ericcornelissen / webmangler

MIT License
1 stars 2 forks source link

Update transitive dependency `json5` #435

Closed ericcornelissen closed 1 year ago

ericcornelissen commented 1 year ago

Bumping because of CVE-2022-46175 . Since json5 is only a development dependency it's not necessary to create a release for any of the packages.

$ npm ls json5    
webmangler-monorepo@0.1.0-alpha /path/to/webmangler
├─┬ @stryker-mutator/core@6.3.0
│ └─┬ @stryker-mutator/instrumenter@6.3.0
│   └─┬ @babel/core@7.19.0
│     └── json5@2.2.3 deduped
├─┬ eslint-plugin-import@2.26.0
│ └─┬ tsconfig-paths@3.14.1
│   └── json5@1.0.2
└─┬ tsconfig-paths@4.1.1
  └── json5@2.2.3