Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade uplot from 1.6.24 to 1.6.31 #32

Open
wants to merge 1 commit into
base: Master
Choose a base branch
from

Conversation

OKEAMAH
Copy link
Owner

@OKEAMAH OKEAMAH commented Sep 30, 2024

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • projects/js-packages/components/package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Prototype Pollution
SNYK-JS-UPLOT-6209224
  249  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

Copy link

vercel bot commented Sep 30, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
jetpack-storybook ❌ Failed (Inspect) Sep 30, 2024 3:15pm

Copy link

changeset-bot bot commented Sep 30, 2024

⚠️ No Changeset found

Latest commit: f96ef69

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Copy link

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We have skipped reviewing this pull request. Here's why:

  • It seems to have been created by a bot ('[Snyk]' found in title). We assume it knows what it's doing!
  • We don't review packaging changes - Let us know if you'd like us to change this.

Copy link

Thank you for your PR!

When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:

  • ✅ Include a description of your PR changes.
  • 🔴 Add a "[Status]" label (In Progress, Needs Team Review, ...).
  • 🔴 Add testing instructions.
  • 🔴 Specify whether this PR includes any changes to data or privacy.
  • 🔴 Add changelog entries to affected projects

This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖


The e2e test report can be found here. Please note that it can take a few minutes after the e2e tests checks are complete for the report to be available.


🔴 Action required: Please include detailed testing steps, explaining how to test your change, like so:

## Testing instructions:

* Go to '..'
*

🔴 Action required: We would recommend that you add a section to the PR description to specify whether this PR includes any changes to data or privacy, like so:

## Does this pull request change what data or activity we track or use?

My PR adds *x* and *y*.

🔴 Action required: Please add missing changelog entries for the following projects: projects/js-packages/components

Use the Jetpack CLI tool to generate changelog entries by running the following command: jetpack changelog add.
Guidelines: /docs/writing-a-good-changelog-entry.md


Follow this PR Review Process:

  1. Ensure all required checks appearing at the bottom of this PR are passing.
  2. Choose a review path based on your changes:
    • A. Team Review: add the "[Status] Needs Team Review" label
      • For most changes, including minor cross-team impacts.
      • Example: Updating a team-specific component or a small change to a shared library.
    • B. Crew Review: add the "[Status] Needs Review" label
      • For significant changes to core functionality.
      • Example: Major updates to a shared library or complex features.
    • C. Both: Start with Team, then request Crew
      • For complex changes or when you need extra confidence.
      • Example: Refactor affecting multiple systems.
  3. Get at least one approval before merging.

Still unsure? Reach out in #jetpack-developers for guidance!

Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@jest/globals@29.4.3 Transitive: eval +13 741 kB simenb
npm/@jest/globals@29.7.0 Transitive: eval +13 741 kB simenb
npm/@mdn/browser-compat-data@5.5.47 None 0 14.5 MB mdn-bot
npm/@microsoft/fetch-event-source@2.0.1 network 0 62.2 kB vishwam
npm/@octokit/auth-token@5.1.1 None 0 19 kB octokitbot
npm/@octokit/rest@20.1.1 Transitive: network +13 6.59 MB octokitbot
npm/@playwright/test@1.45.1 None 0 25.4 kB yurys
npm/@popperjs/core@2.11.8 None 0 1.46 MB fezvrasta
npm/@preact/signals@1.3.0 None +1 301 kB jdecroock
npm/@react-spring/core@9.7.3 environment +4 2.48 MB tdfka_rick
npm/@react-spring/web@9.7.3 environment +4 1.12 MB tdfka_rick
npm/@rollup/plugin-babel@5.3.1 Transitive: environment +21 6.37 MB shellscape
npm/@rollup/plugin-commonjs@26.0.1 filesystem +3 346 kB shellscape
npm/@rollup/plugin-json@4.1.0 None +2 81.2 kB shellscape
npm/@rollup/plugin-node-resolve@13.3.0 filesystem +4 201 kB shellscape
npm/@rollup/plugin-replace@5.0.2 None +2 108 kB shellscape
npm/@rollup/plugin-terser@0.4.3 eval, unsafe 0 28.6 kB shellscape
npm/@rollup/plugin-typescript@8.3.3 environment, filesystem +2 153 kB shellscape
npm/@rushstack/eslint-patch@1.3.3 None 0 33.9 kB odspnpm
npm/@sentry/browser@7.80.1 network +5 6.66 MB sentry-bot
npm/@size-limit/preset-app@11.1.4 Transitive: environment +2 11.5 kB ai
npm/@slack/web-api@7.3.2 filesystem +3 2.66 MB filmaj
npm/@storybook/addon-a11y@8.2.9 None +3 2.85 MB shilman
npm/@storybook/addon-actions@8.2.9 None +3 84.5 kB shilman
npm/@storybook/addon-docs@8.2.9 Transitive: filesystem +5 2.22 MB shilman
npm/@storybook/addon-essentials@8.2.9 None +9 393 kB shilman
npm/@storybook/addon-storysource@8.2.9 None 0 1.89 MB shilman
npm/@storybook/addon-webpack5-compiler-babel@3.0.3 Transitive: filesystem +1 2.79 MB valentinpalkovic
npm/@storybook/blocks@8.2.9 eval +7 2.52 MB shilman
npm/@storybook/components@8.2.9 None 0 1.24 kB shilman
npm/@storybook/manager-api@8.2.9 None 0 1.22 kB shilman
npm/@storybook/preview-api@8.2.9 None 0 1.24 kB shilman
npm/@storybook/react-webpack5@8.2.9 Transitive: filesystem +11 2.47 MB shilman
npm/@storybook/react@8.2.9 None +15 6.81 MB shilman
npm/@storybook/source-loader@8.2.9 filesystem +1 89.4 kB shilman
npm/@storybook/test-runner@0.19.1 environment, eval, filesystem, shell, unsafe +33 9.61 MB shilman
npm/@storybook/theming@8.2.9 None 0 1.56 kB shilman
npm/@svgr/webpack@7.0.0 Transitive: environment, filesystem +21 3.07 MB neoziro
npm/@tanstack/react-query@4.35.3 environment +1 3.6 MB tannerlinsley
npm/@tanstack/react-query@5.0.5 Transitive: environment +1 2.77 MB tannerlinsley
npm/@tanstack/react-query@5.20.5 environment +1 2.85 MB tannerlinsley
npm/@testing-library/dom@10.1.0 environment +11 3.07 MB testing-library-bot
npm/@testing-library/jest-dom@6.4.2 None +18 1.78 MB testing-library-bot
npm/@testing-library/preact@3.2.4 environment +14 3.7 MB testing-library-bot
npm/@testing-library/react@15.0.7 environment 0 4.31 MB testing-library-bot
npm/@testing-library/user-event@14.5.2 None 0 435 kB testing-library-bot
npm/@types/clean-css@4.2.11 None 0 25.2 kB types
npm/@types/cookie@0.6.0 None 0 10.1 kB types
npm/@types/css-tree@2.3.8 None 0 25.7 kB types
npm/@types/jest@29.5.12 None 0 78.7 kB types
npm/@types/jquery@3.5.30 None +1 1.12 MB types
npm/@types/markdown-it@14.1.2 None +2 92.5 kB types
npm/@types/node@20.14.15 None 0 2.09 MB types
npm/@types/qrcode.react@1.0.5 None 0 4.99 kB types
npm/@types/qs@6.9.15 None 0 7.34 kB types
npm/@types/react-dom@18.3.0 None 0 37.8 kB types
npm/@types/react-router-dom@5.3.3 None +2 40.6 kB types
npm/@types/react-slider@1.3.6 None 0 11.8 kB types
npm/@types/react@18.3.3 None +2 1.69 MB types
npm/@types/testing-library__jest-dom@5.14.9 None 0 35.4 kB types
npm/@types/turndown@5.0.5 None 0 7.08 kB types
npm/@types/wordpress__block-editor@11.5.15 None +2 143 kB types
npm/@types/wordpress__editor@13.6.8 None +2 109 kB types
npm/@types/wordpress__media-utils@4.14.4 None 0 4.68 kB types
npm/@typescript-eslint/eslint-plugin@6.21.0 None +10 5.26 MB jameshenry
npm/@typescript-eslint/parser@6.21.0 None +4 1.37 MB jameshenry
npm/@vercel/ncc@0.36.1 filesystem, unsafe 0 15.9 MB vercel-release-bot
npm/@wordpress/annotations@3.5.0 None 0 159 kB gutenbergplugin
npm/@wordpress/api-fetch@7.5.0 None 0 252 kB gutenbergplugin
npm/@wordpress/babel-plugin-import-jsx-pragma@5.5.0 None 0 44.8 kB gutenbergplugin
npm/@wordpress/babel-preset-default@8.5.0 Transitive: environment, eval, filesystem +2 1.52 MB gutenbergplugin
npm/@wordpress/base-styles@5.5.0 None 0 77.4 kB gutenbergplugin
npm/@wordpress/blob@4.5.0 None 0 79.4 kB gutenbergplugin
npm/@wordpress/block-editor@14.0.0 environment Transitive: filesystem +182 52 MB gutenbergplugin
npm/@wordpress/block-serialization-default-parser@5.5.0 None 0 164 kB gutenbergplugin
npm/@wordpress/blocks@13.5.0 environment +11 3.38 MB gutenbergplugin
npm/@wordpress/browserslist-config@6.5.0 None 0 39.3 kB gutenbergplugin
npm/@wordpress/components@28.5.0 environment Transitive: filesystem +120 94.9 MB gutenbergplugin
npm/@wordpress/core-data@7.5.0 None +30 4.57 MB gutenbergplugin
npm/@wordpress/data@10.5.0 environment +19 3.72 MB gutenbergplugin
npm/@wordpress/date@5.5.0 None +1 292 kB gutenbergplugin
npm/@wordpress/dependency-extraction-webpack-plugin@6.5.0 None 0 68.2 kB gutenbergplugin
npm/@wordpress/dom-ready@4.5.0 None 0 64.9 kB gutenbergplugin
npm/@wordpress/edit-post@8.5.0 Transitive: environment, network +50 48.4 MB gutenbergplugin
npm/@wordpress/editor@14.5.0 None +76 76.8 MB gutenbergplugin
npm/@wordpress/element@6.5.0 None +4 441 kB gutenbergplugin
npm/@wordpress/escape-html@3.5.0 None 0 88.5 kB gutenbergplugin
npm/@wordpress/eslint-plugin@20.2.0 Transitive: filesystem +3 299 kB gutenbergplugin
npm/@wordpress/format-library@5.5.0 None +1 759 kB gutenbergplugin
npm/@wordpress/hooks@4.5.0 None 0 220 kB gutenbergplugin
npm/@wordpress/html-entities@4.5.0 None 0 68.3 kB gutenbergplugin
npm/@wordpress/i18n@5.5.0 None 0 232 kB gutenbergplugin
npm/@wordpress/icons@10.5.0 None 0 1.55 MB gutenbergplugin
npm/@wordpress/jest-console@8.5.0 None 0 66.5 kB gutenbergplugin
npm/@wordpress/keycodes@4.5.0 None 0 162 kB gutenbergplugin
npm/@wordpress/media-utils@5.5.0 None 0 189 kB gutenbergplugin
npm/@wordpress/notices@5.5.0 None +1 327 kB gutenbergplugin
npm/@wordpress/plugins@7.5.0 None +2 438 kB gutenbergplugin
npm/@wordpress/postcss-plugins-preset@5.5.0 None 0 38.6 kB gutenbergplugin
npm/@wordpress/primitives@4.5.0 None 0 127 kB gutenbergplugin
npm/@wordpress/private-apis@1.5.0 None 0 113 kB gutenbergplugin
npm/@wordpress/rich-text@7.5.0 None +2 1.2 MB gutenbergplugin
npm/@wordpress/token-list@3.5.0 None 0 101 kB gutenbergplugin
npm/@wordpress/url@4.5.0 None 0 314 kB gutenbergplugin
npm/@wordpress/viewport@6.5.0 None 0 123 kB gutenbergplugin
npm/@wordpress/widgets@4.5.0 None 0 374 kB gutenbergplugin
npm/@wordpress/wordcount@4.5.0 None 0 155 kB gutenbergplugin
npm/allure-playwright@2.9.2 filesystem Transitive: environment +1 211 kB qameta-bot
npm/autoprefixer@10.4.14 environment +1 2.3 MB ai
npm/axios@1.7.4 network 0 2.12 MB jasonsaayman
npm/babel-jest@29.3.1 environment Transitive: eval, filesystem, shell +51 6.01 MB simenb
npm/babel-jest@29.4.3 environment Transitive: eval, filesystem, shell +51 6.01 MB simenb
npm/babel-jest@29.7.0 environment Transitive: eval, filesystem, shell +51 6.01 MB simenb
npm/babel-loader@9.1.2 filesystem 0 38.1 kB nicolo-ribaudo
npm/babel-plugin-inline-json-import@0.3.2 None +2 29 kB yggie
npm/babel-plugin-tester@11.0.4 Transitive: environment, eval, filesystem +1 1.43 MB xunnamius
npm/babel-plugin-transform-rename-properties@0.1.0 None 0 5.03 kB jviide
npm/bounding-client-rect@1.0.5 None 0 8.54 kB tootallnate
npm/browserslist@4.23.1 environment, filesystem +1 2.16 MB ai
npm/camelize@1.0.1 None 0 12.5 kB ljharb
npm/chalk@4.1.2 None +3 85.9 kB sindresorhus
npm/chalk@5.0.1 None 0 41.3 kB sindresorhus
npm/chart.js@3.7.1 None 0 1.16 MB chartjs-ci
npm/cheerio@1.0.0-rc.12 None +4 912 kB feedic
npm/chokidar@3.5.3 environment, filesystem +2 144 kB paulmillr
npm/clean-css@5.3.3 environment, filesystem, network 0 493 kB jakub.pawlowicz
npm/clipboard@2.0.6 None 0 84.2 kB zenorocha
npm/clsx@2.1.1 None 0 8.55 kB lukeed
npm/commander@9.3.0 environment, filesystem, shell 0 169 kB abetomo
npm/compare-versions@3.6.0 None 0 12.4 kB omichelsen
npm/component-uid@0.0.2 None 0 3.78 kB coreh
npm/concurrently@7.6.0 environment, filesystem +1 6.8 MB gustavohenke
npm/config@3.3.7 environment, filesystem 0 92.8 kB markstos
npm/configstore@5.0.1 None 0 7.61 kB sindresorhus
npm/cookie@0.4.1 None 0 18.1 kB dougwilson
npm/copy-webpack-plugin@11.0.0 None 0 77.6 kB evilebottnawi
npm/core-js@3.23.5 environment, eval, filesystem 0 1.01 MB zloirock
npm/crypto-js@4.2.0 None 0 487 kB evanvosberg
npm/css-loader@6.5.1 None 0 173 kB evilebottnawi
npm/css-minimizer-webpack-plugin@5.0.1 eval +7 553 kB evilebottnawi
npm/css-tree@2.3.1 unsafe 0 1.19 MB lahmatiy
npm/debug@4.3.4 environment 0 42.4 kB qix
npm/diff@4.0.2 None 0 335 kB kpdecker

🚮 Removed packages: npm/lodash@4.17.21, npm/regenerator-runtime@0.14.1

View full report↗︎

Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Possible typosquat attack npm/component-uid@0.0.2 ⚠︎

View full report↗︎

Next steps

What is a typosquat?

Package name is similar to other popular packages and may not be the package you want.

Use care when consuming similarly named packages and ensure that you did not intend to consume a different package. Malicious packages often publish using similar names as existing popular packages.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore npm/component-uid@0.0.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants