Skip to content

[Snyk] Fix for 1 vulnerabilities #12

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/react-scripts/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change
low severity Information Disclosure
SNYK-JS-KINDOF-537849
Yes
Commit messages
Package name: fork-ts-checker-webpack-plugin The new version differs by 117 commits.

See the full diff

Package name: sass-loader The new version differs by 44 commits.
  • bcb06d5 chore(release): 7.2.0
  • 6fc9d4e fix: prefer `sass`/`scss`/`css` extensions (#711)
  • 28f1884 feat: allow customize `mainFields` and `extensions` (#710)
  • 2a51502 fix: relax node engine (#708)
  • 9e5a45d refactor: avoid `lodash.tail` (#707)
  • e279f2a fix: better handle stdin in sources (#681)
  • 9162e45 chore: deps update (#673)
  • 69c6f91 docs: add source-map to style-loader (#661)
  • 6c9654d feat: allow passing `functions` option as function (#651)
  • 2d6045b test: support import index file from package (#649)
  • aa64e1b feat: support `data` as `Function` (#648)
  • a8709c9 feat: support `sass` field in `package.json` (#647)
  • ff90dd6 feat: support auto resolving `dart-sass`
  • f524223 fix: prefer `scss`, `sass` and `css` extensions in resolving (#645)
  • 2adcca3 style: use prettier (#644)
  • bc3b848 chore: migrate on defaults eslint config (#643)
  • a80cdb1 ci: improve appveyor config (#642)
  • f799569 chore: integrate lint-staged (#641)
  • d56c0f8 chore: integrate commitlint (#640)
  • 69dc5e5 chore: integrate github templates (#639)
  • 5984a2c chore(deps): update (#638)
  • 472d09a docs: rename `dart-sass` to `sass` (#624)
  • a7bf7c0 docs(readme): add suggestion for `mini-css-extract-plugin` (#597)
  • f4bdcfe test: upgrade webpack-dev-server (#605) (#606)

See the full diff

Package name: ts-jest The new version differs by 250 commits.
  • 6916e7b Merge pull request #650 from kulshekhar/kulshekhar-patch-1
  • 54a30eb Bump the version (minor)
  • 9e61969 Merge pull request #626 from huafu/feature/upgrade-babel-and-fix-tsconfig
  • ef21f50 Merge branch 'master' into feature/upgrade-babel-and-fix-tsconfig
  • c67ba4d Merge pull request #649 from kulshekhar/greenkeeper/monorepo.react-16.4.2
  • 9a6904f Merge branch 'master' of https://github.com/kulshekhar/ts-jest into feature/upgrade-babel-and-fix-tsconfig
  • 8a94008 chore(package): update react-test-renderer to version 16.4.2
  • 6e73fb9 chore(package): update react to version 16.4.2
  • c947791 chore(package): update @types/node to version 10.5.5 (#646)
  • fd24ae6 Merge pull request #640 from jmheik/to-dev-deps
  • e2028da Merge branch 'master' into to-dev-deps
  • 4396dde Merge pull request #641 from jeznag/patch-1
  • 7d78123 Merge branch 'master' into patch-1
  • b38e4ca Add TypeScript ^3.0.0 as supported peer dependencies (#644)
  • 1e287f3 Add more details on using module name mapper
  • df71945 doc: adds troubleshooting wiki page links
  • 0b2e406 Move dev only deps to devDependencies.
  • fb5cd12 chore: simplify jest config test helper + moves test utils
  • ddc8c32 chore: moves test-utils.ts in __helpers__ dir
  • a5370cf Merge branch 'master' into feature/upgrade-babel-and-fix-tsconfig
  • db590d2 Update @types/react to the latest version 🚀 (#631)
  • 4fc3933 chore: changes after GeeWee review
  • fbe4f1f perf: do not hash cache key, jest does it underneath
  • 5ab100c fix: resolves correctly config file path (fix #636)

See the full diff

Package name: webpack-dev-server The new version differs by 39 commits.
  • 298341f chore(release): 2.11.4
  • c42d0da fix: check origin header for websocket connection (#1626)
  • 2be7196 chore: update dependencies in V2 branch, fix compatibility with Node 10 (#1715)
  • 7cdfb74 2.11.3
  • b71137e Increase sockjs-client version for security fix
  • f33be5b 2.11.2
  • dd32166 Fix support for DynamicEntryPlugin (#1319)
  • ab4eeb0 Fix page not reloading after fixing first error on page (#1317)
  • 83c1625 2.11.1
  • 3aa15aa Merge pull request #1273 from yyx990803/master
  • b78e249 fix: pin strip-ansi to 3.x for ES5 compat
  • 8c1ed7a 2.11.0
  • b0fa5f6 Merge pull request #1270 from yyx990803/client-refactor
  • 676d590 revert to prepublish (fix ci)
  • 449494f cleanup client build setup
  • 6689cb8 adding test for dependency lock-down
  • 3e220fe 2.10.1
  • aaf7fce rollback yargs to 6.6.0
  • ca8b5aa 2.10.0 (#1258)
  • 17355f0 transpile client bundles with babel (#1242)
  • ce30460 rolling back webpack-dev-midddleware 2.0, as it's node6+
  • 00e8500 updating deps and patching as necessary
  • 082ddae maint only mode
  • c9c61f2 fix(package): Increase minimum `marked` version for ReDos vuln (#1255)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Version 2.6.0 not on npm
1 participant