From e85e1aae39bd4659eadd61c47304b2dac5788363 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 12 Feb 2024 02:12:15 +0000 Subject: [PATCH] fix: workspaces/libnpmpublish/package.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-IP-6240864 --- workspaces/libnpmpublish/package.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/workspaces/libnpmpublish/package.json b/workspaces/libnpmpublish/package.json index 1b6a53eae6156..fabf5317e9d27 100644 --- a/workspaces/libnpmpublish/package.json +++ b/workspaces/libnpmpublish/package.json @@ -25,7 +25,7 @@ "devDependencies": { "@npmcli/eslint-config": "^4.0.0", "@npmcli/mock-registry": "^1.0.0", - "@npmcli/template-oss": "4.11.4", + "@npmcli/template-oss": "4.20.0", "lodash.clonedeep": "^4.5.0", "nock": "^13.3.0", "tap": "^16.3.4" @@ -41,9 +41,9 @@ "ci-info": "^3.6.1", "normalize-package-data": "^5.0.0", "npm-package-arg": "^10.1.0", - "npm-registry-fetch": "^14.0.3", + "npm-registry-fetch": "^15.0.0", "semver": "^7.3.7", - "sigstore": "^1.0.0", + "sigstore": "^2.0.0", "ssri": "^10.0.1" }, "engines": {