From 71432a306371e236c2dc8cecc2c9c1e969e57da9 Mon Sep 17 00:00:00 2001 From: Jose Bolos Date: Fri, 9 Sep 2016 12:19:28 +0100 Subject: [PATCH 1/5] Upgrade express to 4.14 or greater Prevents https://nodesecurity.io/advisories/106 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index edbe960..2a4250e 100644 --- a/package.json +++ b/package.json @@ -24,7 +24,7 @@ "body-parser": "~1.15", "chalk": "~1.1", "compression": "~1.6", - "express": "~4.13", + "express": "~4.14", "express-hbs": "~1.0", "moment": "~2.13", "pa11y-webservice": "~2.0", From a30e82d5be832c4f747caaadf3b93ba6139e8898 Mon Sep 17 00:00:00 2001 From: Jose Bolos Date: Fri, 9 Sep 2016 12:22:34 +0100 Subject: [PATCH 2/5] Require webservice 2.0.1 or greater Addresses the following vulns present on 2.0.0: * https://nodesecurity.io/advisories/45 * https://nodesecurity.io/advisories/63 * https://nodesecurity.io/advisories/65 * https://nodesecurity.io/advisories/121 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 2a4250e..6b6a566 100644 --- a/package.json +++ b/package.json @@ -27,7 +27,7 @@ "express": "~4.14", "express-hbs": "~1.0", "moment": "~2.13", - "pa11y-webservice": "~2.0", + "pa11y-webservice": "^2.0.1", "pa11y-webservice-client-node": "~1.2", "underscore": "~1.8" }, From 22aab6bee276e32ae4ed53c58b5c17407667736b Mon Sep 17 00:00:00 2001 From: Jose Bolos Date: Fri, 9 Sep 2016 12:27:09 +0100 Subject: [PATCH 3/5] Require request 2.74 or greater Fixes https://nodesecurity.io/advisories/130 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 6b6a566..4e6b99e 100644 --- a/package.json +++ b/package.json @@ -39,7 +39,7 @@ "less": "~2.7", "mocha": "^2", "proclaim": "^3", - "request": "^2", + "request": "^2.74", "uglify-js": "~2.6" }, From 36a677948b2fa8b3081c3c4a10f5de189b9b4ec5 Mon Sep 17 00:00:00 2001 From: Jose Bolos Date: Fri, 9 Sep 2016 12:27:42 +0100 Subject: [PATCH 4/5] Upgrade mocha to version 3 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 4e6b99e..8fcd999 100644 --- a/package.json +++ b/package.json @@ -37,7 +37,7 @@ "jscs": "^2", "jshint": "^2", "less": "~2.7", - "mocha": "^2", + "mocha": "^3", "proclaim": "^3", "request": "^2.74", "uglify-js": "~2.6" From fa0c523e3ff5a3d671bbe62485f958d3109173fb Mon Sep 17 00:00:00 2001 From: Jose Bolos Date: Fri, 9 Sep 2016 12:52:11 +0100 Subject: [PATCH 5/5] Require webservice-client-node 1.2.1 or greater Fixes https://nodesecurity.io/advisories/130 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 8fcd999..b417610 100644 --- a/package.json +++ b/package.json @@ -28,7 +28,7 @@ "express-hbs": "~1.0", "moment": "~2.13", "pa11y-webservice": "^2.0.1", - "pa11y-webservice-client-node": "~1.2", + "pa11y-webservice-client-node": "^1.2.1", "underscore": "~1.8" }, "devDependencies": {