Commit Graph

15 Commits

Author SHA1 Message Date
dependabot[bot]
afd7ca5b82 Bump ecstatic from 2.2.2 to 4.1.4 in /web
Bumps [ecstatic](https://github.com/jfhbrook/node-ecstatic) from 2.2.2 to 4.1.4.
- [Release notes](https://github.com/jfhbrook/node-ecstatic/releases)
- [Changelog](https://github.com/jfhbrook/node-ecstatic/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jfhbrook/node-ecstatic/compare/2.2.2...4.1.4)

Signed-off-by: dependabot[bot] <support@github.com>
2020-12-15 17:01:12 +00:00
grant_____
55b85e7021 Merge branch 'master' into master 2020-08-19 20:03:37 -04:00
Ian Galope
55e42234ac Update package-lock.json 2020-08-18 22:50:27 -04:00
Ian Galope
e6af86f744 Update package-lock.json 2020-08-18 22:47:31 -04:00
Ian Galope
6d4b5d9651 Update package-lock.json 2020-08-18 22:32:55 -04:00
Ian Galope
15d6645ded Update package-lock.json 2020-08-18 22:30:10 -04:00
Ian Galope
b438a32f29 Update package-lock.json 2020-08-18 21:58:54 -04:00
Ian Galope
d771671e3d Update package-lock.json 2020-08-18 20:39:59 -04:00
Ian Galope
da0e432db2 Update package-lock.json
CVE-2019-10744
critical severity
Vulnerable versions: < 4.6.2
Patched version: 4.6.2

Affected versions of lodash are vulnerable to Prototype Pollution.
The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
https://github.com/advisories/GHSA-jf85-cpcp-j695
2020-08-18 20:21:32 -04:00
dependabot[bot]
7b5975b8c2 Bump minimist from 1.2.0 to 1.2.3 in /web
Bumps [minimist](https://github.com/substack/minimist) from 1.2.0 to 1.2.3.
- [Release notes](https://github.com/substack/minimist/releases)
- [Commits](https://github.com/substack/minimist/compare/1.2.0...1.2.3)

Signed-off-by: dependabot[bot] <support@github.com>
2020-04-04 07:27:50 +00:00
grant_____
1714672ba1 Merge pull request #28 from sudomesh/dependabot/npm_and_yarn/web/ws-3.3.1
Bump ws from 3.1.0 to 3.3.1 in /web
2020-02-21 08:26:08 -05:00
dependabot[bot]
c5993500a3 Bump ws from 3.1.0 to 3.3.1 in /web
Bumps [ws](https://github.com/websockets/ws) from 3.1.0 to 3.3.1.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](https://github.com/websockets/ws/compare/3.1.0...3.3.1)

Signed-off-by: dependabot[bot] <support@github.com>
2019-11-12 20:09:28 +00:00
dependabot[bot]
503cdc717f Bump ecstatic from 2.2.1 to 2.2.2 in /web
Bumps [ecstatic](https://github.com/jfhbrook/node-ecstatic) from 2.2.1 to 2.2.2.
- [Release notes](https://github.com/jfhbrook/node-ecstatic/releases)
- [Changelog](https://github.com/jfhbrook/node-ecstatic/blob/2.2.2/CHANGELOG.md)
- [Commits](https://github.com/jfhbrook/node-ecstatic/compare/2.2.1...2.2.2)

Signed-off-by: dependabot[bot] <support@github.com>
2019-11-12 20:09:26 +00:00
Marc Juul
81bffce317 removed hmr 2018-08-11 20:43:28 -07:00
Marc Juul
2e384dcf4c checked in package-lock.json 2018-08-11 19:44:01 -07:00