remy / inliner

Node utility to inline images, CSS and JavaScript for a web page - useful for mobile sites
MIT License
1.1k stars 165 forks source link

fix: update cheerio and svgo to fix vulns #217

Open THATDONFC opened 3 years ago

THATDONFC commented 3 years ago

Reported by npm audit

cheerio 0.14.0 - 0.19.0 Depends on vulnerable versions of lodash lodash <=4.17.18 Prototype Pollution - https://npmjs.com/advisories/1065 Prototype Pollution - https://npmjs.com/advisories/1523 Prototype Pollution - https://npmjs.com/advisories/577 Prototype Pollution - https://npmjs.com/advisories/782

svgo 0.4.2 - 1.0.5 Depends on vulnerable versions of js-yaml js-yaml <=3.13.0 Denial of Service - https://npmjs.com/advisories/788 Code Injection - https://npmjs.com/advisories/813