diff --git a/backend/package.json b/backend/package.json index 6136ed5c37..68bd526295 100644 --- a/backend/package.json +++ b/backend/package.json @@ -111,7 +111,7 @@ "json2csv": "^5.0.7", "jsonwebtoken": "8.5.1", "jwks-rsa": "^3.0.1", - "lodash": "4.17.21", + "lodash": "4.17.23", "moment": "2.29.4", "moment-timezone": "^0.5.34", "mv": "2.1.1", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 6233274f15..36a9572921 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -268,8 +268,8 @@ importers: specifier: ^3.0.1 version: 3.1.0 lodash: - specifier: 4.17.21 - version: 4.17.21 + specifier: 4.17.23 + version: 4.17.23 moment: specifier: 2.29.4 version: 2.29.4 @@ -989,8 +989,8 @@ importers: specifier: ~1.6.2 version: 1.6.8 lodash: - specifier: ~4.17.21 - version: 4.17.21 + specifier: ~4.17.23 + version: 4.17.23 moment: specifier: ~2.29.4 version: 2.29.4 @@ -1918,8 +1918,8 @@ importers: specifier: ~9.0.5 version: 9.0.5 lodash: - specifier: ^4.17.21 - version: 4.17.21 + specifier: ^4.17.23 + version: 4.17.23 lodash.clonedeep: specifier: ^4.5.0 version: 4.5.0 @@ -5289,6 +5289,7 @@ packages: aws-sdk@2.814.0: resolution: {integrity: sha512-empd1m/J/MAkL6d9OeRpmg9thobULu0wk4v8W3JToaxGi2TD7PIdvE6yliZKyOVAdJINhBWEBhxR4OUIHhcGbQ==} engines: {node: '>= 0.8.0'} + deprecated: The AWS SDK for JavaScript (v2) has reached end-of-support, and no longer receives updates. Please migrate your code to use AWS SDK for JavaScript (v3). More info https://a.co/cUPnyil aws4@1.12.0: resolution: {integrity: sha512-NmWvPnx0F1SfrQbYwOi7OeaNGokp9XhzNioJ/CSBs8Qa4vxug81mhJEAVZwxXuBmYB5KDRfMq/F3RR0BIU7sWg==} @@ -6789,15 +6790,16 @@ packages: glob@10.3.12: resolution: {integrity: sha512-TCNv8vJ+xz4QiqTpfOJA7HvYv+tNIRHKfUWw/q+v2jdgN4ebz+KY9tGx5J4rHP0o84mNP+ApH66HRX8us3Khqg==} engines: {node: '>=16 || 14 >=14.17'} + deprecated: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me hasBin: true glob@6.0.4: resolution: {integrity: sha512-MKZeRNyYZAVVVG1oZeLaWie1uweH40m9AZwIwxyPbTSX4hHrVYSzLg0Ro5Z5R7XKkIX+Cc6oD1rqeDJnwsB8/A==} - deprecated: Glob versions prior to v9 are no longer supported + deprecated: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me glob@7.2.3: resolution: {integrity: sha512-nFR0zLpU2YCaRxwoCJvL6UvCH2JFyFVIvwTLsIf21AuHlMskA1hhTdk+LlYJtOlYt9v6dvszD2BGRqBL+iQK9Q==} - deprecated: Glob versions prior to v9 are no longer supported + deprecated: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me global-directory@4.0.1: resolution: {integrity: sha512-wHTUcDUoZ1H5/0iVqEudYW4/kAlN5cZ3j/bXn0Dpbizl9iaUVeWSHqiOjsgk6OW2bkLclbBjzewBz6weQ1zA2Q==} @@ -7643,8 +7645,8 @@ packages: lodash.upperfirst@4.3.1: resolution: {integrity: sha512-sReKOYJIJf74dhJONhU4e0/shzi1trVbSWDOhKYE5XV2O+H7Sb2Dihwuc7xWxVl+DgFPyTqIN3zMfT9cq5iWDg==} - lodash@4.17.21: - resolution: {integrity: sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==} + lodash@4.17.23: + resolution: {integrity: sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==} log-symbols@4.1.0: resolution: {integrity: sha512-8XPvpAA8uyhfteu8pIvQxpJZ7SYYdpUivZpGy6sFsBuKRY/7rQGavedeB8aK+Zkyq6upMFVL/9AW6vOYzfRyLg==} @@ -7922,8 +7924,8 @@ packages: engines: {node: '>= 4.4.x'} hasBin: true - needle@https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: - resolution: {tarball: https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b} + needle@git+https://git@github.com:clearbit/needle.git#84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: + resolution: {commit: 84d28b5f2c3916db1e7eb84aeaa9d976cc40054b, repo: git@github.com:clearbit/needle.git, type: git} version: 0.7.10 engines: {node: '>= 0.10.x'} hasBin: true @@ -9307,6 +9309,7 @@ packages: tar@4.4.19: resolution: {integrity: sha512-a20gEsvHnWe0ygBY8JbxoM4w3SJdhc7ZAuxkLqh+nvNQN2IOt0B5lLgM490X5Hl8FF0dl0tOf2ewFYAlIFgzVA==} engines: {node: '>=4.5'} + deprecated: Old versions of tar are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me tdigest@0.1.2: resolution: {integrity: sha512-+G0LLgjjo9BZX2MfdvPfH+MKLCrxlXSYec5DaPYP1fe6Iyhf0/fSmJ0bFiZ1F8BT6cGXl2LpltQptzjXKWEkKA==} @@ -13021,7 +13024,7 @@ snapshots: '@sapphire/shapeshift@3.9.7': dependencies: fast-deep-equal: 3.1.3 - lodash: 4.17.21 + lodash: 4.17.23 '@sapphire/snowflake@3.5.1': {} @@ -13925,7 +13928,7 @@ snapshots: '@babel/traverse': 7.23.2 '@babel/types': 7.17.0 javascript-natural-sort: 0.7.1 - lodash: 4.17.21 + lodash: 4.17.23 prettier: 3.3.3 transitivePeerDependencies: - supports-color @@ -15018,8 +15021,8 @@ snapshots: dependencies: bluebird: 2.11.0 create-error: 0.3.1 - lodash: 4.17.21 - needle: https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b + lodash: 4.17.23 + needle: git+https://git@github.com:clearbit/needle.git#84d28b5f2c3916db1e7eb84aeaa9d976cc40054b cli-boxes@2.2.1: {} @@ -17384,7 +17387,7 @@ snapshots: lodash.upperfirst@4.3.1: {} - lodash@4.17.21: {} + lodash@4.17.23: {} log-symbols@4.1.0: dependencies: @@ -17639,7 +17642,7 @@ snapshots: transitivePeerDependencies: - supports-color - needle@https://codeload.github.com/clearbit/needle/tar.gz/84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: + needle@git+https://git@github.com:clearbit/needle.git#84d28b5f2c3916db1e7eb84aeaa9d976cc40054b: dependencies: iconv-lite: 0.4.24 @@ -17905,7 +17908,7 @@ snapshots: omit-deep-by-values@1.0.2: dependencies: - lodash: 4.17.21 + lodash: 4.17.23 on-finished@2.3.0: dependencies: @@ -18780,7 +18783,7 @@ snapshots: cli-color: 1.4.0 fs-extra: 4.0.3 js-beautify: 1.15.1 - lodash: 4.17.21 + lodash: 4.17.23 resolve: 1.22.8 umzug: 2.3.0 yargs: 8.0.2 @@ -18794,7 +18797,7 @@ snapshots: debug: 4.3.4(supports-color@5.5.0) dottie: 2.0.6 inflection: 1.13.4 - lodash: 4.17.21 + lodash: 4.17.23 moment: 2.29.4 moment-timezone: 0.5.45 pg-connection-string: 2.6.4 diff --git a/services/apps/members_enrichment_worker/package.json b/services/apps/members_enrichment_worker/package.json index 5fb52b957c..46c3605245 100644 --- a/services/apps/members_enrichment_worker/package.json +++ b/services/apps/members_enrichment_worker/package.json @@ -28,7 +28,7 @@ "@temporalio/workflow": "~1.11.8", "auth0": "^4.3.1", "axios": "~1.6.2", - "lodash": "~4.17.21", + "lodash": "~4.17.23", "moment": "~2.29.4", "tsx": "^4.7.1", "typescript": "^5.6.3" diff --git a/services/libs/data-access-layer/package.json b/services/libs/data-access-layer/package.json index 53ed7d5128..4bf966c22b 100644 --- a/services/libs/data-access-layer/package.json +++ b/services/libs/data-access-layer/package.json @@ -18,7 +18,7 @@ "@crowd/telemetry": "workspace:*", "@crowd/types": "workspace:*", "html-to-text": "~9.0.5", - "lodash": "^4.17.21", + "lodash": "^4.17.23", "lodash.clonedeep": "^4.5.0", "lodash.map": "^4.6.0", "lodash.merge": "^4.6.2",