diff --git a/CHANGELOG.md b/CHANGELOG.md index 92a1e2c..eaa8831 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,7 @@ +## 2.0.3 +* Remediates CVE-2021-3765 + + ## 2.0.2 * add typescript definitions * update deps diff --git a/package-lock.json b/package-lock.json index 5e88dc2..6b686ee 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "alexa-verifier-middleware", - "version": "2.0.1", + "version": "2.0.3", "lockfileVersion": 2, "requires": true, "packages": { "": { "name": "alexa-verifier-middleware", - "version": "2.0.1", + "version": "2.0.3", "license": "MIT", "dependencies": { "alexa-verifier": "^3.0.2" @@ -541,7 +541,7 @@ "integrity": "sha512-M9pJp/fbmniEvQ0IAoZ6jIXCJ9zIGaxZHRi9n7FPwoSPsMm8IcCWAE0AGjQEmshAg8oSxTRnUOsRrkRWxZYzBw==", "dependencies": { "node-forge": "^1.2.1", - "validator": "^9.0.0" + "validator": "^13.7.0" }, "engines": { "node": ">=12.17" @@ -5145,9 +5145,9 @@ } }, "node_modules/validator": { - "version": "9.4.1", - "resolved": "https://registry.npmjs.org/validator/-/validator-9.4.1.tgz", - "integrity": "sha512-YV5KjzvRmSyJ1ee/Dm5UED0G+1L4GZnLN3w6/T+zZm8scVua4sOhYKWTUrKa0H/tMiJyO9QLHMPN+9mB/aMunA==", + "version": "13.11.0", + "resolved": "https://registry.npmjs.org/validator/-/validator-13.11.0.tgz", + "integrity": "sha512-Ii+sehpSfZy+At5nPdnyMhx78fEoPDkR2XW/zimHEL3MyGJQOCQ7WeP20jPYRz7ZCpcKLB21NxuXHF3bxjStBQ==", "engines": { "node": ">= 0.10" } @@ -5770,7 +5770,7 @@ "integrity": "sha512-M9pJp/fbmniEvQ0IAoZ6jIXCJ9zIGaxZHRi9n7FPwoSPsMm8IcCWAE0AGjQEmshAg8oSxTRnUOsRrkRWxZYzBw==", "requires": { "node-forge": "^1.2.1", - "validator": "^9.0.0" + "validator": "^13.7.0" } }, "ansi-regex": { @@ -9049,9 +9049,9 @@ "dev": true }, "validator": { - "version": "9.4.1", - "resolved": "https://registry.npmjs.org/validator/-/validator-9.4.1.tgz", - "integrity": "sha512-YV5KjzvRmSyJ1ee/Dm5UED0G+1L4GZnLN3w6/T+zZm8scVua4sOhYKWTUrKa0H/tMiJyO9QLHMPN+9mB/aMunA==" + "version": "13.11.0", + "resolved": "https://registry.npmjs.org/validator/-/validator-13.11.0.tgz", + "integrity": "sha512-Ii+sehpSfZy+At5nPdnyMhx78fEoPDkR2XW/zimHEL3MyGJQOCQ7WeP20jPYRz7ZCpcKLB21NxuXHF3bxjStBQ==" }, "vary": { "version": "1.1.2", diff --git a/package.json b/package.json index 29bc2f9..9d765b1 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "alexa-verifier-middleware", - "version": "2.0.2", + "version": "2.0.3", "description": "An expressjs middleware that verifies HTTP requests sent to an Alexa skill are sent from Amazon.", "type": "module", "types": "index.d.ts",