caravaggio
Advanced tools
Comparing version 2.2.2 to 2.3.0
@@ -5,4 +5,7 @@ { | ||
"rules": { | ||
"no-nested-ternary": 0 | ||
"no-nested-ternary": 0, | ||
"no-multiple-empty-lines": ["error", | ||
{ "max": 2, "maxEOF": 1 } | ||
] | ||
} | ||
} | ||
} |
# Changelog | ||
## 2.3.0 | ||
- Dependencies security updates | ||
## 2.2.2 | ||
@@ -4,0 +9,0 @@ |
@@ -1,2 +0,1 @@ | ||
[{"type":"issue","check_name":"Vulnerable module \"tough-cookie\" identified","description":"`tough-cookie` Regular Expression Denial of Service","categories":["Security"],"remediation_points":300000,"content":{"body":"# Regular Expression Denial of Service\n## Overview:\nThe tough-cookie module is vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds.\n\nUnless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb so the impact of the ReDoS is limited to around 7.3 seconds of blocking.\n\nAt the time of writing all version \u003c=2.3.2 are vulnerable\n\n## Recommendation:\nPlease update to version 2.3.3 or greater"},"location":{"path":"package-lock.json","lines":{"begin":3251,"end":3258}},"engine_name":"nodesecurity","fingerprint":"4cdf86fa345ebf706041609832e5a167","severity":"minor"}, | ||
{"type":"issue","check_name":"Vulnerable module \"debug\" identified","description":"`debug` Regular Expression Denial of Service","categories":["Security"],"remediation_points":300000,"content":{"body":"# Regular Expression Denial of Service\n## Overview:\nThe debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the `o` formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.\n\n## Recommendation:\nUpgrade to version 2.6.9 or greater if you are on the 2.6.x series or 3.1.0 or greater."},"location":{"path":"package-lock.json","lines":{"begin":2600,"end":2607}},"engine_name":"nodesecurity","fingerprint":"82f98b1c73a1bd2659e5d0a968d287a5","severity":"minor"}] | ||
[] |
@@ -13,4 +13,5 @@ | ||
level: 'debug', | ||
pretty: true, | ||
}, | ||
}; | ||
module.exports = { | ||
logger: { | ||
level: 'fatal', | ||
stream: 'stdout', | ||
}, | ||
@@ -6,0 +5,0 @@ defaultTransformations: [], |
{ | ||
"name": "caravaggio", | ||
"version": "2.2.2", | ||
"version": "2.3.0", | ||
"description": "A blazing fast image processor service", | ||
@@ -10,3 +10,3 @@ "main": "index.js", | ||
"now-start": "bin/caravaggio --cache memory", | ||
"dev": "NODE_ENV=development micro-dev -p 3001 src/ -s | pino", | ||
"dev": "NODE_ENV=development micro-dev -p 3001 src/ -s", | ||
"test": "npm run lint && npm run test-only -- --coverage --colors=false", | ||
@@ -36,4 +36,4 @@ "test-only": "NODE_ENV=test ALLOW_CONFIG_MUTATIONS=true jest", | ||
"dependencies": { | ||
"config": "^1.30.0", | ||
"fs-extra": "^6.0.0", | ||
"config": "2.0.1", | ||
"fs-extra": "7.0.0", | ||
"md5": "^2.2.1", | ||
@@ -44,14 +44,15 @@ "micro": "^9.3.0", | ||
"node-fetch": "^2.1.2", | ||
"pino": "^4.16.1", | ||
"pino": "^5.4.0", | ||
"sharp": "^0.20.2", | ||
"yargs": "^11.0.0" | ||
"yargs": "12.0.1" | ||
}, | ||
"devDependencies": { | ||
"eslint": "^4.19.1", | ||
"eslint-config-airbnb-base": "^12.1.0", | ||
"eslint": "^5.4.0", | ||
"eslint-config-airbnb-base": "^13.1.0", | ||
"eslint-import-resolver-jest": "^2.1.1", | ||
"eslint-plugin-import": "^2.11.0", | ||
"eslint-plugin-jest": "^21.15.1", | ||
"jest": "^22.4.3", | ||
"micro-dev": "^2.2.2", | ||
"jest": "^23.5.0", | ||
"micro-dev": "3.0.0", | ||
"pino-pretty": "^2.0.1", | ||
"request-promise": "^4.2.2", | ||
@@ -65,5 +66,3 @@ "test-listen": "^1.1.0" | ||
"coverageReporters": [ | ||
"json", | ||
"lcov", | ||
"text", | ||
"text-summary", | ||
"html" | ||
@@ -82,4 +81,8 @@ ], | ||
"pkg": { | ||
"assets": "config/**/*" | ||
"assets": [ | ||
"config/**/*", | ||
"static/**/*", | ||
"node_modules/config/**/*.*" | ||
] | ||
} | ||
} |
Sorry, the diff of this file is not supported yet
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
License Policy Violation
LicenseThis package is not allowed per your license policy. Review the package's license to ensure compliance.
Found 1 instance in 1 package
62001
10
1491
+ Addedatomic-sleep@1.0.0(transitive)
+ Addedconfig@2.0.1(transitive)
+ Addedcross-spawn@5.1.0(transitive)
+ Addeddecamelize@2.0.0(transitive)
+ Addedexeca@0.7.0(transitive)
+ Addedfast-redact@2.1.0(transitive)
+ Addedfast-safe-stringify@2.1.1(transitive)
+ Addedfind-up@3.0.0(transitive)
+ Addedfs-extra@7.0.0(transitive)
+ Addedget-stream@3.0.0(transitive)
+ Addedinvert-kv@1.0.0(transitive)
+ Addedlcid@1.0.0(transitive)
+ Addedlocate-path@3.0.0(transitive)
+ Addedlru-cache@4.1.5(transitive)
+ Addedmem@1.1.0(transitive)
+ Addedmimic-fn@1.2.0(transitive)
+ Addedos-locale@2.1.0(transitive)
+ Addedp-limit@2.3.0(transitive)
+ Addedp-locate@3.0.0(transitive)
+ Addedp-try@2.2.0(transitive)
+ Addedpino@5.17.0(transitive)
+ Addedpseudomap@1.0.2(transitive)
+ Addedquick-format-unescaped@3.0.3(transitive)
+ Addedsonic-boom@0.7.7(transitive)
+ Addedxregexp@4.0.0(transitive)
+ Addedy18n@4.0.3(transitive)
+ Addedyallist@2.1.2(transitive)
+ Addedyargs@12.0.1(transitive)
+ Addedyargs-parser@10.1.0(transitive)
- Removedansi-styles@3.2.1(transitive)
- Removedchalk@2.4.2(transitive)
- Removedconfig@1.31.0(transitive)
- Removedcross-spawn@6.0.6(transitive)
- Removeddecamelize@1.2.0(transitive)
- Removedescape-string-regexp@1.0.5(transitive)
- Removedexeca@1.0.0(transitive)
- Removedfast-json-parse@1.0.3(transitive)
- Removedfast-safe-stringify@1.2.3(transitive)
- Removedfind-up@2.1.0(transitive)
- Removedfs-extra@6.0.1(transitive)
- Removedget-stream@4.1.0(transitive)
- Removedhas-flag@3.0.0(transitive)
- Removedinvert-kv@2.0.0(transitive)
- Removedlcid@2.0.0(transitive)
- Removedlocate-path@2.0.0(transitive)
- Removedmap-age-cleaner@0.1.3(transitive)
- Removedmem@4.3.0(transitive)
- Removedmimic-fn@2.1.0(transitive)
- Removednice-try@1.0.5(transitive)
- Removedos-locale@3.1.0(transitive)
- Removedp-defer@1.0.0(transitive)
- Removedp-is-promise@2.1.0(transitive)
- Removedp-limit@1.3.0(transitive)
- Removedp-locate@2.0.0(transitive)
- Removedp-try@1.0.0(transitive)
- Removedpino@4.17.6(transitive)
- Removedpump@3.0.2(transitive)
- Removedquick-format-unescaped@1.1.2(transitive)
- Removedsplit2@2.2.0(transitive)
- Removedsupports-color@5.5.0(transitive)
- Removedthrough2@2.0.5(transitive)
- Removedy18n@3.2.2(transitive)
- Removedyargs@11.1.1(transitive)
- Removedyargs-parser@9.0.2(transitive)
Updatedconfig@2.0.1
Updatedfs-extra@7.0.0
Updatedpino@^5.4.0
Updatedyargs@12.0.1