/swarm-js/**/ws": "5.2.4",
117117
"**/swarm-js/**/tar": "6.2.1",
118-
"serialize-javascript": "^6.0.2",
118+
"serialize-javascript": "7.0.5",
119119
"@grpc/grpc-js": "^1.12.6",
120120
"bigint-buffer": "npm:@trufflesuite/bigint-buffer@1.1.10",
121121
"request": "npm:@cypress/request@3.0.9",
@@ -131,7 +131,7 @@
131131
"picomatch": ">=2.3.2",
132132
"fast-uri": "3.1.2",
133133
"@babel/plugin-transform-modules-systemjs": "7.29.4",
134-
"protobufjs": "7.5.6"
134+
"protobufjs": "7.5.8"
135135
},
136136
"workspaces": [
137137
"modules/*"

yarn.lock

Lines changed: 73 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -4881,27 +4881,21 @@
48814881
integrity sha512-j9ednRT81vYJ9OfVuXG6ERSTdEL1xVsNgqpkxMsbIabzSo3goCjDIveeGv5d03om39ML71RdmrGNjG5SReBP/Q==
48824882

48834883
"@protobufjs/fetch@^1.1.0":
4884-
version "1.1.0"
4885-
resolved "https://registry.npmjs.org/@protobufjs/fetch/-/fetch-1.1.0.tgz"
4886-
integrity sha512-lljVXpqXebpsijW71PZaCYeIcE5on1w5DlQy5WH6GLbFryLUrBD4932W/E2BSpfRJWseIL4v/KPgBFxDOIdKpQ==
4884+
version "1.1.1"
4885+
resolved "https://registry.npmjs.org/@protobufjs/fetch/-/fetch-1.1.1.tgz#4d6fc00c8fb64016a5c81b469d549046350f1065"
4886+
integrity sha512-GpptLrs57adMSuHi3VNj0mAF8dwh36LMaYF6XyJ6JMWlVsc+t42tm1HSEDmOs3A8fC9yyeisgLhsTVQokOZ0zw==
48874887
dependencies:
48884888
"@protobufjs/aspromise" "^1.1.1"
4889-
"@protobufjs/inquire" "^1.1.0"
48904889

48914890
"@protobufjs/float@^1.0.2":
48924891
version "1.0.2"
48934892
resolved "https://registry.npmjs.org/@protobufjs/float/-/float-1.0.2.tgz"
48944893
integrity sha512-Ddb+kVXlXst9d+R9PfTIxh1EdNkgoRe5tOX6t01f1lYWOvJnSPDBlG241QLzcyPdoNTsblLUdujGSE4RzrTZGQ==
48954894

4896-
"@protobufjs/inquire@^1.1.0":
4897-
version "1.1.0"
4898-
resolved "https://registry.npmjs.org/@protobufjs/inquire/-/inquire-1.1.0.tgz"
4899-
integrity sha512-kdSefcPdruJiFMVSbn801t4vFK7KB/5gd2fYvrxhuJYg8ILrmn9SKSX2tZdV6V+ksulWqS7aXjBcRXl3wHoD9Q==
4900-
49014895
"@protobufjs/inquire@^1.1.1":
4902-
version "1.1.1"
4903-
resolved "https://registry.npmjs.org/@protobufjs/inquire/-/inquire-1.1.1.tgz#6cb936f4ac50965230af1e9d0bbfd57ea3675aa4"
4904-
integrity sha512-mnzgDV26ueAvk7rsbt9L7bE0SuAoqyuys/sMMrmVcN5x9VsxpcG3rqAUSgDyLp0UZlmNfIbQ4fHfCtreVBk8Ew==
4896+
version "1.1.2"
4897+
resolved "https://registry.npmjs.org/@protobufjs/inquire/-/inquire-1.1.2.tgz#ae64fbc014ff44c8bfad03dd4c93cd2d6a4c82db"
4898+
integrity sha512-pa0vFRuws4wkvaXKK1uXZMAwAX4/t8ANaJo45iw/oQHNQ9q5xUzwgFmVJGXiga2BeN+zpX7Vf9vmsiIa2J+MUw==
49054899

49064900
"@protobufjs/path@^1.1.2":
49074901
version "1.1.2"
@@ -9873,6 +9867,11 @@ dayjs@^1.10.4:
98739867
resolved "https://registry.npmjs.org/dayjs/-/dayjs-1.11.18.tgz"
98749868
integrity sha512-zFBQ7WFRvVRhKcWoUh+ZA1g2HVgUbsZm9sbddh8EC5iv93sui8DVVz1Npvz+r6meo9VKfa8NyLWBsQK1VvIKPA==
98759869

9870+
dayjs@^1.11.7:
9871+
version "1.11.20"
9872+
resolved "https://registry.npmjs.org/dayjs/-/dayjs-1.11.20.tgz#88d919fd639dc991415da5f4cb6f1b6650811938"
9873+
integrity sha512-YbwwqR/uYpeoP4pu043q+LTDLFBLApUP6VxRihdfNTqu4ubqMlGDLd6ErXhEgsyvY0K6nCs7nggYumAN+9uEuQ==
9874+
98769875
debounce@^1.2.1:
98779876
version "1.2.1"
98789877
resolved "https://registry.npmjs.org/debounce/-/debounce-1.2.1.tgz"
@@ -10366,9 +10365,9 @@ domutils@^2.5.2, domutils@^2.8.0:
1036610365
domelementtype "^2.2.0"
1036710366
domhandler "^4.2.0"
1036810367

10369-
domutils@^3.0.1:
10368+
domutils@^3.2.2:
1037010369
version "3.2.2"
10371-
resolved "https://registry.npmjs.org/domutils/-/domutils-3.2.2.tgz"
10370+
resolved "https://registry.npmjs.org/domutils/-/domutils-3.2.2.tgz#edbfe2b668b0c1d97c24baf0f1062b132221bc78"
1037210371
integrity sha512-6kZKyUajlDuqlHKVX1w7gyslj9MPIXzIFiz/rGu35uC1wMi+kMhQwGhl4lt9unC9Vb9INnY9Z3/ZA3+FhASLaw==
1037310372
dependencies:
1037410373
dom-serializer "^2.0.0"
@@ -10620,11 +10619,16 @@ entities@^2.0.0:
1062010619
resolved "https://registry.npmjs.org/entities/-/entities-2.2.0.tgz"
1062110620
integrity sha512-p92if5Nz619I0w+akJrLZH0MX0Pb5DX39XOwQTtXSdQQOaYH03S1uIQp4mhOZtAXrxq4ViO67YTiLBo2638o9A==
1062210621

10623-
entities@^4.2.0, entities@^4.4.0, entities@^4.5.0:
10622+
entities@^4.2.0, entities@^4.5.0:
1062410623
version "4.5.0"
1062510624
resolved "https://registry.npmjs.org/entities/-/entities-4.5.0.tgz"
1062610625
integrity sha512-V0hjH4dGPh9Ao5p0MoRY6BVqtwCjhz6vI5LT8AJ55H+4g9/4vbHx1I54fS0XuclLhDHArPQCiMjDxjaL8fPxhw==
1062710626

10627+
entities@^7.0.1:
10628+
version "7.0.1"
10629+
resolved "https://registry.npmjs.org/entities/-/entities-7.0.1.tgz#26e8a88889db63417dcb9a1e79a3f1bc92b5976b"
10630+
integrity sha512-TWrgLOFUQTH994YUyl1yT4uyavY5nNB5muff+RtWaqNVCAK408b5ZnnbNAUEWLTCpum9w6arT70i1XdQ4UeOPA==
10631+
1062810632
env-paths@^2.2.0, env-paths@^2.2.1:
1062910633
version "2.2.1"
1063010634
resolved "https://registry.npmjs.org/env-paths/-/env-paths-2.2.1.tgz"
@@ -12760,7 +12764,18 @@ html-minifier-terser@^6.0.2:
1276012764
tapable "^1.1.3"
1276112765
util.promisify "1.0.0"
1276212766

12763-
"html-webpack-plugin-5@npm:html-webpack-plugin@^5", html-webpack-plugin@^5.5.0:
12767+
"html-webpack-plugin-5@npm:html-webpack-plugin@^5":
12768+
version "5.6.4"
12769+
resolved "https://registry.npmjs.org/html-webpack-plugin/-/html-webpack-plugin-5.6.4.tgz"
12770+
integrity sha512-V/PZeWsqhfpE27nKeX9EO2sbR+D17A+tLf6qU+ht66jdUsN0QLKJN27Z+1+gHrVMKgndBahes0PU6rRihDgHTw==
12771+
dependencies:
12772+
"@types/html-minifier-terser" "^6.0.0"
12773+
html-minifier-terser "^6.0.2"
12774+
lodash "^4.17.21"
12775+
pretty-error "^4.0.0"
12776+
tapable "^2.0.0"
12777+
12778+
html-webpack-plugin@^5.5.0:
1276412779
version "5.6.4"
1276512780
resolved "https://registry.npmjs.org/html-webpack-plugin/-/html-webpack-plugin-5.6.4.tgz"
1276612781
integrity sha512-V/PZeWsqhfpE27nKeX9EO2sbR+D17A+tLf6qU+ht66jdUsN0QLKJN27Z+1+gHrVMKgndBahes0PU6rRihDgHTw==
@@ -12784,6 +12799,16 @@ htmlescape@^1.1.0:
1278412799
resolved "https://registry.npmjs.org/htmlescape/-/htmlescape-1.1.1.tgz"
1278512800
integrity sha512-eVcrzgbR4tim7c7soKQKtxa/kQM4TzjnlU83rcZ9bHU6t31ehfV7SktN6McWgwPWg+JYMA/O3qpGxBvFq1z2Jg==
1278612801

12802+
htmlparser2@^10.1.0:
12803+
version "10.1.0"
12804+
resolved "https://registry.npmjs.org/htmlparser2/-/htmlparser2-10.1.0.tgz#fe3f2e12c73b6e462d4e10395db9c1119e4d6ae4"
12805+
integrity sha512-VTZkM9GWRAtEpveh7MSF6SjjrpNVNNVJfFup7xTY3UpFtm67foy9HDVXneLtFVt4pMz5kZtgNcvCniNFb1hlEQ==
12806+
dependencies:
12807+
domelementtype "^2.3.0"
12808+
domhandler "^5.0.3"
12809+
domutils "^3.2.2"
12810+
entities "^7.0.1"
12811+
1278712812
htmlparser2@^6.1.0:
1278812813
version "6.1.0"
1278912814
resolved "https://registry.npmjs.org/htmlparser2/-/htmlparser2-6.1.0.tgz"
@@ -12794,16 +12819,6 @@ htmlparser2@^6.1.0:
1279412819
domutils "^2.5.2"
1279512820
entities "^2.0.0"
1279612821

12797-
htmlparser2@^8.0.0:
12798-
version "8.0.2"
12799-
resolved "https://registry.npmjs.org/htmlparser2/-/htmlparser2-8.0.2.tgz"
12800-
integrity sha512-GYdjWKDkbRLkZ5geuHs5NY1puJ+PXwP7+fHPRz06Eirsb9ugf6d8kkXav6ADhcODhFFPMIXyxkxSuMf3D6NCFA==
12801-
dependencies:
12802-
domelementtype "^2.3.0"
12803-
domhandler "^5.0.3"
12804-
domutils "^3.0.1"
12805-
entities "^4.4.0"
12806-
1280712822
http-cache-semantics@^4.0.0, http-cache-semantics@^4.1.0, http-cache-semantics@^4.1.1:
1280812823
version "4.2.0"
1280912824
resolved "https://registry.npmjs.org/http-cache-semantics/-/http-cache-semantics-4.2.0.tgz"
@@ -12912,7 +12927,7 @@ https-browserify@^1.0.0:
1291212927

1291312928
https-proxy-agent@^5.0.0:
1291412929
version "5.0.1"
12915-
resolved "https://registry.npmjs.org/https-proxy-agent/-/https-proxy-agent-5.0.1.tgz"
12930+
resolved "https://registry.npmjs.org/https-proxy-agent/-/https-proxy-agent-5.0.1.tgz#c59ef224a04fe8b754f3db0063a25ea30d0005d6"
1291612931
integrity sha512-dFcAjpTQFgoLMzC2VwU+C/CbS7uRL0lWmxDITmqm7C+7F0Odmj6s9l6alZc6AELXhrnggM2CeWSXHGOdX2YtwA==
1291712932
dependencies:
1291812933
agent-base "6"
@@ -14316,6 +14331,13 @@ launch-editor@^2.6.1:
1431614331
picocolors "^1.1.1"
1431714332
shell-quote "^1.8.3"
1431814333

14334+
launder@^1.7.1:
14335+
version "1.7.1"
14336+
resolved "https://registry.npmjs.org/launder/-/launder-1.7.1.tgz#ef7155ab0c3ddec2323089c961d2e9a249aa5b0d"
14337+
integrity sha512-mU6WRz5EusL9ZZuiZ5SO4Y6C0P9PAUR9iwdb6bzj4KDihm28DiHFw+/yk9DBH4f+Pv1wuzQ4e2jV3oQ7mkIqvw==
14338+
dependencies:
14339+
dayjs "^1.11.7"
14340+
1431914341
lazy-ass@^1.6.0:
1432014342
version "1.6.0"
1432114343
resolved "https://registry.npmjs.org/lazy-ass/-/lazy-ass-1.6.0.tgz"
@@ -17485,10 +17507,10 @@ propagate@^2.0.0:
1748517507
resolved "https://registry.npmjs.org/propagate/-/propagate-2.0.1.tgz"
1748617508
integrity sha512-vGrhOavPSTz4QVNuBNdcNXePNdNMaO1xj9yBeH1ScQPjk/rhg9sSlCXPhMkFuaNNW/syTvYqsnbIJxMBfRbbag==
1748717509

17488-
protobufjs@7.2.5, protobufjs@7.5.6, protobufjs@^6.8.8, protobufjs@^7.2.5, protobufjs@^7.4.0, protobufjs@^7.5.0, protobufjs@~6.11.2, protobufjs@~6.11.3:
17489-
version "7.5.6"
17490-
resolved "https://registry.npmjs.org/protobufjs/-/protobufjs-7.5.6.tgz#11af832ebc4b4326f658a5b1308e6141eb57edfd"
17491-
integrity sha512-M71sTMB146U3u0di3yup8iM+zv8yPRNQVr1KK4tyBitl3qFvEGucq/rGDRShD2rsJhtN02RJaJ7j5X5hmy8SJg==
17510+
protobufjs@7.2.5, protobufjs@7.5.8, protobufjs@^6.8.8, protobufjs@^7.2.5, protobufjs@^7.5.8, protobufjs@~6.11.2, protobufjs@~6.11.3:
17511+
version "7.5.8"
17512+
resolved "https://registry.npmjs.org/protobufjs/-/protobufjs-7.5.8.tgz#51b153a06da6e47153a1aa6800cb1253bc502436"
17513+
integrity sha512-dvpCIeLPbXZS/Ete7yLaO7RenOdken2NHKykBXbsaGxZT0UTltcarBciw+A78SRQs9iMAAVpsYA+l8b1hTePIA==
1749217514
dependencies:
1749317515
"@protobufjs/aspromise" "^1.1.2"
1749417516
"@protobufjs/base64" "^1.1.2"
@@ -18451,15 +18473,16 @@ safe-stable-stringify@^2.3.1:
1845118473
resolved "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz"
1845218474
integrity sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==
1845318475

18454-
sanitize-html@^2.11:
18455-
version "2.17.0"
18456-
resolved "https://registry.npmjs.org/sanitize-html/-/sanitize-html-2.17.0.tgz"
18457-
integrity sha512-dLAADUSS8rBwhaevT12yCezvioCA+bmUTPH/u57xKPT8d++voeYE6HeluA/bPbQ15TwDBG2ii+QZIEmYx8VdxA==
18476+
sanitize-html@^2.17.4:
18477+
version "2.17.4"
18478+
resolved "https://registry.npmjs.org/sanitize-html/-/sanitize-html-2.17.4.tgz#7db8b73b0024ccf543978c2a44da8223c4740cb1"
18479+
integrity sha512-2HW7v2ol/uAM7sX4hbD8Z59OGWmAPrvjL8E71UWlBcj6m+kcF6ilQBLny+cIgY214QJeJT5tQuxKKqX0SQqjGQ==
1845818480
dependencies:
1845918481
deepmerge "^4.2.2"
1846018482
escape-string-regexp "^4.0.0"
18461-
htmlparser2 "^8.0.0"
18483+
htmlparser2 "^10.1.0"
1846218484
is-plain-object "^5.0.0"
18485+
launder "^1.7.1"
1846318486
parse-srcset "^1.0.2"
1846418487
postcss "^8.3.11"
1846518488

@@ -18604,10 +18627,10 @@ send@0.19.0:
1860418627
range-parser "~1.2.1"
1860518628
statuses "2.0.1"
1860618629

18607-
serialize-javascript@7.0.3, serialize-javascript@^6.0.0, serialize-javascript@^6.0.2:
18608-
version "7.0.3"
18609-
resolved "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.3.tgz#c92008d8a21bc7b2307c2e885a4bd0f03b2aee6c"
18610-
integrity sha512-h+cZ/XXarqDgCjo+YSyQU/ulDEESGGf8AMK9pPNmhNSl/FzPl6L8pMp1leca5z6NuG6tvV/auC8/43tmovowww==
18630+
serialize-javascript@7.0.5, serialize-javascript@^6.0.0, serialize-javascript@^6.0.2:
18631+
version "7.0.5"
18632+
resolved "https://registry.npmjs.org/serialize-javascript/-/serialize-javascript-7.0.5.tgz#c798cc0552ffbb08981914a42a8756e339d0d5b1"
18633+
integrity sha512-F4LcB0UqUl1zErq+1nYEEzSHJnIwb3AF2XWB94b+afhrekOUijwooAYqFyRbjYkm2PAKBabx6oYv/xDxNi8IBw==
1861118634

1861218635
serve-index@^1.9.1:
1861318636
version "1.9.1"
@@ -21262,8 +21285,7 @@ workerpool@^6.5.1:
2126221285
resolved "https://registry.npmjs.org/workerpool/-/workerpool-6.5.1.tgz"
2126321286
integrity sha512-Fs4dNYcsdpYSAfVxhnl1L5zTksjvOJxtC5hzMNl+1t9B8hTJTdKDyZ5ju7ztgPy+ft9tBFXoOlDNiOT9WUXZlA==
2126421287

21265-
"wrap-ansi-cjs@npm:wrap-ansi@^7.0.0", wrap-ansi@^7.0.0:
21266-
name wrap-ansi-cjs
21288+
"wrap-ansi-cjs@npm:wrap-ansi@^7.0.0":
2126721289
version "7.0.0"
2126821290
resolved "https://registry.npmjs.org/wrap-ansi/-/wrap-ansi-7.0.0.tgz"
2126921291
integrity sha512-YVGIj2kamLSTxw6NsZjoBxfSwsn0ycdesmc4p+Q21c5zPuZ1pl+NfxVdxPtdHvmNVOQ6XSYG4AUtyt/Fi7D16Q==
@@ -21281,6 +21303,15 @@ wrap-ansi@^6.2.0:
2128121303
string-width "^4.1.0"
2128221304
strip-ansi "^6.0.0"
2128321305

21306+
wrap-ansi@^7.0.0:
21307+
version "7.0.0"
21308+
resolved "https://registry.npmjs.org/wrap-ansi/-/wrap-ansi-7.0.0.tgz"
21309+
integrity sha512-YVGIj2kamLSTxw6NsZjoBxfSwsn0ycdesmc4p+Q21c5zPuZ1pl+NfxVdxPtdHvmNVOQ6XSYG4AUtyt/Fi7D16Q==
21310+
dependencies:
21311+
ansi-styles "^4.0.0"
21312+
string-width "^4.1.0"
21313+
strip-ansi "^6.0.0"
21314+
2128421315
wrap-ansi@^8.1.0:
2128521316
version "8.1.0"
2128621317
resolved "https://registry.npmjs.org/wrap-ansi/-/wrap-ansi-8.1.0.tgz"

0 commit comments

Comments
 (0)