Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

My Security update #9398

Closed
wants to merge 83 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
83 commits
Select commit Hold shift + click to select a range
bead342
Adds Babel plugin babel-plugin-optimize-react
trueadm Jan 17, 2019
591ce25
Typo
trueadm Jan 17, 2019
835fcbd
Increase version and added fix for no default import
trueadm Jan 17, 2019
f472a2a
Fixed more bugs + added more tests + bumped version
trueadm Jan 17, 2019
d335e0b
Adds support for more React imports and fixes a bunch of bugs
trueadm Jan 21, 2019
b22c4b3
Updated README.md
trueadm Jan 21, 2019
e1e660f
Add Lighthouse audit command
mrmckeb Nov 16, 2019
c2a87e0
Bump elliptic from 6.5.2 to 6.5.3 in /docusaurus/website
dependabot[bot] Jul 31, 2020
3830f15
Bump websocket-extensions from 0.1.3 to 0.1.4 in /docusaurus/website
dependabot[bot] Jul 31, 2020
929d86d
Bump lodash from 4.17.15 to 4.17.19 in /docusaurus/website
dependabot[bot] Jul 31, 2020
193b3a1
Merge pull request #1 from phibosGit/dependabot/npm_and_yarn/docusaur…
phibosGit Jul 31, 2020
97055a1
Merge pull request #2 from phibosGit/dependabot/npm_and_yarn/docusaur…
phibosGit Jul 31, 2020
1f72595
Merge pull request #3 from phibosGit/dependabot/npm_and_yarn/docusaur…
phibosGit Jul 31, 2020
8f2237a
Create workflows
phibosGit Jul 31, 2020
7a7f18f
Google Files
phibosGit Jul 31, 2020
c0c1bbc
Merge pull request #4 from phibosGit/add-babel-plugin-optimize-react
phibosGit Jul 31, 2020
0f85a69
Security
phibosGit Jul 31, 2020
95d7970
Atualização
phibosGit Jul 31, 2020
8ad2379
Merge branch 'master' into feat/audits
phibosGit Aug 1, 2020
09bbed0
Merge pull request #5 from phibosGit/feat/audits
phibosGit Aug 1, 2020
1f0d525
Bot de Dependências
phibosGit Aug 1, 2020
a40e86c
Merge pull request #6 from phibosGit/phibosGit-patch-1
phibosGit Aug 1, 2020
ac08b64
Azure Conect
phibosGit Aug 1, 2020
7c9476b
Create greetings.yml
phibosGit Aug 1, 2020
87f655d
Bump actions/setup-node from v1 to v2.1.1
dependabot[bot] Aug 1, 2020
fe96178
Update greetings.yml
phibosGit Aug 1, 2020
39edc14
Nova Versão
phibosGit Aug 1, 2020
515d0a1
Update running-tests.md (#10)
phibosGit Aug 1, 2020
59368eb
Delete azure.yml
phibosGit Aug 1, 2020
04f895f
Delete google.yml
phibosGit Aug 1, 2020
f19bf2f
Delete greethinks.yml
phibosGit Aug 1, 2020
e57b2d2
Delete node.js.yml
phibosGit Aug 1, 2020
edb8098
feat: exit on outdated create-react-app version (#9)
phibosGit Aug 1, 2020
1a3f1ba
Bump escape-string-regexp from 2.0.0 to 4.0.0
dependabot-preview[bot] Aug 1, 2020
1d1fa19
Bump escape-string-regexp from 2.0.0 to 4.0.0 (#11)
dependabot-preview[bot] Aug 1, 2020
bb8c246
Bump @babel/runtime from 7.10.5 to 7.11.0 (#13)
dependabot-preview[bot] Aug 1, 2020
9e45408
Bump css-loader from 3.6.0 to 4.2.0 (#12)
dependabot-preview[bot] Aug 1, 2020
20e2cd3
Bump flow-bin from 0.116.1 to 0.130.0 (#19)
dependabot-preview[bot] Aug 1, 2020
728dd9f
Bump commander from 4.1.0 to 6.0.0 (#21)
dependabot-preview[bot] Aug 1, 2020
f751536
Bump jest-circus from 26.1.0 to 26.2.2 (#17)
dependabot-preview[bot] Aug 1, 2020
b3a4b7f
Bump lerna from 3.20.2 to 3.22.1 (#23)
dependabot-preview[bot] Aug 1, 2020
2ebc7dc
Bump babel-plugin-tester from 8.0.1 to 9.2.0 (#22)
dependabot-preview[bot] Aug 1, 2020
7647746
Bump envinfo from 7.5.1 to 7.7.2 (#20)
dependabot-preview[bot] Aug 1, 2020
2f57129
Bump webpack from 4.43.0 to 4.44.1 (#18)
dependabot-preview[bot] Aug 1, 2020
29615ce
Bump escape-string-regexp from 2.0.0 to 4.0.0 (#16)
phibosGit Aug 1, 2020
1a5f372
Bump jest-resolve from 26.1.0 to 26.2.2 (#14)
dependabot-preview[bot] Aug 1, 2020
52fdafe
Bump jest from 23.6.0 to 26.2.2 (#15)
dependabot-preview[bot] Aug 1, 2020
c772ab5
Create node.js.yml
phibosGit Aug 1, 2020
a7bd086
Azure Workflow
phibosGit Aug 1, 2020
6be4677
Bump puppeteer from 3.3.0 to 5.2.1 (#26)
dependabot-preview[bot] Aug 1, 2020
1716d14
Bump @babel/core from 7.10.5 to 7.11.0 (#29)
dependabot-preview[bot] Aug 1, 2020
ac8a7fe
Bump @babel/plugin-proposal-optional-chaining from 7.10.4 to 7.11.0 (…
dependabot-preview[bot] Aug 1, 2020
3d07f07
Bump source-map from 0.5.6 to 0.7.3 (#30)
dependabot-preview[bot] Aug 1, 2020
dc3a902
Bump @babel/preset-env from 7.10.4 to 7.11.0 (#31)
dependabot-preview[bot] Aug 1, 2020
b6fc0a2
Bump meow from 6.1.1 to 7.0.1
dependabot-preview[bot] Aug 1, 2020
15ec991
Bump lighthouse from 5.6.0 to 6.1.1
dependabot-preview[bot] Aug 1, 2020
4d7c4b7
Bump immer from 1.10.0 to 7.0.7 (#34)
dependabot-preview[bot] Aug 1, 2020
299e73d
Bump @babel/plugin-transform-runtime from 7.10.5 to 7.11.0
dependabot-preview[bot] Aug 1, 2020
2dae428
Updated README.md Templates to Follow ESLint Markdown Rules (#9241)
Aug 1, 2020
36d2aa4
[Doc] fix React Testing Library example (#9245)
sakit0 Aug 1, 2020
52f75fb
Bump actions/setup-node from v1 to v2.1.1
dependabot[bot] Aug 1, 2020
55edf7a
Merge pull request #36 from facebook/master
phibosGit Aug 2, 2020
f2f3eed
Merge pull request #33 from phibosGit/dependabot/npm_and_yarn/lightho…
phibosGit Aug 2, 2020
6d3e947
Merge pull request #32 from phibosGit/dependabot/npm_and_yarn/babel/p…
phibosGit Aug 2, 2020
753ffcf
Merge pull request #27 from phibosGit/dependabot/npm_and_yarn/meow-7.0.1
phibosGit Aug 2, 2020
360df98
Bump inquirer from 7.3.2 to 7.3.3
dependabot-preview[bot] Aug 2, 2020
3de9f33
Bump tempy from 0.2.1 to 0.6.0
dependabot-preview[bot] Aug 2, 2020
3dba6e0
Bump jest-environment-jsdom-fourteen from 0.1.0 to 1.0.1
dependabot-preview[bot] Aug 2, 2020
b5624ea
Bump sass-loader from 8.0.2 to 9.0.2
dependabot-preview[bot] Aug 2, 2020
2bb9de4
Bump fork-ts-checker-webpack-plugin from 4.1.6 to 5.0.13
dependabot-preview[bot] Aug 2, 2020
a4000ac
Bump lerna-changelog from 0.8.3 to 1.0.1
dependabot-preview[bot] Aug 3, 2020
88c9b98
Bump postcss-normalize from 8.0.1 to 9.0.0
dependabot-preview[bot] Aug 3, 2020
afe1cdf
Bump jest-fetch-mock from 2.1.2 to 3.0.3
dependabot-preview[bot] Aug 3, 2020
2286ef4
Merge pull request #41 from phibosGit/dependabot/npm_and_yarn/fork-ts…
phibosGit Aug 3, 2020
e55d790
Merge pull request #40 from phibosGit/dependabot/npm_and_yarn/sass-lo…
phibosGit Aug 3, 2020
6825a75
Merge pull request #39 from phibosGit/dependabot/npm_and_yarn/jest-en…
phibosGit Aug 3, 2020
08cb528
Merge pull request #38 from phibosGit/dependabot/npm_and_yarn/tempy-0…
phibosGit Aug 3, 2020
931f0c7
Merge pull request #37 from phibosGit/dependabot/npm_and_yarn/inquire…
phibosGit Aug 3, 2020
de40aea
Merge pull request #42 from phibosGit/dependabot/npm_and_yarn/lerna-c…
phibosGit Aug 3, 2020
57880a1
Merge pull request #43 from phibosGit/dependabot/npm_and_yarn/postcss…
phibosGit Aug 3, 2020
77672bf
Merge pull request #44 from phibosGit/dependabot/npm_and_yarn/jest-fe…
phibosGit Aug 3, 2020
7a6af38
Merge pull request #45 from phibosGit/dependabot/npm_and_yarn/escape-…
phibosGit Aug 3, 2020
11c65bd
Merge pull request #46 from facebook/master
phibosGit Aug 3, 2020
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://help.github.com/github/administering-a-repository/configuration-options-for-dependency-updates

version: 2
updates:
- package-ecosystem: "github-actions" # See documentation for possible values
directory: "/" # Location of package manifests
schedule:
interval: "daily"
29 changes: 29 additions & 0 deletions .github/workflows/node.js.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# This workflow will do a clean install of node dependencies, build the source code and run tests across different versions of node
# For more information see: https://help.github.com/actions/language-and-framework-guides/using-nodejs-with-github-actions

name: Node.js CI

on:
push:
branches: [ master ]
pull_request:
branches: [ master ]

jobs:
build:

runs-on: ubuntu-latest

strategy:
matrix:
node-version: [10.x, 12.x, 14.x]

steps:
- uses: actions/checkout@v2
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v2.1.1
with:
node-version: ${{ matrix.node-version }}
- run: npm ci
- run: npm run build --if-present
- run: npm test
21 changes: 21 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Security Policy

## Supported Versions

Use this section to tell people about which versions of your project are
currently being supported with security updates.

| Version | Supported |
| ------- | ------------------ |
| 5.1.x | :white_check_mark: |
| 5.0.x | :white_check_mark: |
| 4.0.x | :white_check_mark: |
| < 4.0 | :white_check_mark: |

## Reporting a Vulnerability

Use this section to tell people how to report a vulnerability.

Tell them where to go, how often they can expect to get an update on a
reported vulnerability, what to expect if the vulnerability is accepted or
declined, etc.
33 changes: 33 additions & 0 deletions azure.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# This is a basic workflow to help you get started with Actions

name: CI

# Controls when the action will run. Triggers the workflow on push or pull request
# events but only for the master branch
on:
push:
branches: [ master ]
pull_request:
branches: [ master ]

# A workflow run is made up of one or more jobs that can run sequentially or in parallel
jobs:
# This workflow contains a single job called "build"
build:
# The type of runner that the job will run on
runs-on: ubuntu-latest

# Steps represent a sequence of tasks that will be executed as part of the job
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- uses: actions/checkout@v2

# Runs a single command using the runners shell
- name: Run a one-line script
run: echo Hello, world!

# Runs a set of commands using the runners shell
- name: Run a multi-line script
run: |
echo Add other actions to build,
echo test, and deploy your project.
24 changes: 12 additions & 12 deletions docusaurus/website/yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -1748,9 +1748,9 @@ bluebird@^3.5.5, bluebird@^3.7.1:
integrity sha512-XpNj6GDQzdfW+r2Wnn7xiSAd7TM3jzkxGXBGTtWKuSXv1xUV+azxAm8jdWZN06QTQk+2N2XB9jRDkvbmQmcRtg==

bn.js@^4.0.0, bn.js@^4.1.0, bn.js@^4.1.1, bn.js@^4.4.0:
version "4.11.8"
resolved "https://registry.yarnpkg.com/bn.js/-/bn.js-4.11.8.tgz#2cde09eb5ee341f484746bb0309b3253b1b1442f"
integrity sha512-ItfYfPLkWHUjckQCk8xC+LwxgK8NYcXywGigJgSwOP8Y2iyWT4f2vsZnoOXTTbo+o5yXmIUJ4gn5538SO5S3gA==
version "4.11.9"
resolved "https://registry.yarnpkg.com/bn.js/-/bn.js-4.11.9.tgz#26d556829458f9d1e81fc48952493d0ba3507828"
integrity sha512-E6QoYqCKZfgatHTdHzs1RRKP7ip4vvm+EyRUeE2RF0NblwVvb0p6jSVeNTOFxPn26QXN2o6SMfNxKp6kU8zQaw==

body-parser@1.19.0:
version "1.19.0"
Expand Down Expand Up @@ -3150,9 +3150,9 @@ electron-to-chromium@^1.3.247, electron-to-chromium@^1.3.322:
integrity sha512-Tc8JQEfGQ1MzfSzI/bTlSr7btJv/FFO7Yh6tanqVmIWOuNCu6/D1MilIEgLtmWqIrsv+o4IjpLAhgMBr/ncNAA==

elliptic@^6.0.0:
version "6.5.2"
resolved "https://registry.yarnpkg.com/elliptic/-/elliptic-6.5.2.tgz#05c5678d7173c049d8ca433552224a495d0e3762"
integrity sha512-f4x70okzZbIQl/NSRLkI/+tteV/9WqL98zx+SQ69KbXxmVrmjwsNUPn/gYJJ0sHvEak24cZgHIPegRePAtA/xw==
version "6.5.3"
resolved "https://registry.yarnpkg.com/elliptic/-/elliptic-6.5.3.tgz#cb59eb2efdaf73a0bd78ccd7015a62ad6e0f93d6"
integrity sha512-IMqzv5wNQf+E6aHeIqATs0tOLeOTwj1QKbRcS3jBbYkl5oLAserA8yJTT7/VyHUYG91PRmPyeQDObKLPpeS4dw==
dependencies:
bn.js "^4.4.0"
brorand "^1.0.1"
Expand Down Expand Up @@ -5219,9 +5219,9 @@ lodash.uniq@4.5.0, lodash.uniq@^4.5.0:
integrity sha1-0CJTc662Uq3BvILklFM5qEJ1R3M=

lodash@^4.17.11, lodash@^4.17.12, lodash@^4.17.13, lodash@^4.17.14, lodash@^4.17.15, lodash@^4.17.5:
version "4.17.15"
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.15.tgz#b447f6670a0455bbfeedd11392eff330ea097548"
integrity sha512-8xOcRHvCjnocdS5cpwXQXVzmmh5e5+saE2QGoeQmbKmRS6J3VQppPOIt0MnmE+4xlZoumy0GPG0D0MVIQbNA1A==
version "4.17.19"
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.19.tgz#e48ddedbe30b3321783c5b4301fbd353bc1e4a4b"
integrity sha512-JNvd8XER9GQX0v2qJgsaN/mzFCNA5BRe/j8JN9d+tWyGLSodKQHKFicdwNYzWwI3wjRnaKPsGj1XkBjx/F96DQ==

loglevel@^1.6.4:
version "1.6.6"
Expand Down Expand Up @@ -9137,9 +9137,9 @@ websocket-driver@>=0.5.1:
websocket-extensions ">=0.1.1"

websocket-extensions@>=0.1.1:
version "0.1.3"
resolved "https://registry.yarnpkg.com/websocket-extensions/-/websocket-extensions-0.1.3.tgz#5d2ff22977003ec687a4b87073dfbbac146ccf29"
integrity sha512-nqHUnMXmBzT0w570r2JpJxfiSD1IzoI+HGVdd3aZ0yNi3ngvQ4jv1dtHt5VGxfI2yj5yqImPhOK4vmIh2xMbGg==
version "0.1.4"
resolved "https://registry.yarnpkg.com/websocket-extensions/-/websocket-extensions-0.1.4.tgz#7f8473bc839dfd87608adb95d7eb075211578a42"
integrity sha512-OqedPIGOfsDlo31UNwYbCFMSaO9m9G/0faIHj5/dZFDMFqPTcx6UwqyOy3COEaEOg/9VsGIpdqn62W5KhoKSpg==

whatwg-url@^7.0.0:
version "7.1.0"
Expand Down
12 changes: 6 additions & 6 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -30,17 +30,17 @@
"get-port": "^5.1.1",
"globby": "^11.0.0",
"husky": "^4.2.5",
"jest": "26.1.0",
"lerna": "3.20.2",
"lerna-changelog": "~0.8.2",
"jest": "26.2.2",
"lerna": "3.22.1",
"lerna-changelog": "~1.0.1",
"lint-staged": "^10.2.2",
"meow": "^6.1.1",
"meow": "^7.0.1",
"multimatch": "^4.0.0",
"prettier": "2.0.5",
"puppeteer": "^3.0.2",
"puppeteer": "^5.2.1",
"strip-ansi": "^6.0.0",
"svg-term-cli": "^2.1.1",
"tempy": "^0.2.1",
"tempy": "^0.6.0",
"wait-for-localhost": "^3.1.0",
"web-vitals": "^0.2.2"
},
Expand Down
4 changes: 2 additions & 2 deletions packages/babel-plugin-named-asset-import/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,8 @@
"@babel/core": "^7.1.0"
},
"devDependencies": {
"babel-plugin-tester": "^8.0.1",
"jest": "26.1.0"
"babel-plugin-tester": "^9.2.0",
"jest": "26.2.2"
},
"scripts": {
"test": "jest"
Expand Down
1 change: 1 addition & 0 deletions packages/babel-plugin-optimize-react/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
sandbox.js
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove @sandbox

21 changes: 21 additions & 0 deletions packages/babel-plugin-optimize-react/LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright (c) 2013-present, Facebook, Inc.

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
58 changes: 58 additions & 0 deletions packages/babel-plugin-optimize-react/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
# babel-plugin-optimize-react

This Babel 7 plugin optimizes React hooks by transforming common patterns into more effecient output when using with tools such as [Create React App](https://github.com/facebook/create-react-app). For example, with this plugin the following output is optimized as shown:

```js
// Original
var _useState = Object(react__WEBPACK_IMPORTED_MODULE_1_["useState"])(Math.random()),
_State2 = Object(_Users_gaearon_p_create_rreact_app_node_modules_babel_runtime_helpers_esm_sliceToArray_WEBPACK_IMPORTED_MODULE_0__["default"])(_useState, 1),
value = _useState2[0];

// With this plugin
var useState = react__WEBPACK_IMPORTED_MODULE_1_.useState;
var __ref__0 = useState(Math.random());
var value = __ref__0[0];
```

## Named imports for React get transformed

```js
// Original
import React, {memo, useState} from 'react';

// With this plugin
import React from 'react';
const {memo, useState} = React;
```

## Array destructuring transform for React's built-in hooks

```js
// Original
const [counter, setCounter] = useState(0);

// With this plugin
const __ref__0 = useState(0);
const counter = __ref__0[0];
const setCounter = __ref__0[1];
```

## React.createElement becomes a hoisted constant

```js
// Original
import React from 'react';

function MyComponent() {
return React.createElement('div', null, 'Hello world');
}

// With this plugin
import React from 'react';
const __reactCreateElement__ = React.createElement;

function MyComponent() {
return __reactCreateElement__('div', null, 'Hello world');
}
```

Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
// Jest Snapshot v1, https://goo.gl/fbAQLP

exports[`React createElement transforms should transform React.createElement calls #2 1`] = `
"const React = require(\\"react\\");

const __reactCreateElement__ = React.createElement;
export function MyComponent() {
return __reactCreateElement__(\\"div\\", null, __reactCreateElement__(\\"span\\", null, \\"Hello world!\\"));
}"
`;

exports[`React createElement transforms should transform React.createElement calls #3 1`] = `
"const React = require(\\"react\\");

const __reactCreateElement__ = React.createElement;

const node = __reactCreateElement__(\\"div\\", null, __reactCreateElement__(\\"span\\", null, \\"Hello world!\\"));

export function MyComponent() {
return node;
}"
`;

exports[`React createElement transforms should transform React.createElement calls #4 1`] = `
"import * as React from \\"react\\";
const __reactCreateElement__ = React.createElement;

const node = __reactCreateElement__(\\"div\\", null, __reactCreateElement__(\\"span\\", null, \\"Hello world!\\"));

export function MyComponent() {
return node;
}"
`;

exports[`React createElement transforms should transform React.createElement calls 1`] = `
"import React from \\"react\\";
const __reactCreateElement__ = React.createElement;
export function MyComponent() {
return __reactCreateElement__(\\"div\\");
}"
`;
Loading