Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Security upgrade postcss from 6.0.23 to 8.2.13 #370

Merged

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • yarn.lock

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@jamesros161 jamesros161 changed the base branch from master to branch-2.16.3 August 24, 2022 14:57
@jamesros161 jamesros161 merged commit ff2a4f1 into branch-2.16.3 Aug 24, 2022
@jamesros161 jamesros161 deleted the snyk-fix-66404609c3dab4fa81af4af7197eabca branch August 24, 2022 15:05
@jamesros161 jamesros161 added the bug General bug issues label Aug 24, 2022
@jamesros161 jamesros161 added this to the 2.16.3 milestone Aug 24, 2022
jamesros161 added a commit that referenced this pull request Sep 7, 2022
* fix: upgrade @babel/runtime-corejs2 from 7.12.1 to 7.13.17 (#365)

Snyk has created this PR to upgrade @babel/runtime-corejs2 from 7.12.1 to 7.13.17.

See this package in npm:


See this project in Snyk:
https://app.snyk.io/org/cssjoe/project/5d219e30-bbd4-4803-80ef-bce43258a15a?utm_source=github&utm_medium=upgrade-pr

* remove unused variable

* fix: upgrade @wordpress/hooks from 2.10.0 to 2.12.2 (#366)

Snyk has created this PR to upgrade @wordpress/hooks from 2.10.0 to 2.12.2.

See this package in npm:


See this project in Snyk:
https://app.snyk.io/org/cssjoe/project/5d219e30-bbd4-4803-80ef-bce43258a15a?utm_source=github&utm_medium=upgrade-pr

Co-authored-by: jamesros <jamesros@boldgrid.com>

* fix: upgrade @wordpress/dom-ready from 2.11.0 to 2.13.2 (#367)

Snyk has created this PR to upgrade @wordpress/dom-ready from 2.11.0 to 2.13.2.

See this package in npm:


See this project in Snyk:
https://app.snyk.io/org/cssjoe/project/5d219e30-bbd4-4803-80ef-bce43258a15a?utm_source=github&utm_medium=upgrade-pr

Co-authored-by: jamesros <jamesros@boldgrid.com>

* fix: package.json & yarn.lock to reduce vulnerabilities (#504)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-SSH2-1656673

Co-authored-by: jamesros <jamesros@boldgrid.com>

* updated yarn.lock

* fix: package.json & yarn.lock to reduce vulnerabilities (#562)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908

Co-authored-by: jamesros <jamesros@boldgrid.com>

* update yarn.lock

* fix: package.json & yarn.lock to reduce vulnerabilities (#370)

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-POSTCSS-1255640

* update yarn.lock

* update puppeteer & ws

* update 'i'

* update chownr

* updated url-parse

* update follow-redirects

* update moment

* update readme

* fix 'final private' notices

* resolves #516 (#730)

* resolves #401 (#729)

* update version numbers and readme

* specify nanoid version for postcss

* fix secondary hover color display

* update version numbers

Co-authored-by: Snyk bot <snyk-bot@snyk.io>
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
bug General bug issues
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants