Resolve CVE-2019-10744 (lodash-es dependency)

This commit is contained in:
Jonathan Abbett 2019-07-23 16:38:01 -04:00
parent 99a5ee32a1
commit 9eb495c9fe
4 changed files with 47 additions and 18 deletions

View File

@ -1,7 +1,7 @@
PATH
remote: .
specs:
abraham (1.5)
abraham (1.5.1)
rails (~> 5.1)
GEM

View File

@ -1,5 +1,5 @@
# frozen_string_literal: true
module Abraham
VERSION = "1.5"
VERSION = "1.5.1"
end

View File

@ -4,6 +4,6 @@
"dependencies": {
"jquery": "^3.4.0",
"js-cookie": "^2.2.0",
"shepherd.js": "^2.5.0"
"shepherd.js": "^3.1.0"
}
}

View File

@ -2,6 +2,11 @@
# yarn lockfile v1
body-scroll-lock@^2.6.1:
version "2.6.4"
resolved "https://registry.yarnpkg.com/body-scroll-lock/-/body-scroll-lock-2.6.4.tgz#567abc60ef4d656a79156781771398ef40462e94"
integrity sha512-NP08WsovlmxEoZP9pdlqrE+AhNaivlTrz9a0FF37BQsnOrpN48eNqivKkE7SYpM9N+YIPjsdVzfLAUQDBm6OQw==
element-matches@^0.1.2:
version "0.1.2"
resolved "https://registry.yarnpkg.com/element-matches/-/element-matches-0.1.2.tgz#7345cb71e965bd2b12f725e524591c102198361a"
@ -17,29 +22,53 @@ js-cookie@^2.2.0:
resolved "https://registry.yarnpkg.com/js-cookie/-/js-cookie-2.2.0.tgz#1b2c279a6eece380a12168b92485265b35b1effb"
integrity sha1-Gywnmm7s44ChIWi5JIUmWzWx7/s=
lodash-es@^4.17.11:
version "4.17.11"
resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.17.11.tgz#145ab4a7ac5c5e52a3531fb4f310255a152b4be0"
integrity sha512-DHb1ub+rMjjrxqlB3H56/6MXtm1lSksDp2rA2cNWjG8mlDUYFhUj3Di2Zn5IwSU87xLv8tNIQ7sSwE/YOX/D/Q==
lodash.defer@^4.1.0:
version "4.1.0"
resolved "https://registry.yarnpkg.com/lodash.defer/-/lodash.defer-4.1.0.tgz#e9c158a961de1a46ea24fda34685b4ccdd358f3f"
integrity sha1-6cFYqWHeGkbqJP2jRoW0zN01jz8=
lodash.iselement@^4.1.1:
version "4.1.1"
resolved "https://registry.yarnpkg.com/lodash.iselement/-/lodash.iselement-4.1.1.tgz#f678d4f6f3a964f9ec7f115f2546f3e4a0ba82ca"
integrity sha1-9njU9vOpZPnsfxFfJUbz5KC6gso=
lodash.isobjectlike@^4.0.0:
version "4.0.0"
resolved "https://registry.yarnpkg.com/lodash.isobjectlike/-/lodash.isobjectlike-4.0.0.tgz#742c5fc65add27924d3d24191681aa9a17b2b60d"
integrity sha1-dCxfxlrdJ5JNPSQZFoGqmheytg0=
lodash.zipobject@^4.1.3:
version "4.1.3"
resolved "https://registry.yarnpkg.com/lodash.zipobject/-/lodash.zipobject-4.1.3.tgz#b399f5aba8ff62a746f6979bf20b214f964dbef8"
integrity sha1-s5n1q6j/YqdG9peb8gshT5ZNvvg=
popper.js@^1.14.7:
version "1.14.7"
resolved "https://registry.yarnpkg.com/popper.js/-/popper.js-1.14.7.tgz#e31ec06cfac6a97a53280c3e55e4e0c860e7738e"
integrity sha512-4q1hNvoUre/8srWsH7hnoSJ5xVmIL4qgz+s4qf2TnJIMyZFUFMGH+9vE7mXynAlHSZ/NdTmmow86muD0myUkVQ==
shepherd.js@^2.5.0:
version "2.5.0"
resolved "https://registry.yarnpkg.com/shepherd.js/-/shepherd.js-2.5.0.tgz#c8fdc1fbaff55f1e021c930178d0e2b1cea7a7e3"
integrity sha512-DesuIO0wqlCWP6tWU/g5Qt//OfapVEamnvLBWwCBUB/AbrPtWomngi7MJmmkulTJGQz8F6FGnc3TSXK6bM9cOA==
shepherd.js@^3.1.0:
version "3.1.0"
resolved "https://registry.yarnpkg.com/shepherd.js/-/shepherd.js-3.1.0.tgz#743769a604ecc8174403fb53766a4b2609690fb5"
integrity sha512-Q6akYrPhNBClTxXQG5URAUc1tfimOAeah7EtZ+xqVcpSPo6BY41MxOrB/u5PZPDsGnjak4woJqhgpwo7UmAyiw==
dependencies:
body-scroll-lock "^2.6.1"
element-matches "^0.1.2"
lodash-es "^4.17.11"
popper.js "^1.14.7"
tippy.js "^4.0.1"
lodash.defer "^4.1.0"
lodash.iselement "^4.1.1"
lodash.isobjectlike "^4.0.0"
lodash.zipobject "^4.1.3"
smoothscroll-polyfill "^0.4.4"
tippy.js "^4.3.4"
tippy.js@^4.0.1:
version "4.2.0"
resolved "https://registry.yarnpkg.com/tippy.js/-/tippy.js-4.2.0.tgz#68387485cbc5d30ad5416bb01a20e63548898145"
integrity sha512-+WZRGtpIusZeJdZB2W5/rmOsT+6t3ASiQP0gln/OW1c+Goc6lx4vf+3i3KAJO875y7Vc1hGmFgyAMHor/eISBQ==
smoothscroll-polyfill@^0.4.4:
version "0.4.4"
resolved "https://registry.yarnpkg.com/smoothscroll-polyfill/-/smoothscroll-polyfill-0.4.4.tgz#3a259131dc6930e6ca80003e1cb03b603b69abf8"
integrity sha512-TK5ZA9U5RqCwMpfoMq/l1mrH0JAR7y7KRvOBx0n2869aLxch+gT9GhN3yUfjiw+d/DiF1mKo14+hd62JyMmoBg==
tippy.js@^4.3.4:
version "4.3.4"
resolved "https://registry.yarnpkg.com/tippy.js/-/tippy.js-4.3.4.tgz#9a91fd5ce8c401f181b7adaa6b2c27f3d105f3ba"
integrity sha512-O2ukxHOJTLVYZ/TfHjNd8WgAWoefX9uk5QiWRdHfX2PR2lBpUU4BJQLl7U2Ykc8K7o16gTeHEElpuRfgD5b0aA==
dependencies:
popper.js "^1.14.7"