Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade: , postcss, , , , , eslint-plugin-react, prettier #17

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Exkaleburx
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@crowdin/cli
from 3.17.0 to 3.19.4 | 6 versions ahead of your current version | 4 months ago
on 2024-05-16
postcss
from 8.4.31 to 8.4.41 | 10 versions ahead of your current version | a month ago
on 2024-08-05
@docusaurus/core
from 2.2.0 to 2.4.3 | 5 versions ahead of your current version | a year ago
on 2023-09-20
@docusaurus/plugin-google-gtag
from 2.4.0 to 2.4.3 | 2 versions ahead of your current version | a year ago
on 2023-09-20
@docusaurus/theme-search-algolia
from 2.2.0 to 2.4.3 | 5 versions ahead of your current version | a year ago
on 2023-09-20
@docusaurus/preset-classic
from 2.2.0 to 2.4.3 | 5 versions ahead of your current version | a year ago
on 2023-09-20
eslint-plugin-react
from 7.31.10 to 7.35.0 | 13 versions ahead of your current version | 2 months ago
on 2024-07-20
prettier
from 2.7.1 to 2.8.8 | 9 versions ahead of your current version | a year ago
on 2023-04-23

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Remote Code Execution (RCE)
SNYK-JS-ETA-2936803
432 Proof of Concept
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
432 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-ETA-3261240
432 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-3244450
432 Proof of Concept
Release notes
Package name: @crowdin/cli from @crowdin/cli GitHub release notes
Package name: postcss
  • 8.4.41 - 2024-08-05
  • 8.4.40 - 2024-07-24
    • Moved to getter/setter in nodes types to help Sass team (by @ nex3).
  • 8.4.39 - 2024-06-29
  • 8.4.38 - 2024-03-20
  • 8.4.37 - 2024-03-19
    • Fixed original.column are not numbers error in another case.
  • 8.4.36 - 2024-03-17
    • Fixed original.column are not numbers error on broken previous source map.
  • 8.4.35 - 2024-02-07
  • 8.4.34 - 2024-02-05
  • 8.4.33 - 2024-01-04
  • 8.4.32 - 2023-12-02
  • 8.4.31 - 2023-09-28
from postcss GitHub release notes
Package name: @docusaurus/core
  • 2.4.3 - 2023-09-20
  • 2.4.1 - 2023-05-15
  • 2.4.0 - 2023-03-23
  • 2.3.1 - 2023-02-03
  • 2.3.0 - 2023-01-27
  • 2.2.0 - 2022-10-29
from @docusaurus/core GitHub release notes
Package name: @docusaurus/plugin-google-gtag
  • 2.4.3 - 2023-09-20
  • 2.4.1 - 2023-05-15
  • 2.4.0 - 2023-03-23
from @docusaurus/plugin-google-gtag GitHub release notes
Package name: @docusaurus/theme-search-algolia
  • 2.4.3 - 2023-09-20
  • 2.4.1 - 2023-05-15
  • 2.4.0 - 2023-03-23
  • 2.3.1 - 2023-02-03
  • 2.3.0 - 2023-01-27
  • 2.2.0 - 2022-10-29
from @docusaurus/theme-search-algolia GitHub release notes
Package name: @docusaurus/preset-classic
  • 2.4.3 - 2023-09-20
  • 2.4.1 - 2023-05-15
  • 2.4.0 - 2023-03-23
  • 2.3.1 - 2023-02-03
  • 2.3.0 - 2023-01-27
  • 2.2.0 - 2022-10-29
from @docusaurus/preset-classic GitHub release notes
Package name: eslint-plugin-react

Snyk has created this PR to upgrade:
  - @crowdin/cli from 3.17.0 to 3.19.4.
    See this package in npm: https://www.npmjs.com/package/@crowdin/cli
  - postcss from 8.4.31 to 8.4.41.
    See this package in npm: https://www.npmjs.com/package/postcss
  - @docusaurus/core from 2.2.0 to 2.4.3.
    See this package in npm: https://www.npmjs.com/package/@docusaurus/core
  - @docusaurus/plugin-google-gtag from 2.4.0 to 2.4.3.
    See this package in npm: https://www.npmjs.com/package/@docusaurus/plugin-google-gtag
  - @docusaurus/theme-search-algolia from 2.2.0 to 2.4.3.
    See this package in npm: https://www.npmjs.com/package/@docusaurus/theme-search-algolia
  - @docusaurus/preset-classic from 2.2.0 to 2.4.3.
    See this package in npm: https://www.npmjs.com/package/@docusaurus/preset-classic
  - eslint-plugin-react from 7.31.10 to 7.35.0.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-react
  - prettier from 2.7.1 to 2.8.8.
    See this package in npm: https://www.npmjs.com/package/prettier

See this project in Snyk:
https://app.snyk.io/org/companykobiimports/project/354b6a13-5c4f-4b02-af2d-19de8a7ab789?utm_source=github&utm_medium=referral&page=upgrade-pr
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants