From c7e064bb6ca67d360b631f36ddb8aa5d7322ae02 Mon Sep 17 00:00:00 2001 From: Ethan Lane Date: Thu, 14 Mar 2024 17:31:53 +0000 Subject: [PATCH 1/3] Fix vulnerabilities with undici and ip --- package-lock.json | 37 ++++++------------------------------- package.json | 4 +++- 2 files changed, 9 insertions(+), 32 deletions(-) diff --git a/package-lock.json b/package-lock.json index d6339c8..fc8eb0d 100644 --- a/package-lock.json +++ b/package-lock.json @@ -2886,28 +2886,6 @@ "node": "^14.15.0 || ^16.10.0 || >=18.0.0" } }, - "node_modules/babel-plugin-jest-hoist/node_modules/@babel/parser": { - "version": "7.23.0", - "license": "MIT", - "bin": { - "parser": "bin/babel-parser.js" - }, - "engines": { - "node": ">=6.0.0" - } - }, - "node_modules/babel-plugin-jest-hoist/node_modules/@babel/template": { - "version": "7.22.5", - "license": "MIT", - "dependencies": { - "@babel/code-frame": "^7.22.5", - "@babel/parser": "^7.22.5", - "@babel/types": "^7.22.5" - }, - "engines": { - "node": ">=6.9.0" - } - }, "node_modules/babel-preset-current-node-syntax": { "version": "1.0.1", "license": "MIT", @@ -6218,9 +6196,9 @@ } }, "node_modules/ip": { - "version": "2.0.0", - "resolved": "https://registry.npmjs.org/ip/-/ip-2.0.0.tgz", - "integrity": "sha512-WKa+XuLG1A1R0UWhl2+1XQSi+fZWMsYKffMZTTYsiZaUD8k2yDAj5atimTUD2TZkyCkNEeYE5NhFZmupOGtjYQ==", + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/ip/-/ip-2.0.1.tgz", + "integrity": "sha512-lJUL9imLTNi1ZfXT+DU6rBBdbiKGBuay9B6xGSPVjUeQwaH1RIGqef8RZkUtHioLmSNpPR5M4HVKJGm1j8FWVQ==", "optional": true, "peer": true }, @@ -11234,8 +11212,9 @@ } }, "node_modules/undici": { - "version": "5.27.2", - "license": "MIT", + "version": "5.28.3", + "resolved": "https://registry.npmjs.org/undici/-/undici-5.28.3.tgz", + "integrity": "sha512-3ItfzbrhDlINjaP0duwnNsKpDQk3acHI3gVJ1z4fmwMK31k5G9OVIAMLSIaP6w4FaGkaAkN6zaQO9LUvZ1t7VA==", "dependencies": { "@fastify/busboy": "^2.0.0" }, @@ -11412,10 +11391,6 @@ "node": ">=10.12.0" } }, - "node_modules/v8-to-istanbul/node_modules/@types/istanbul-lib-coverage": { - "version": "2.0.4", - "license": "MIT" - }, "node_modules/vali-date": { "version": "1.0.0", "dev": true, diff --git a/package.json b/package.json index 732ab99..02a2062 100644 --- a/package.json +++ b/package.json @@ -43,7 +43,9 @@ "ts-jest": "^29.0.0", "typeorm": "0.3.20" }, - "resolutions": {}, + "overrides": { + "undici": "^5.28.3" + }, "devDependencies": { "@types/node": "^20.0.0", "@typescript-eslint/eslint-plugin": "^6.16.0", From e0479127ac6caa75f3198b0632a6564ff478f706 Mon Sep 17 00:00:00 2001 From: Ethan Lane Date: Thu, 14 Mar 2024 17:35:59 +0000 Subject: [PATCH 2/3] 0.5.1 --- .dev.env | 2 +- .prod.env | 2 +- .stage.env | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.dev.env b/.dev.env index b61d698..9965665 100644 --- a/.dev.env +++ b/.dev.env @@ -7,7 +7,7 @@ # any secret values. BOT_TOKEN= -BOT_VER=0.5.0 +BOT_VER=0.5.1 BOT_AUTHOR=Vylpes BOT_OWNERID=147392775707426816 BOT_CLIENTID=682942374040961060 diff --git a/.prod.env b/.prod.env index a3d5a1e..da1fc9c 100644 --- a/.prod.env +++ b/.prod.env @@ -7,7 +7,7 @@ # any secret values. BOT_TOKEN= -BOT_VER=0.5.0 +BOT_VER=0.5.1 BOT_AUTHOR=Vylpes BOT_OWNERID=147392775707426816 BOT_CLIENTID=1093810443589529631 diff --git a/.stage.env b/.stage.env index c2f65e6..0c9264a 100644 --- a/.stage.env +++ b/.stage.env @@ -7,7 +7,7 @@ # any secret values. BOT_TOKEN= -BOT_VER=0.5.0 +BOT_VER=0.5.1 BOT_AUTHOR=Vylpes BOT_OWNERID=147392775707426816 BOT_CLIENTID=1147976642942214235 From 370730cbea192a53ed770621de5aea9cb6837b47 Mon Sep 17 00:00:00 2001 From: Ethan Lane Date: Thu, 14 Mar 2024 17:36:26 +0000 Subject: [PATCH 3/3] 0.5.1 --- package-lock.json | 4 ++-- package.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index fc8eb0d..51c2c39 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "card-drop", - "version": "0.5.0", + "version": "0.5.1", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "card-drop", - "version": "0.5.0", + "version": "0.5.1", "license": "MIT", "dependencies": { "@discordjs/rest": "^2.0.0", diff --git a/package.json b/package.json index 02a2062..d481825 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "card-drop", - "version": "0.5.0", + "version": "0.5.1", "main": "./dist/bot.js", "typings": "./dist", "scripts": {