Commit 67ca636
Upgrade dom-iterator from 1.0.0 to 1.0.2
Summary:
The 3P Library Vulnerability Remediation Team is dedicated to remediating high-risk external libraries at Meta using both manual and automated processes. Older versions of this library have been identified as risky, and this diff stack is intended to upgrade the library to a recommended version.
We kindly request your help with the diff review. Please commandeer this diff stack if specific merges need to be added or if there are any build or dependency failures.
Asset Name: asset://code.third_party_library/fbsource/fbobjc%2FLibraries%2FMobileUI%2FQuickLayout%2Fdocs%2Fyarn.lock%23pkg:npm%2Fdom-iterator@1.0.0
Asset Version: 1.0.0
Asset Vulnerabilities:
CVE-2024-21541, CWEs: Improper Control of Generation of Code ('Code Injection')
Version to upgrade to: 1.0.1
Additional Info: This diff contains updated yarn files and changes to update vulnerable package. As a part of this diff performed below steps
update resolutions section with recommended version
run yarn install
revert changes in resolutions section
run yarn install
Reviewed By: ide-2
Differential Revision: D87274669
fbshipit-source-id: ed5fff58404052f259cedddb9a9b8f09b158aa5f1 parent 47ffabd commit 67ca636
1 file changed
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6137 | 6137 | | |
6138 | 6138 | | |
6139 | 6139 | | |
6140 | | - | |
6141 | | - | |
6142 | | - | |
| 6140 | + | |
| 6141 | + | |
| 6142 | + | |
6143 | 6143 | | |
6144 | 6144 | | |
6145 | 6145 | | |
| |||
0 commit comments