Skip to content

Commit a17ad89

Browse files
authored
Pin sha.js 2.4.12 in resolutions to fix CVE-2025-9288 (#384)
Signed-off-by: David Zane <[email protected]>
1 parent 873c10d commit a17ad89

File tree

2 files changed

+4
-11
lines changed

2 files changed

+4
-11
lines changed

package.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,8 @@
6060
"@babel/runtime": "^7.26.10",
6161
"@babel/runtime-corejs3": "^7.22.9",
6262
"pbkdf2": "3.1.5",
63-
"form-data": "4.0.4"
63+
"form-data": "4.0.4",
64+
"sha.js": "^2.4.12"
6465
},
6566
"devDependencies": {
6667
"@cypress/webpack-preprocessor": "^6.0.1",
@@ -90,4 +91,4 @@
9091
"node_modules/*",
9192
"target/*"
9293
]
93-
}
94+
}

yarn.lock

Lines changed: 1 addition & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -5694,15 +5694,7 @@ setimmediate@^1.0.4:
56945694
resolved "https://registry.yarnpkg.com/setimmediate/-/setimmediate-1.0.5.tgz#290cbb232e306942d7d7ea9b83732ab7856f8285"
56955695
integrity sha512-MATJdZp8sLqDl/68LfQmbP8zKPLQNV6BIZoIgrscFDQ+RsvK/BxeDQOgyxKKoh0y/8h3BqVFnCqQ/gd+reiIXA==
56965696

5697-
sha.js@^2.4.0, sha.js@^2.4.8:
5698-
version "2.4.11"
5699-
resolved "https://registry.yarnpkg.com/sha.js/-/sha.js-2.4.11.tgz#37a5cf0b81ecbc6943de109ba2960d1b26584ae7"
5700-
integrity sha512-QMEp5B7cftE7APOjk5Y6xgrbWu+WkLVQwk8JNjZ8nKRciZaByEW6MubieAiToS7+dwvrjGhH8jRXz3MVd0AYqQ==
5701-
dependencies:
5702-
inherits "^2.0.1"
5703-
safe-buffer "^5.0.1"
5704-
5705-
sha.js@^2.4.12:
5697+
sha.js@^2.4.0, sha.js@^2.4.12, sha.js@^2.4.8:
57065698
version "2.4.12"
57075699
resolved "https://registry.yarnpkg.com/sha.js/-/sha.js-2.4.12.tgz#eb8b568bf383dfd1867a32c3f2b74eb52bdbf23f"
57085700
integrity sha512-8LzC5+bvI45BjpfXU8V5fdU2mfeKiQe1D1gIMn7XUlF3OTUrpdJpPPH4EMAnF0DsHHdSZqCdSss5qCmJKuiO3w==

0 commit comments

Comments
 (0)