Fix prismjs security vuln (take II)

Summary:
The previous attempt kept the vulnerable dependency around in `yarn.lock`. Now
it's being resolved to the "fixed" version.

Reviewed By: mweststrate

Differential Revision: D26778354

fbshipit-source-id: 17d8e2f1bbcd28939d85e5a976da0bd074ea25e2
This commit is contained in:
Pascal Hartig
2021-03-03 05:39:30 -08:00
committed by Facebook GitHub Bot
parent effd334f98
commit 7202fb2abb
2 changed files with 3 additions and 12 deletions

View File

@@ -24,9 +24,6 @@
"react-docgen": "^5.2.1",
"react-dom": "^16.13.1"
},
"dependencies": {
"prismjs": "1.23.0"
},
"resolutions": {
"axios": "0.21.1",
"minimist": "1.2.3",
@@ -34,6 +31,7 @@
"serialize-javascript": "^3.1.0",
"node-forge": "^0.10.0",
"node-fetch": "^2.6.1",
"immer": "^8.0.1"
"immer": "^8.0.1",
"prismjs": "1.23.0"
}
}

View File

@@ -9618,20 +9618,13 @@ prism-react-renderer@^1.1.1:
resolved "https://registry.yarnpkg.com/prism-react-renderer/-/prism-react-renderer-1.1.1.tgz#1c1be61b1eb9446a146ca7a50b7bcf36f2a70a44"
integrity sha512-MgMhSdHuHymNRqD6KM3eGS0PNqgK9q4QF5P0yoQQvpB6jNjeSAi3jcSAz0Sua/t9fa4xDOMar9HJbLa08gl9ug==
prismjs@1.23.0:
prismjs@1.23.0, prismjs@^1.22.0:
version "1.23.0"
resolved "https://registry.yarnpkg.com/prismjs/-/prismjs-1.23.0.tgz#d3b3967f7d72440690497652a9d40ff046067f33"
integrity sha512-c29LVsqOaLbBHuIbsTxaKENh1N2EQBOHaWv7gkHN4dgRbxSREqDnDbtFJYdpPauS4YCplMSNCABQ6Eeor69bAA==
optionalDependencies:
clipboard "^2.0.0"
prismjs@^1.22.0:
version "1.22.0"
resolved "https://registry.yarnpkg.com/prismjs/-/prismjs-1.22.0.tgz#73c3400afc58a823dd7eed023f8e1ce9fd8977fa"
integrity sha512-lLJ/Wt9yy0AiSYBf212kK3mM5L8ycwlyTlSxHBAneXLR0nzFMlZ5y7riFPF3E33zXOF2IH95xdY5jIyZbM9z/w==
optionalDependencies:
clipboard "^2.0.0"
private@^0.1.8:
version "0.1.8"
resolved "https://registry.yarnpkg.com/private/-/private-0.1.8.tgz#2381edb3689f7a53d653190060fcf822d2f368ff"