From 2f38149b34aba1cec306cdd34ec4b0779991aaf8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 1 Feb 2024 14:53:08 +0000 Subject: [PATCH] fix: package.json & yarn.lock to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-NODEMAILER-6219989 --- package.json | 2 +- yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package.json b/package.json index e405c47..0189b17 100644 --- a/package.json +++ b/package.json @@ -47,7 +47,7 @@ "ioredis": "^4.9.5", "meteor-random": "0.0.3", "mongoose": "^5.2.16", - "nodemailer": "^4.0.1", + "nodemailer": "^6.9.9", "q": "^1.5.1", "underscore": "^1.8.3", "validator": "^10.9.0" diff --git a/yarn.lock b/yarn.lock index cf5c134..a6fa7e3 100644 --- a/yarn.lock +++ b/yarn.lock @@ -5505,10 +5505,10 @@ node-pre-gyp@^0.13.0: semver "^5.3.0" tar "^4" -nodemailer@^4.0.1: - version "4.7.0" - resolved "https://registry.yarnpkg.com/nodemailer/-/nodemailer-4.7.0.tgz#4420e06abfffd77d0618f184ea49047db84f4ad8" - integrity sha512-IludxDypFpYw4xpzKdMAozBSkzKHmNBvGanUREjJItgJ2NYcK/s8+PggVhj7c2yGFQykKsnnmv1+Aqo0ZfjHmw== +nodemailer@^6.9.9: + version "6.9.9" + resolved "https://registry.yarnpkg.com/nodemailer/-/nodemailer-6.9.9.tgz#4549bfbf710cc6addec5064dd0f19874d24248d9" + integrity sha512-dexTll8zqQoVJEZPwQAKzxxtFn0qTnjdQTchoU6Re9BUUGBJiOy3YMn/0ShTW6J5M0dfQ1NeDeRTTl4oIWgQMA== nopt@^4.0.1: version "4.0.1"