From b073e290fb476699b4eec64512ae96d1d08eeec7 Mon Sep 17 00:00:00 2001 From: Changkun Ou Date: Thu, 11 Jul 2019 09:41:45 +0200 Subject: [PATCH] fix: security vulnerability in lodash.merge --- website/package-lock.json | 41 +++++++++---------- website/package.json | 4 +- .../source/modern-cpp/css/index.styl | 2 +- 3 files changed, 23 insertions(+), 24 deletions(-) diff --git a/website/package-lock.json b/website/package-lock.json index 61cf389..3127fea 100644 --- a/website/package-lock.json +++ b/website/package-lock.json @@ -1958,13 +1958,12 @@ } }, "hexo-renderer-marked": { - "version": "0.3.2", - "resolved": "https://registry.npmjs.org/hexo-renderer-marked/-/hexo-renderer-marked-0.3.2.tgz", - "integrity": "sha512-joSLeHB0YRkuViIPQlRz4A+zfJKPNHT+rABFgPHiT1zL9eeTUPxoLL4h7kcgOwRLAontVScaxP2Sie15mNitFg==", + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/hexo-renderer-marked/-/hexo-renderer-marked-1.0.1.tgz", + "integrity": "sha512-oAOthvEYWJx4hvzD8WE7hOSYoTooOe5Vtb7mW6LtM3rEpQhXaWXPq7fOrEhCfdjgDr3DusSi7x19XgLIx+hcmQ==", "requires": { "hexo-util": "^0.6.2", - "marked": "^0.3.9", - "object-assign": "^4.1.1", + "marked": "^0.6.1", "strip-indent": "^2.0.0" } }, @@ -2246,9 +2245,9 @@ } }, "lodash": { - "version": "4.17.11", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.11.tgz", - "integrity": "sha512-cQKh8igo5QUhZ7lg38DYWAxMvjSAKG0A8wGSVimP07SIUEK2UO+arSRKbRZWtelMtN5V0Hkwh5ryOto/SshYIg==", + "version": "4.17.14", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.14.tgz", + "integrity": "sha512-mmKYbW3GLuJeX+iGP+Y7Gp1AiGHGbXHCOh/jZmrawMmsE7MS4znI3RL2FsjbqOyMayHInjOeykW7PEajUk1/xw==", "dev": true }, "lodash.assignin": { @@ -2294,9 +2293,9 @@ "dev": true }, "lodash.merge": { - "version": "4.6.1", - "resolved": "https://registry.npmjs.org/lodash.merge/-/lodash.merge-4.6.1.tgz", - "integrity": "sha512-AOYza4+Hf5z1/0Hztxpm2/xiPZgi/cjMqdnKTUWTBSKchJlxXXuUSxCCl8rJlf4g6yww/j6mA8nC8Hw/EZWxKQ==", + "version": "4.6.2", + "resolved": "https://registry.npmjs.org/lodash.merge/-/lodash.merge-4.6.2.tgz", + "integrity": "sha512-0KpjqXRVvrYyCsX1swR/XTK0va6VQkQM6MNo7PqW77ByjAhoARA8EfrP1N4+KlKj8YS0ZUCtRT/YUuhyYDujIQ==", "dev": true }, "lodash.pick": { @@ -2368,9 +2367,9 @@ } }, "marked": { - "version": "0.3.19", - "resolved": "https://registry.npmjs.org/marked/-/marked-0.3.19.tgz", - "integrity": "sha512-ea2eGWOqNxPcXv8dyERdSr/6FmzvWwzjMxpfGB/sbMccXoct+xY+YukPD+QTUZwyvK7BZwcr4m21WBOW41pAkg==" + "version": "0.6.3", + "resolved": "https://registry.npmjs.org/marked/-/marked-0.6.3.tgz", + "integrity": "sha512-Fqa7eq+UaxfMriqzYLayfqAE40WN03jf+zHjT18/uXNuzjq3TY0XTbrAoPeqSJrAmPz11VuUA+kBPYOhHt9oOQ==" }, "micromatch": { "version": "3.1.10", @@ -2968,9 +2967,9 @@ "integrity": "sha1-1HLbIo6zMcJQaw6MFVJK25OdEsE=" }, "serve": { - "version": "11.0.2", - "resolved": "https://registry.npmjs.org/serve/-/serve-11.0.2.tgz", - "integrity": "sha512-TjjjwUdPU+STkUyxvZFtkWOTRXdNDNMfot9Z/f97eEeyjPAV69o1TmJrNAlDbvpPu1JEjCoWiGCjkel7kWNF4A==", + "version": "11.1.0", + "resolved": "https://registry.npmjs.org/serve/-/serve-11.1.0.tgz", + "integrity": "sha512-+4wpDtOSS+4ZLyDWMxThutA3iOTawX2+yDovOI8cjOUOmemyvNlHyFAsezBlSgbZKTYChI3tzA1Mh0z6XZ62qA==", "dev": true, "requires": { "@zeit/schemas": "2.6.0", @@ -2980,7 +2979,7 @@ "chalk": "2.4.1", "clipboardy": "1.2.3", "compression": "1.7.3", - "serve-handler": "6.0.2", + "serve-handler": "6.1.0", "update-check": "1.5.2" }, "dependencies": { @@ -2998,9 +2997,9 @@ } }, "serve-handler": { - "version": "6.0.2", - "resolved": "https://registry.npmjs.org/serve-handler/-/serve-handler-6.0.2.tgz", - "integrity": "sha512-D1zgDpvx9Rgjip6rzY2QBjlZwfr/oiDSg66HipOWkEw1appHn7/mXdVRL6F8+bd1KD117Wch4+4x78OTXQVwDg==", + "version": "6.1.0", + "resolved": "https://registry.npmjs.org/serve-handler/-/serve-handler-6.1.0.tgz", + "integrity": "sha512-63N075Tn3PsFYcu0NVV7tb367UbiW3gnC+/50ohL4oqOhAG6bmbaWqiRcXQgbzqc0ALBjSAzg7VTfa0Qw4E3hA==", "dev": true, "requires": { "bytes": "3.0.0", diff --git a/website/package.json b/website/package.json index cf0b554..d86bed9 100755 --- a/website/package.json +++ b/website/package.json @@ -9,11 +9,11 @@ "hexo-generator-index": "^0.2.1", "hexo-image-caption": "^0.1.1", "hexo-renderer-ejs": "^0.3.1", - "hexo-renderer-marked": "^0.3.2", + "hexo-renderer-marked": "^1.0.1", "hexo-renderer-stylus": "^0.3.3" }, "devDependencies": { "hexo": "^3.8.0", "serve": ">=7.0.0" } -} \ No newline at end of file +} diff --git a/website/themes/moderncpp/source/modern-cpp/css/index.styl b/website/themes/moderncpp/source/modern-cpp/css/index.styl index be385cd..5e61b0c 100755 --- a/website/themes/moderncpp/source/modern-cpp/css/index.styl +++ b/website/themes/moderncpp/source/modern-cpp/css/index.styl @@ -6,7 +6,7 @@ $width = 900px body background-color: #fff - + margin-bottom: 200px #logo span font-size: 1.2em