From 485b53335ec7daf492748ed56576bc229b37224f Mon Sep 17 00:00:00 2001 From: Mason McAllaster <5580190+McAllaster@users.noreply.github.com> Date: Tue, 4 Aug 2020 16:09:23 -0400 Subject: [PATCH] fix(deps): bump conventionalcommits to 4.3.1 Update the conventional-changelog-conventionalcommits dependency to version 4.3.1 from 4.3.0 to address security vulnerabilities outlined in https://npmjs.com/advisories/1213, present in chain-dependency "dot-prop" which has since been fixed upstream. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index c701310e4..2ec18c6ae 100644 --- a/package.json +++ b/package.json @@ -38,7 +38,7 @@ "chalk": "^2.4.2", "conventional-changelog": "3.1.21", "conventional-changelog-config-spec": "2.1.0", - "conventional-changelog-conventionalcommits": "4.3.0", + "conventional-changelog-conventionalcommits": "4.3.1", "conventional-recommended-bump": "6.0.9", "detect-indent": "^6.0.0", "detect-newline": "^3.1.0",