Browse Source

fix: update flatted to 3.4.2 to fix prototype pollution (GHSA-rf6f-7fwh-wjgh)

copilot-swe-agent[bot] 1 week ago
parent
commit
4afa37ac8d
2 changed files with 6 additions and 4 deletions
  1. 5 4
      package-lock.json
  2. 1 0
      package.json

+ 5 - 4
package-lock.json

@@ -14,6 +14,7 @@
         "@actions/github": "^6.0.0",
         "@actions/io": "^1.1.3",
         "@actions/tool-cache": "^2.0.1",
+        "flatted": "^3.4.2",
         "uuid": "^9.0.1"
       },
       "devDependencies": {
@@ -3590,10 +3591,10 @@
       }
     },
     "node_modules/flatted": {
-      "version": "3.3.1",
-      "resolved": "https://registry.npmjs.org/flatted/-/flatted-3.3.1.tgz",
-      "integrity": "sha512-X8cqMLLie7KsNUDSdzeN8FYK9rEt4Dt67OsG/DNGnYTSDBG4uFAJFBnUeiV+zCVAvwFy56IjM9sH51jVaEhNxw==",
-      "dev": true
+      "version": "3.4.2",
+      "resolved": "https://registry.npmjs.org/flatted/-/flatted-3.4.2.tgz",
+      "integrity": "sha512-PjDse7RzhcPkIJwy5t7KPWQSZ9cAbzQXcafsetQoD7sOJRQlGikNbx7yZp2OotDnJyrDcbyRq3Ttb18iYOqkxA==",
+      "license": "ISC"
     },
     "node_modules/for-each": {
       "version": "0.3.3",

+ 1 - 0
package.json

@@ -33,6 +33,7 @@
     "@actions/github": "^6.0.0",
     "@actions/io": "^1.1.3",
     "@actions/tool-cache": "^2.0.1",
+    "flatted": "^3.4.2",
     "uuid": "^9.0.1"
   },
   "devDependencies": {