Skip to content

Commit 83bc596

Browse files
committed
bug #848 Update resolve-url-loader to fix prototype pollution (Thomas Gnandt)
This PR was merged into the main branch. Discussion ---------- Update resolve-url-loader to fix prototype pollution See bholloway/resolve-url-loader#170 and https://npmjs.com/advisories/1573 Commits ------- d7717e1 update resolve-url-loader to fix prototype pollution
2 parents fdf90da + d7717e1 commit 83bc596

File tree

2 files changed

+16
-36
lines changed

2 files changed

+16
-36
lines changed

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@
4141
"optimize-css-assets-webpack-plugin": "^5.0.1",
4242
"pkg-up": "^3.1.0",
4343
"pretty-error": "^2.1.1",
44-
"resolve-url-loader": "^3.0.1",
44+
"resolve-url-loader": "^3.1.2",
4545
"semver": "^7.3.2",
4646
"style-loader": "^1.1.3",
4747
"terser-webpack-plugin": "^1.1.0",

yarn.lock

+15-35
Original file line numberDiff line numberDiff line change
@@ -1411,16 +1411,13 @@ acorn@^7.1.1:
14111411
resolved "https://registry.yarnpkg.com/acorn/-/acorn-7.4.0.tgz#e1ad486e6c54501634c6c397c5c121daa383607c"
14121412
integrity sha512-+G7P8jJmCHr+S+cLfQxygbWhXy+8YTVGzAkpEbcLo2mLoL7tij/VG41QSHACSf5QgYRhMZYHuNc6drJaO0Da+w==
14131413

1414-
adjust-sourcemap-loader@2.0.0:
1415-
version "2.0.0"
1416-
resolved "https://registry.yarnpkg.com/adjust-sourcemap-loader/-/adjust-sourcemap-loader-2.0.0.tgz#6471143af75ec02334b219f54bc7970c52fb29a4"
1417-
integrity sha512-4hFsTsn58+YjrU9qKzML2JSSDqKvN8mUGQ0nNIrfPi8hmIONT4L3uUaT6MKdMsZ9AjsU6D2xDkZxCkbQPxChrA==
1414+
adjust-sourcemap-loader@3.0.0:
1415+
version "3.0.0"
1416+
resolved "https://registry.yarnpkg.com/adjust-sourcemap-loader/-/adjust-sourcemap-loader-3.0.0.tgz#5ae12fb5b7b1c585e80bbb5a63ec163a1a45e61e"
1417+
integrity sha512-YBrGyT2/uVQ/c6Rr+t6ZJXniY03YtHGMJQYal368burRGYKqhx9qGTWqcBU5s1CwYY9E/ri63RYyG1IacMZtqw==
14181418
dependencies:
1419-
assert "1.4.1"
1420-
camelcase "5.0.0"
1421-
loader-utils "1.2.3"
1422-
object-path "0.11.4"
1423-
regex-parser "2.2.10"
1419+
loader-utils "^2.0.0"
1420+
regex-parser "^2.2.11"
14241421

14251422
ajv-errors@^1.0.0:
14261423
version "1.0.1"
@@ -1654,13 +1651,6 @@ [email protected], assert-plus@^1.0.0:
16541651
resolved "https://registry.yarnpkg.com/assert-plus/-/assert-plus-1.0.0.tgz#f12e0f3c5d77b0b1cdd9146942e4e96c1e4dd525"
16551652
integrity sha1-8S4PPF13sLHN2RRpQuTpbB5N1SU=
16561653

1657-
1658-
version "1.4.1"
1659-
resolved "https://registry.yarnpkg.com/assert/-/assert-1.4.1.tgz#99912d591836b5a6f5b345c0f07eefc08fc65d91"
1660-
integrity sha1-mZEtWRg2tab1s0XA8H7vwI/GXZE=
1661-
dependencies:
1662-
util "0.10.3"
1663-
16641654
assert@^1.1.1:
16651655
version "1.5.0"
16661656
resolved "https://registry.yarnpkg.com/assert/-/assert-1.5.0.tgz#55c109aaf6e0aefdb3dc4b71240c70bf574b18eb"
@@ -2169,11 +2159,6 @@ camelcase-keys@^2.0.0:
21692159
camelcase "^2.0.0"
21702160
map-obj "^1.0.0"
21712161

2172-
2173-
version "5.0.0"
2174-
resolved "https://registry.yarnpkg.com/camelcase/-/camelcase-5.0.0.tgz#03295527d58bd3cd4aa75363f35b2e8d97be2f42"
2175-
integrity sha512-faqwZqnWxbxn+F1d399ygeamQNy3lPp/H9H6rNrqYh4FSVCtcY+3cub1MxA8o9mDd55mM8Aghuu/kuyYA6VTsA==
2176-
21772162
[email protected], camelcase@^5.0.0, camelcase@^5.3.1:
21782163
version "5.3.1"
21792164
resolved "https://registry.yarnpkg.com/camelcase/-/camelcase-5.3.1.tgz#e3c9b31569e106811df242f715725a1f4c494320"
@@ -6115,11 +6100,6 @@ object-keys@^1.0.11, object-keys@^1.0.12, object-keys@^1.1.1:
61156100
resolved "https://registry.yarnpkg.com/object-keys/-/object-keys-1.1.1.tgz#1c47f272df277f3b1daf061677d9c82e2322c60e"
61166101
integrity sha512-NuAESUOUMrlIXOfHKzD6bpPu3tYt3xvjNdRIQ+FeT0lNb4K8WR70CaDxhuNguS2XG+GjkyMwOzsN5ZktImfhLA==
61176102

6118-
6119-
version "0.11.4"
6120-
resolved "https://registry.yarnpkg.com/object-path/-/object-path-0.11.4.tgz#370ae752fbf37de3ea70a861c23bba8915691949"
6121-
integrity sha1-NwrnUvvzfePqcKhhwju6iRVpGUk=
6122-
61236103
object-visit@^1.0.0:
61246104
version "1.0.1"
61256105
resolved "https://registry.yarnpkg.com/object-visit/-/object-visit-1.0.1.tgz#f79c4493af0c5377b59fe39d395e41042dd045bb"
@@ -7278,10 +7258,10 @@ regex-not@^1.0.0, regex-not@^1.0.2:
72787258
extend-shallow "^3.0.2"
72797259
safe-regex "^1.1.0"
72807260

7281-
7282-
version "2.2.10"
7283-
resolved "https://registry.yarnpkg.com/regex-parser/-/regex-parser-2.2.10.tgz#9e66a8f73d89a107616e63b39d4deddfee912b37"
7284-
integrity sha512-8t6074A68gHfU8Neftl0Le6KTDwfGAj7IyjPIMSfikI2wJUTHDMaIq42bUsfVnj8mhx0R+45rdUXHGpN164avA==
7261+
regex-parser@^2.2.11:
7262+
version "2.2.11"
7263+
resolved "https://registry.yarnpkg.com/regex-parser/-/regex-parser-2.2.11.tgz#3b37ec9049e19479806e878cabe7c1ca83ccfe58"
7264+
integrity sha512-jbD/FT0+9MBU2XAZluI7w2OBs1RBi6p9M83nkoZayQXXU9e8Robt69FcZc7wU4eJD/YFTjn1JdCk3rbMJajz8Q==
72857265

72867266
regexp.prototype.flags@^1.2.0:
72877267
version "1.3.0"
@@ -7435,12 +7415,12 @@ resolve-from@^4.0.0:
74357415
resolved "https://registry.yarnpkg.com/resolve-from/-/resolve-from-4.0.0.tgz#4abcd852ad32dd7baabfe9b40e00a36db5f392e6"
74367416
integrity sha512-pb/MYmXstAkysRFx8piNI1tGFNQIFA3vkE3Gq4EuA1dF6gHp/+vgZqsCGJapvy8N3Q+4o7FwvquPJcnZ7RYy4g==
74377417

7438-
resolve-url-loader@^3.0.1:
7439-
version "3.1.1"
7440-
resolved "https://registry.yarnpkg.com/resolve-url-loader/-/resolve-url-loader-3.1.1.tgz#28931895fa1eab9be0647d3b2958c100ae3c0bf0"
7441-
integrity sha512-K1N5xUjj7v0l2j/3Sgs5b8CjrrgtC70SmdCuZiJ8tSyb5J+uk3FoeZ4b7yTnH6j7ngI+Bc5bldHJIa8hYdu2gQ==
7418+
resolve-url-loader@^3.1.2:
7419+
version "3.1.2"
7420+
resolved "https://registry.yarnpkg.com/resolve-url-loader/-/resolve-url-loader-3.1.2.tgz#235e2c28e22e3e432ba7a5d4e305c59a58edfc08"
7421+
integrity sha512-QEb4A76c8Mi7I3xNKXlRKQSlLBwjUV/ULFMP+G7n3/7tJZ8MG5wsZ3ucxP1Jz8Vevn6fnJsxDx9cIls+utGzPQ==
74427422
dependencies:
7443-
adjust-sourcemap-loader "2.0.0"
7423+
adjust-sourcemap-loader "3.0.0"
74447424
camelcase "5.3.1"
74457425
compose-function "3.0.3"
74467426
convert-source-map "1.7.0"

0 commit comments

Comments
 (0)