From cecafc9d19519490a61901a7e74d2e12c004f928 Mon Sep 17 00:00:00 2001 From: m-brophy Date: Fri, 10 May 2024 10:55:44 +0100 Subject: [PATCH 1/2] WINDUP-4115 CVE upgrade css-tools --- ui-pf4/src/main/webapp/package.json | 1 + ui-pf4/src/main/webapp/yarn.lock | 5 +++++ 2 files changed, 6 insertions(+) diff --git a/ui-pf4/src/main/webapp/package.json b/ui-pf4/src/main/webapp/package.json index d28f7c435..d553fef2a 100644 --- a/ui-pf4/src/main/webapp/package.json +++ b/ui-pf4/src/main/webapp/package.json @@ -5,6 +5,7 @@ "proxy": "http://localhost:8080", "homepage": "./", "dependencies": { + "@adobe/css-tools": "^4.3.3", "@babel/core": "^7.20.2", "@babel/plugin-syntax-flow": "^7.18.6", "@babel/plugin-transform-react-jsx": "^7.19.0", diff --git a/ui-pf4/src/main/webapp/yarn.lock b/ui-pf4/src/main/webapp/yarn.lock index 4a75c2e75..5db350536 100644 --- a/ui-pf4/src/main/webapp/yarn.lock +++ b/ui-pf4/src/main/webapp/yarn.lock @@ -7,6 +7,11 @@ resolved "https://registry.yarnpkg.com/@adobe/css-tools/-/css-tools-4.0.1.tgz#b38b444ad3aa5fedbb15f2f746dcd934226a12dd" integrity sha512-+u76oB43nOHrF4DDWRLWDCtci7f3QJoEBigemIdIeTi1ODqjx6Tad9NCVnPRwewWlKkVab5PlK8DCtPTyX7S8g== +"@adobe/css-tools@^4.3.3": + version "4.3.3" + resolved "https://registry.yarnpkg.com/@adobe/css-tools/-/css-tools-4.3.3.tgz#90749bde8b89cd41764224f5aac29cd4138f75ff" + integrity sha512-rE0Pygv0sEZ4vBWHlAgJLGDU7Pm8xoO6p3wsEceb7GYAjScrOHpEo8KK/eVkAcnSM+slAEtXjA2JpdjLp4fJQQ== + "@ampproject/remapping@^2.1.0": version "2.2.0" resolved "https://registry.yarnpkg.com/@ampproject/remapping/-/remapping-2.2.0.tgz#56c133824780de3174aed5ab6834f3026790154d" From 883204e7cb55f1cafc7860ac80c0bdae341ccd87 Mon Sep 17 00:00:00 2001 From: m-brophy Date: Fri, 10 May 2024 11:57:20 +0100 Subject: [PATCH 2/2] WINDUP-4115 place css-tools in resolutions section --- ui-pf4/src/main/webapp/package.json | 4 ++-- ui-pf4/src/main/webapp/yarn.lock | 7 +------ 2 files changed, 3 insertions(+), 8 deletions(-) diff --git a/ui-pf4/src/main/webapp/package.json b/ui-pf4/src/main/webapp/package.json index d553fef2a..1a3f20ef0 100644 --- a/ui-pf4/src/main/webapp/package.json +++ b/ui-pf4/src/main/webapp/package.json @@ -5,7 +5,6 @@ "proxy": "http://localhost:8080", "homepage": "./", "dependencies": { - "@adobe/css-tools": "^4.3.3", "@babel/core": "^7.20.2", "@babel/plugin-syntax-flow": "^7.18.6", "@babel/plugin-transform-react-jsx": "^7.19.0", @@ -68,7 +67,8 @@ "follow-redirects": "^1.15.6", "semver": "^7.5.4", "tough-cookie": "^4.1.3", - "axios": "^0.28.0" + "axios": "^0.28.0", + "@adobe/css-tools": "^4.3.3" }, "scripts": { "start": "react-scripts start", diff --git a/ui-pf4/src/main/webapp/yarn.lock b/ui-pf4/src/main/webapp/yarn.lock index 5db350536..c579797f2 100644 --- a/ui-pf4/src/main/webapp/yarn.lock +++ b/ui-pf4/src/main/webapp/yarn.lock @@ -2,12 +2,7 @@ # yarn lockfile v1 -"@adobe/css-tools@^4.0.1": - version "4.0.1" - resolved "https://registry.yarnpkg.com/@adobe/css-tools/-/css-tools-4.0.1.tgz#b38b444ad3aa5fedbb15f2f746dcd934226a12dd" - integrity sha512-+u76oB43nOHrF4DDWRLWDCtci7f3QJoEBigemIdIeTi1ODqjx6Tad9NCVnPRwewWlKkVab5PlK8DCtPTyX7S8g== - -"@adobe/css-tools@^4.3.3": +"@adobe/css-tools@^4.0.1", "@adobe/css-tools@^4.3.3": version "4.3.3" resolved "https://registry.yarnpkg.com/@adobe/css-tools/-/css-tools-4.3.3.tgz#90749bde8b89cd41764224f5aac29cd4138f75ff" integrity sha512-rE0Pygv0sEZ4vBWHlAgJLGDU7Pm8xoO6p3wsEceb7GYAjScrOHpEo8KK/eVkAcnSM+slAEtXjA2JpdjLp4fJQQ==