fix: package.json & yarn.lock to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ACTIONSCORE-1015402
pull/76/head
snyk-bot 2020-10-02 23:03:50 +00:00
parent c4e44617e2
commit 35d50d30e8
No known key found for this signature in database
GPG Key ID: 09541BBFF0C4C795
2 changed files with 5 additions and 5 deletions

View File

@ -13,7 +13,7 @@
"test": "jest"
},
"dependencies": {
"@actions/core": "^1.2.1",
"@actions/core": "^1.2.6",
"@actions/exec": "1.0.3",
"@actions/github": "^2.1.1"
},

View File

@ -2,10 +2,10 @@
# yarn lockfile v1
"@actions/core@^1.2.1":
version "1.2.2"
resolved "https://registry.yarnpkg.com/@actions/core/-/core-1.2.2.tgz#3c4848d50378f9e3bcb67bcf97813382ec7369ee"
integrity sha512-IbCx7oefq+Gi6FWbSs2Fnw8VkEI6Y4gvjrYprY3RV//ksq/KPMlClOerJ4jRosyal6zkUIc8R9fS/cpRMlGClg==
"@actions/core@^1.2.6":
version "1.2.6"
resolved "https://registry.yarnpkg.com/@actions/core/-/core-1.2.6.tgz#a78d49f41a4def18e88ce47c2cac615d5694bf09"
integrity sha512-ZQYitnqiyBc3D+k7LsgSBmMDVkOVidaagDG7j3fOym77jNunWRuYx7VSHa9GNfFZh+zh61xsCjRj4JxMZlDqTA==
"@actions/exec@1.0.3":
version "1.0.3"