From 743f9ff63bf1e3825a1788978a9f6bad8ebddc0d Mon Sep 17 00:00:00 2001 From: Gijs Weterings Date: Tue, 26 Jul 2022 04:17:11 -0700 Subject: [PATCH] mitigate CVE-2022-25858 for hermes inspector by bumping terser version Summary: Changelog: [General][Security] bump terser minor version to mitigate CVE-2022-25858 Reviewed By: jacdebug Differential Revision: D38115818 fbshipit-source-id: 79a4513fc5345c158c92912559217bdbed608b7f --- ReactCommon/hermes/inspector/tools/msggen/yarn.lock | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/ReactCommon/hermes/inspector/tools/msggen/yarn.lock b/ReactCommon/hermes/inspector/tools/msggen/yarn.lock index 40a02746282e98..cf72d2b1e3fc6b 100644 --- a/ReactCommon/hermes/inspector/tools/msggen/yarn.lock +++ b/ReactCommon/hermes/inspector/tools/msggen/yarn.lock @@ -5517,9 +5517,9 @@ terser-webpack-plugin@^1.4.3: worker-farm "^1.7.0" terser@^4.1.2: - version "4.8.0" - resolved "https://registry.yarnpkg.com/terser/-/terser-4.8.0.tgz#63056343d7c70bb29f3af665865a46fe03a0df17" - integrity sha512-EAPipTNeWsb/3wLPeup1tVPaXfIaU68xMnVdPafIL1TV05OhASArYyIfFvnvJCNrR2NIOvDVNNTFRa+Re2MWyw== + version "4.8.1" + resolved "https://registry.yarnpkg.com/terser/-/terser-4.8.1.tgz#a00e5634562de2239fd404c649051bf6fc21144f" + integrity sha512-4GnLC0x667eJG0ewJTa6z/yXrbLGv80D9Ru6HIpCQmO+Q4PfEtBFi0ObSckqwL6VyQv/7ENJieXHo2ANmdQwgw== dependencies: commander "^2.20.0" source-map "~0.6.1"