From a1d444955245f833a5c5bce03f605f477c388bbf Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 8 Apr 2019 00:00:31 +0000 Subject: [PATCH] fix: package.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-174129 - https://snyk.io/vuln/SNYK-JS-MARKED-174116 - https://snyk.io/vuln/SNYK-JS-TAR-174125 --- package.json | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) mode change 100755 => 100644 package.json diff --git a/package.json b/package.json old mode 100755 new mode 100644 index c9811d4..a8287b2 --- a/package.json +++ b/package.json @@ -84,7 +84,7 @@ "core-js": "^2.4.0", "cpx": "^1.5.0", "cross-env": "^3.2.4", - "css-loader": "^0.28.0", + "css-loader": "^1.0.0", "extract-text-webpack-plugin": "2.0.0-beta.4", "file-loader": "^0.11.1", "fs-extra": "^2.1.2", @@ -290,14 +290,14 @@ "cryptiles": "^2.0.5", "create-ecdh": "^4.0.0", "crypto-browserify": "^3.11.1", - "css-loader": "^0.28.4", + "css-loader": "^1.0.0", "core-util-is": "^1.0.2", "clone-stats": "^0.0.1", "css-select": "^1.2.0", "css-selector-tokenizer": "^0.7.0", "css-what": "^2.1.0", "cssesc": "^0.1.0", - "cssnano": "^3.10.0", + "cssnano": "^4.0.0", "currently-unhandled": "^0.4.1", "custom-event": "^1.0.1", "dashdash": "^1.14.1", @@ -603,7 +603,7 @@ "lodash.escape": "^3.2.0", "marked-terminal": "^1.7.0", "math-expression-evaluator": "^1.2.17", - "marked": "^0.3.6", + "marked": "^0.6.2", "media-typer": "^0.3.0", "meow": "^3.7.0", "memory-fs": "^0.4.1", @@ -637,7 +637,7 @@ "node-libs-browser": "^2.0.0", "node-notifier": "^4.6.1", "node-gyp": "^3.6.2", - "node-pre-gyp": "^0.6.36", + "node-pre-gyp": "^0.8.0", "node-sass": "^4.5.3", "nomnom": "^1.6.2", "normalize-package-data": "^2.4.0", @@ -732,7 +732,7 @@ "postcss-reduce-initial": "^1.0.1", "postcss-reduce-transforms": "^1.0.4", "postcss-ordered-values": "^2.2.3", - "postcss-svgo": "^2.1.6", + "postcss-svgo": "^4.0.0", "postcss-selector-parser": "^2.2.3", "postcss-normalize-charset": "^1.1.1", "postcss-unique-selectors": "^2.0.2", @@ -872,10 +872,10 @@ "strip-json-comments": "^2.0.1", "style-loader": "^0.16.1", "subarg": "^1.0.0", - "svgo": "^0.7.2", + "svgo": "^1.1.0", "symbol-observable": "^1.0.4", "tapable": "^0.2.6", - "tar": "^2.2.1", + "tar": "^4.4.2", "tar-pack": "^3.4.0", "through": "^2.3.8", "through2": "^2.0.1",