Blame SOURCES/013-CVE-2021-23648.patch

f6686b
From 76121bc49ce1d5417202ce0a567e4f0f00c75667 Mon Sep 17 00:00:00 2001
f6686b
From: Andreas Gerstmayr <agerstmayr@redhat.com>
f6686b
Date: Tue, 5 Apr 2022 17:40:30 +0200
f6686b
Subject: [PATCH] upgrade @braintree/sanitize-url to v6.0.0
f6686b
f6686b
Resolves: CVE-2021-23648
f6686b
f6686b
diff --git a/package.json b/package.json
f6686b
index 831586ad88..ab8b142ed9 100644
f6686b
--- a/package.json
f6686b
+++ b/package.json
f6686b
@@ -209,7 +209,6 @@
f6686b
     "@sentry/utils": "5.24.2",
f6686b
     "@torkelo/react-select": "3.0.8",
f6686b
     "@types/antlr4": "^4.7.1",
f6686b
-    "@types/braintree__sanitize-url": "4.0.0",
f6686b
     "@types/common-tags": "^1.8.0",
f6686b
     "@types/hoist-non-react-statics": "3.3.1",
f6686b
     "@types/jsurl": "^1.2.28",
f6686b
diff --git a/packages/grafana-data/package.json b/packages/grafana-data/package.json
f6686b
index b24b1af2f4..c3f1b4e181 100644
f6686b
--- a/packages/grafana-data/package.json
f6686b
+++ b/packages/grafana-data/package.json
f6686b
@@ -22,7 +22,7 @@
f6686b
     "typecheck": "tsc --noEmit"
f6686b
   },
f6686b
   "dependencies": {
f6686b
-    "@braintree/sanitize-url": "4.0.0",
f6686b
+    "@braintree/sanitize-url": "6.0.0",
f6686b
     "@types/d3-interpolate": "^1.3.1",
f6686b
     "apache-arrow": "0.16.0",
f6686b
     "eventemitter3": "4.0.7",
f6686b
@@ -36,7 +36,6 @@
f6686b
     "@rollup/plugin-commonjs": "16.0.0",
f6686b
     "@rollup/plugin-json": "4.1.0",
f6686b
     "@rollup/plugin-node-resolve": "10.0.0",
f6686b
-    "@types/braintree__sanitize-url": "4.0.0",
f6686b
     "@types/jest": "26.0.15",
f6686b
     "@types/jquery": "3.3.38",
f6686b
     "@types/lodash": "4.14.123",
f6686b
diff --git a/yarn.lock b/yarn.lock
f6686b
index 3f5e5b80d6..a84bfebaa7 100644
f6686b
--- a/yarn.lock
f6686b
+++ b/yarn.lock
f6686b
@@ -3030,10 +3030,10 @@
f6686b
   resolved "https://registry.yarnpkg.com/@bcoe/v8-coverage/-/v8-coverage-0.2.3.tgz#75a2e8b51cb758a7553d6804a5932d7aace75c39"
f6686b
   integrity sha512-0hYQ8SB4Db5zvZB4axdMHGwEaQjkZzFjQiN9LVYvIFB2nSUHW9tYpxWriPrWDASIxiaXax83REcLxuSdnGPZtw==
f6686b
 
f6686b
-"@braintree/sanitize-url@4.0.0":
f6686b
-  version "4.0.0"
f6686b
-  resolved "https://registry.yarnpkg.com/@braintree/sanitize-url/-/sanitize-url-4.0.0.tgz#2cda79ffd67b6ea919a63b5e1a883b92d636e844"
f6686b
-  integrity sha512-bOoFoTxuEUuri/v1q0OXN0HIrZ2EiZlRSKdveU8vS5xf2+g0TmpXhmxkTc1s+XWR5xZNoVU4uvf/Mher98tfLw==
f6686b
+"@braintree/sanitize-url@6.0.0":
f6686b
+  version "6.0.0"
f6686b
+  resolved "https://registry.yarnpkg.com/@braintree/sanitize-url/-/sanitize-url-6.0.0.tgz#fe364f025ba74f6de6c837a84ef44bdb1d61e68f"
f6686b
+  integrity sha512-mgmE7XBYY/21erpzhexk4Cj1cyTQ9LzvnTxtzM17BJ7ERMNE6W72mQRo0I1Ud8eFJ+RVVIcBNhLFZ3GX4XFz5w==
f6686b
 
f6686b
 "@cnakazawa/watch@^1.0.3":
f6686b
   version "1.0.3"
f6686b
@@ -5752,11 +5752,6 @@
f6686b
   resolved "https://registry.yarnpkg.com/@types/braces/-/braces-3.0.0.tgz#7da1c0d44ff1c7eb660a36ec078ea61ba7eb42cb"
f6686b
   integrity sha512-TbH79tcyi9FHwbyboOKeRachRq63mSuWYXOflsNO9ZyE5ClQ/JaozNKl+aWUq87qPNsXasXxi2AbgfwIJ+8GQw==
f6686b
 
f6686b
-"@types/braintree__sanitize-url@4.0.0":
f6686b
-  version "4.0.0"
f6686b
-  resolved "https://registry.yarnpkg.com/@types/braintree__sanitize-url/-/braintree__sanitize-url-4.0.0.tgz#0e8a834501f8c375d4b3fb8dcf9398a08ebe068d"
f6686b
-  integrity sha512-69eGJ8808/WfTJGsvMi1pxQ9UG5Z+llD1x9ash5QX+qvxElDD+eYNAn19cTEVTq6WwUqrqlaTWVCKaTRFTuGmA==
f6686b
-
f6686b
 "@types/cheerio@*":
f6686b
   version "0.22.13"
f6686b
   resolved "https://registry.yarnpkg.com/@types/cheerio/-/cheerio-0.22.13.tgz#5eecda091a24514185dcba99eda77e62bf6523e6"