diff --git a/.changeset/@graphql-tools_utils-6822-dependencies.md b/.changeset/@graphql-tools_utils-6822-dependencies.md new file mode 100644 index 00000000000..c19273d406e --- /dev/null +++ b/.changeset/@graphql-tools_utils-6822-dependencies.md @@ -0,0 +1,5 @@ +--- +"@graphql-tools/utils": patch +--- +dependencies updates: + - Updated dependency [`dset@^3.1.4` ↗︎](https://www.npmjs.com/package/dset/v/3.1.4) (from `^3.1.2`, in `dependencies`) diff --git a/.changeset/new-squids-cheat.md b/.changeset/new-squids-cheat.md new file mode 100644 index 00000000000..e03dc2e6ecc --- /dev/null +++ b/.changeset/new-squids-cheat.md @@ -0,0 +1,7 @@ +--- +'@graphql-tools/utils': patch +--- + +Bump dset dependency handling the CVE-2024-21529 + +https://security.snyk.io/vuln/SNYK-JS-DSET-7116691 diff --git a/packages/utils/package.json b/packages/utils/package.json index 8eb9860d83b..f8c0321d12c 100644 --- a/packages/utils/package.json +++ b/packages/utils/package.json @@ -39,7 +39,7 @@ "dependencies": { "@graphql-typed-document-node/core": "^3.1.1", "cross-inspect": "1.0.1", - "dset": "^3.1.2", + "dset": "^3.1.4", "tslib": "^2.4.0" }, "devDependencies": { diff --git a/yarn.lock b/yarn.lock index 9e0d9eade4a..ef7ff325ab1 100644 --- a/yarn.lock +++ b/yarn.lock @@ -5395,7 +5395,7 @@ dotenv@^8.1.0: resolved "https://registry.yarnpkg.com/dotenv/-/dotenv-8.6.0.tgz#061af664d19f7f4d8fc6e4ff9b584ce237adcb8b" integrity sha512-IrPdXQsk2BbzvCBGBOTmmSH5SodmqZNt4ERAZDmW4CT+tL8VtvinqywuANaFu4bOMWki16nqf0e4oC0QIaDr/g== -dset@^3.1.1, dset@^3.1.2: +dset@^3.1.1, dset@^3.1.2, dset@^3.1.4: version "3.1.4" resolved "https://registry.yarnpkg.com/dset/-/dset-3.1.4.tgz#f8eaf5f023f068a036d08cd07dc9ffb7d0065248" integrity sha512-2QF/g9/zTaPDc3BjNcVTGoBbXBgYfMTTceLaYcFJ/W9kggFUkhxD/hMEeuLKbugyef9SqAx8cpgwlIP/jinUTA==