Skip to content

Conversation

@snyk-bot
Copy link

Snyk have raised this PR to upgrade react-scripts from 1.1.4 to 1.1.5.

  • The recommended version is 3 versions ahead of your current version.
  • The recommended version was released a year ago, on 2018-08-22.

The recommended version fixes:

Severity Title Issue ID
Prototype Pollution SNYK-JS-MIXINDEEP-450212
Prototype Pollution SNYK-JS-HANDLEBARS-173692
Prototype Pollution SNYK-JS-LODASH-450202
Prototype Pollution SNYK-JS-LODASH-73638
Prototype Pollution SNYK-JS-HANDLEBARS-174183
Arbitrary File Overwrite SNYK-JS-TAR-174125
Prototype Pollution npm:extend:20180424
Arbitrary Code Execution SNYK-JS-REACTDEVUTILS-72875
Prototype Pollution SNYK-JS-SETVALUE-450213
Prototype Pollution SNYK-JS-SETVALUE-450213
Open Redirect npm:url-parse:20180731
Time of Check Time of Use (TOCTOU) npm:chownr:20180731
Regular Expression Denial of Service (ReDoS) SNYK-JS-LODASH-73639
Prototype Pollution SNYK-JS-MERGE-72553
Release notes

from react-scripts GitHub Release Notes


🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants