Refresh dependencies, drop node-sass
`npm audit` revealed some vulnerabilities: ``` scss-tokenizer <=0.4.2 Severity: high Regular expression denial of service in scss-tokenizer - https://github.com/advisories/GHSA-7mwh-4pqv-wmr8 fix available via `npm audit fix --force` Will install node-sass@4.5.3, which is a breaking change node_modules/scss-tokenizer sass-graph >=2.2.0 Depends on vulnerable versions of scss-tokenizer node_modules/sass-graph node-sass >=4.6.0 Depends on vulnerable versions of sass-graph node_modules/node-sass 3 high severity vulnerabilities ``` We don't need node-sass, and sass-loader is just as happy using another sass implementation. The preferred one is dart-sass which is simply called sass in npm. In the process, I also did an `npm update` just for good measure.
This commit is contained in:
@@ -8,7 +8,7 @@
|
||||
"license-loader": "^0.5.0",
|
||||
"license-webpack-plugin": "^4.0.2",
|
||||
"purgecss": "^4.1.3",
|
||||
"sass": "^1.50.0",
|
||||
"sass": "^1.54.5",
|
||||
"sass-loader": "^12.6.0",
|
||||
"terser-webpack-plugin": "^5.3.1",
|
||||
"ts-loader": "^8.3.0",
|
||||
@@ -21,7 +21,6 @@
|
||||
"bootstrap": "^5.1.3",
|
||||
"css-loader": "^5.2.6",
|
||||
"debounce": "^1.2.1",
|
||||
"node-sass": "^7.0.1",
|
||||
"preact": "^10.7.1",
|
||||
"react-bootstrap": "^2.2.3",
|
||||
"style-loader": "^2.0.0",
|
||||
|
||||
Reference in New Issue
Block a user