From 9bb46776b6e3ce88e5d9ed50d95115b3f842b6ef Mon Sep 17 00:00:00 2001 From: SanjalKatiyar Date: Thu, 19 Dec 2024 15:52:05 +0530 Subject: [PATCH] Fix 'cross-spawn' CVE --- package.json | 3 ++- yarn.lock | 8 ++++---- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index e013ed8d0..18492214c 100644 --- a/package.json +++ b/package.json @@ -178,7 +178,8 @@ "webpack": "5.94.0", "webpack-bundle-analyzer/ws": "^7.5.10", "webpack-dev-server/express": "^4.21.0", - "webpack-dev-server/ws": "^8.18.0" + "webpack-dev-server/ws": "^8.18.0", + "cross-spawn": "^7.0.6" }, "engines": { "node": ">=14.17.0" diff --git a/yarn.lock b/yarn.lock index 4c96909e5..cc37e0528 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3910,10 +3910,10 @@ cosmiconfig@^7.0.1: path-type "^4.0.0" yaml "^1.10.0" -cross-spawn@^7.0.0, cross-spawn@^7.0.2, cross-spawn@^7.0.3: - version "7.0.3" - resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.3.tgz#f73a85b9d5d41d045551c177e2882d4ac85728a6" - integrity sha512-iRDPJKUPVEND7dHPO8rkbOnPpyDygcDFtWjpeWNCgy8WP2rXcxXL8TskReQl6OrB2G7+UJrags1q15Fudc7G6w== +cross-spawn@^7.0.0, cross-spawn@^7.0.2, cross-spawn@^7.0.3, cross-spawn@^7.0.6: + version "7.0.6" + resolved "https://registry.yarnpkg.com/cross-spawn/-/cross-spawn-7.0.6.tgz#8a58fe78f00dcd70c370451759dfbfaf03e8ee9f" + integrity sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA== dependencies: path-key "^3.1.0" shebang-command "^2.0.0"