From cc34263bd943b215255c3527b21ca8a81717ff48 Mon Sep 17 00:00:00 2001 From: igraczech Date: Mon, 8 Jul 2019 11:47:24 +0200 Subject: [PATCH 01/10] version bump --- package.json | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/package.json b/package.json index a720e6c..4fbf6b9 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "fs-finder", "description": "[ABANDONED] File system recursive finder", - "version": "1.8.1", + "version": "1.8.2", "author": { "name": "David Kudera", "email": "kudera.d@gmail.com" @@ -40,4 +40,3 @@ "build": "coffee -co ./test/lib ./test/src" } } - From 3525d4160e0f3d4aeeaede5a22e96530962ffdb6 Mon Sep 17 00:00:00 2001 From: igraczech Date: Mon, 8 Jul 2019 11:50:26 +0200 Subject: [PATCH 02/10] updated dependencies with security issues --- package.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index 4fbf6b9..74d37c2 100644 --- a/package.json +++ b/package.json @@ -23,11 +23,11 @@ }, "main": "./lib/Finder.js", "dependencies": { - "moment": "^2.5.0", + "moment": "^2.24.0", "operator-compare": "~1.0.1", "escape-regexp": "~0.0.1", "q": "~1.0.0", - "async": "~0.2.9" + "async": "^0.2.10" }, "devDependencies": { "chai": "~1.8.1", From 018e7d60699e29f23a97055440aec85785c477b8 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Mon, 2 May 2022 12:47:50 +0200 Subject: [PATCH 03/10] updated async to non-vulnerable version --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 74d37c2..6331ed3 100644 --- a/package.json +++ b/package.json @@ -27,7 +27,7 @@ "operator-compare": "~1.0.1", "escape-regexp": "~0.0.1", "q": "~1.0.0", - "async": "^0.2.10" + "async": "^2.6.4" }, "devDependencies": { "chai": "~1.8.1", From 00e8750f46e5ced78cfbad9a58b46c413dcfae05 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Mon, 2 May 2022 12:48:16 +0200 Subject: [PATCH 04/10] Update package.json --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 6331ed3..5a93157 100644 --- a/package.json +++ b/package.json @@ -23,7 +23,7 @@ }, "main": "./lib/Finder.js", "dependencies": { - "moment": "^2.24.0", + "moment": "^2.26.0", "operator-compare": "~1.0.1", "escape-regexp": "~0.0.1", "q": "~1.0.0", From 8df884f92390dc504365e72c10fd76e46bd5d196 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Mon, 2 May 2022 12:50:11 +0200 Subject: [PATCH 05/10] Update package.json --- package.json | 3 +++ 1 file changed, 3 insertions(+) diff --git a/package.json b/package.json index 5a93157..853d6ed 100644 --- a/package.json +++ b/package.json @@ -29,6 +29,9 @@ "q": "~1.0.0", "async": "^2.6.4" }, + "overrides": { + "minimatch": "3.0.2", + }, "devDependencies": { "chai": "~1.8.1", "fs-mock": "~1.0.1", From 43da0d9ee0761dadf447bff98ea80cfc37229508 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Mon, 2 May 2022 12:57:00 +0200 Subject: [PATCH 06/10] Updated more dependencies to make sure this will have zero vulnerabilities --- package.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index 853d6ed..5ee1846 100644 --- a/package.json +++ b/package.json @@ -23,19 +23,19 @@ }, "main": "./lib/Finder.js", "dependencies": { + "async": "^2.6.4", + "escape-regexp": "~0.0.1", "moment": "^2.26.0", "operator-compare": "~1.0.1", - "escape-regexp": "~0.0.1", - "q": "~1.0.0", - "async": "^2.6.4" + "q": "~1.0.0" }, "overrides": { - "minimatch": "3.0.2", + "minimatch": "3.0.2" }, "devDependencies": { "chai": "~1.8.1", "fs-mock": "~1.0.1", - "mocha": "~1.17.0" + "mocha": "^10.0.0" }, "scripts": { "build-and-test": "npm run build && npm run test", From 7193a17e1843f379a2be0e782dacfe09623995e8 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Mon, 2 May 2022 13:01:30 +0200 Subject: [PATCH 07/10] more pinning overrides --- package.json | 2 ++ 1 file changed, 2 insertions(+) diff --git a/package.json b/package.json index 5ee1846..b66f478 100644 --- a/package.json +++ b/package.json @@ -30,6 +30,8 @@ "q": "~1.0.0" }, "overrides": { + "ansi-regex": "5.0.1", + "json-schema": "0.4.0", "minimatch": "3.0.2" }, "devDependencies": { From d55a196a890999378b0307df0341af16d6153a94 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Tue, 3 May 2022 14:25:13 +0200 Subject: [PATCH 08/10] specific version pinned --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index b66f478..c725c2d 100644 --- a/package.json +++ b/package.json @@ -23,7 +23,7 @@ }, "main": "./lib/Finder.js", "dependencies": { - "async": "^2.6.4", + "async": "2.6.4", "escape-regexp": "~0.0.1", "moment": "^2.26.0", "operator-compare": "~1.0.1", From 6d056ba33eacca48b548e43bcf6e7cdbc2c258c6 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Mon, 18 Jul 2022 14:18:24 +0200 Subject: [PATCH 09/10] security update adressing issues in moment <2.29.3 (https://www.cve.org/CVERecord?id=CVE-2022-31129) --- package.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index c725c2d..69778ff 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "fs-finder", "description": "[ABANDONED] File system recursive finder", - "version": "1.8.2", + "version": "1.8.4", "author": { "name": "David Kudera", "email": "kudera.d@gmail.com" @@ -25,7 +25,7 @@ "dependencies": { "async": "2.6.4", "escape-regexp": "~0.0.1", - "moment": "^2.26.0", + "moment": "^2.29.3", "operator-compare": "~1.0.1", "q": "~1.0.0" }, From fa11a835805147c6143418442a82c408c74b32f3 Mon Sep 17 00:00:00 2001 From: Matej Sychra Date: Wed, 9 Nov 2022 13:31:59 +0100 Subject: [PATCH 10/10] patched vulnerable dependencies --- package.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index 69778ff..4c4c10e 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "fs-finder", "description": "[ABANDONED] File system recursive finder", - "version": "1.8.4", + "version": "1.8.5", "author": { "name": "David Kudera", "email": "kudera.d@gmail.com" @@ -25,19 +25,19 @@ "dependencies": { "async": "2.6.4", "escape-regexp": "~0.0.1", - "moment": "^2.29.3", + "moment": "^2.29.4", "operator-compare": "~1.0.1", "q": "~1.0.0" }, "overrides": { "ansi-regex": "5.0.1", "json-schema": "0.4.0", - "minimatch": "3.0.2" + "minimatch": "5.1.0" }, "devDependencies": { - "chai": "~1.8.1", + "chai": "~4.3.7", "fs-mock": "~1.0.1", - "mocha": "^10.0.0" + "mocha": "^10.1.0" }, "scripts": { "build-and-test": "npm run build && npm run test",