diff --git a/changelog.d/705.misc b/changelog.d/705.misc new file mode 100644 index 00000000..8b4985e5 --- /dev/null +++ b/changelog.d/705.misc @@ -0,0 +1 @@ +Update dependency used in Generic Webhook JS functions to fix a security flaw. diff --git a/package.json b/package.json index bba0c179..14dd4846 100644 --- a/package.json +++ b/package.json @@ -67,7 +67,7 @@ "source-map-support": "^0.5.21", "string-argv": "^0.3.1", "tiny-typed-emitter": "^2.1.0", - "vm2": "^3.9.11", + "vm2": "^3.9.15", "winston": "^3.3.3", "xml2js": "^0.4.23", "yaml": "^1.10.2" diff --git a/yarn.lock b/yarn.lock index 06da9cea..7be32ee3 100644 --- a/yarn.lock +++ b/yarn.lock @@ -6037,10 +6037,10 @@ vite@^4.1.4: optionalDependencies: fsevents "~2.3.2" -vm2@^3.9.11: - version "3.9.11" - resolved "https://registry.yarnpkg.com/vm2/-/vm2-3.9.11.tgz#a880f510a606481719ec3f9803b940c5805a06fe" - integrity sha512-PFG8iJRSjvvBdisowQ7iVF580DXb1uCIiGaXgm7tynMR1uTBlv7UJlB1zdv5KJ+Tmq1f0Upnj3fayoEOPpCBKg== +vm2@^3.9.15: + version "3.9.15" + resolved "https://registry.yarnpkg.com/vm2/-/vm2-3.9.15.tgz#c544e6a9bc31e4e40d2e5f532342cf799ea56a6e" + integrity sha512-XqNqknHGw2avJo13gbIwLNZUumvrSHc9mLqoadFZTpo3KaNEJoe1I0lqTFhRXmXD7WkLyG01aaraXdXT0pa4ag== dependencies: acorn "^8.7.0" acorn-walk "^8.2.0"