Skip to content

Conversation

@TheJ-Erk400
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade react-hot-loader from 4.12.12 to 4.13.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 11 versions ahead of your current version.

  • The recommended version was released on 2 years ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
427 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
427 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3042992
427 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
427 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
427 Proof of Concept
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
427 Proof of Concept
Release notes
Package name: react-hot-loader from react-hot-loader GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade react-hot-loader from 4.12.12 to 4.13.1.

See this package in npm:
react-hot-loader

See this project in Snyk:
https://app.snyk.io/org/snowcittysecuritysolutions/project/ae0aaacc-0440-45c7-9a19-163fcf13ee2d?utm_source=github&utm_medium=referral&page=upgrade-pr
@bolt-new-by-stackblitz
Copy link

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/[email protected] None 0 235 kB jordanbtucker
npm/[email protected] environment, eval Transitive: filesystem, network +3 600 kB kashey

🚮 Removed packages: npm/[email protected]), npm/[email protected]), npm/[email protected])

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment