Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #12

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/react-scripts/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change
low severity Information Disclosure
SNYK-JS-KINDOF-537849
Yes
Commit messages
Package name: fork-ts-checker-webpack-plugin The new version differs by 117 commits.

See the full diff

Package name: sass-loader The new version differs by 44 commits.
  • bcb06d5 chore(release): 7.2.0
  • 6fc9d4e fix: prefer `sass`/`scss`/`css` extensions (#711)
  • 28f1884 feat: allow customize `mainFields` and `extensions` (#710)
  • 2a51502 fix: relax node engine (#708)
  • 9e5a45d refactor: avoid `lodash.tail` (#707)
  • e279f2a fix: better handle stdin in sources (#681)
  • 9162e45 chore: deps update (#673)
  • 69c6f91 docs: add source-map to style-loader (#661)
  • 6c9654d feat: allow passing `functions` option as function (#651)
  • 2d6045b test: support import index file from package (#649)
  • aa64e1b feat: support `data` as `Function` (#648)
  • a8709c9 feat: support `sass` field in `package.json` (#647)
  • ff90dd6 feat: support auto resolving `dart-sass`
  • f524223 fix: prefer `scss`, `sass` and `css` extensions in resolving (#645)
  • 2adcca3 style: use prettier (#644)
  • bc3b848 chore: migrate on defaults eslint config (#643)
  • a80cdb1 ci: improve appveyor config (#642)
  • f799569 chore: integrate lint-staged (#641)
  • d56c0f8 chore: integrate commitlint (#640)
  • 69dc5e5 chore: integrate github templates (#639)
  • 5984a2c chore(deps): update (#638)
  • 472d09a docs: rename `dart-sass` to `sass` (#624)
  • a7bf7c0 docs(readme): add suggestion for `mini-css-extract-plugin` (#597)
  • f4bdcfe test: upgrade webpack-dev-server (#605) (#606)

See the full diff

Package name: ts-jest The new version differs by 250 commits.
  • 6916e7b Merge pull request #650 from kulshekhar/kulshekhar-patch-1
  • 54a30eb Bump the version (minor)
  • 9e61969 Merge pull request #626 from huafu/feature/upgrade-babel-and-fix-tsconfig
  • ef21f50 Merge branch 'master' into feature/upgrade-babel-and-fix-tsconfig
  • c67ba4d Merge pull request #649 from kulshekhar/greenkeeper/monorepo.react-16.4.2
  • 9a6904f Merge branch 'master' of https://github.com/kulshekhar/ts-jest into feature/upgrade-babel-and-fix-tsconfig
  • 8a94008 chore(package): update react-test-renderer to version 16.4.2
  • 6e73fb9 chore(package): update react to version 16.4.2
  • c947791 chore(package): update @types/node to version 10.5.5 (#646)
  • fd24ae6 Merge pull request #640 from jmheik/to-dev-deps
  • e2028da Merge branch 'master' into to-dev-deps
  • 4396dde Merge pull request #641 from jeznag/patch-1
  • 7d78123 Merge branch 'master' into patch-1
  • b38e4ca Add TypeScript ^3.0.0 as supported peer dependencies (#644)
  • 1e287f3 Add more details on using module name mapper
  • df71945 doc: adds troubleshooting wiki page links
  • 0b2e406 Move dev only deps to devDependencies.
  • fb5cd12 chore: simplify jest config test helper + moves test utils
  • ddc8c32 chore: moves test-utils.ts in __helpers__ dir
  • a5370cf Merge branch 'master' into feature/upgrade-babel-and-fix-tsconfig
  • db590d2 Update @types/react to the latest version 🚀 (#631)
  • 4fc3933 chore: changes after GeeWee review
  • fbe4f1f perf: do not hash cache key, jest does it underneath
  • 5ab100c fix: resolves correctly config file path (fix #636)

See the full diff

Package name: webpack-dev-server The new version differs by 39 commits.
  • 298341f chore(release): 2.11.4
  • c42d0da fix: check origin header for websocket connection (#1626)
  • 2be7196 chore: update dependencies in V2 branch, fix compatibility with Node 10 (#1715)
  • 7cdfb74 2.11.3
  • b71137e Increase sockjs-client version for security fix
  • f33be5b 2.11.2
  • dd32166 Fix support for DynamicEntryPlugin (#1319)
  • ab4eeb0 Fix page not reloading after fixing first error on page (#1317)
  • 83c1625 2.11.1
  • 3aa15aa Merge pull request #1273 from yyx990803/master
  • b78e249 fix: pin strip-ansi to 3.x for ES5 compat
  • 8c1ed7a 2.11.0
  • b0fa5f6 Merge pull request #1270 from yyx990803/client-refactor
  • 676d590 revert to prepublish (fix ci)
  • 449494f cleanup client build setup
  • 6689cb8 adding test for dependency lock-down
  • 3e220fe 2.10.1
  • aaf7fce rollback yargs to 6.6.0
  • ca8b5aa 2.10.0 (#1258)
  • 17355f0 transpile client bundles with babel (#1242)
  • ce30460 rolling back webpack-dev-midddleware 2.0, as it's node6+
  • 00e8500 updating deps and patching as necessary
  • 082ddae maint only mode
  • c9c61f2 fix(package): Increase minimum `marked` version for ReDos vuln (#1255)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Version 2.6.0 not on npm
1 participant