[Snyk] Upgrade: react, react-dom, chalk, codemirror, deep-equal, dompurify, dugite, event-kit, focus-trap-react, fs-admin, fs-extra, keytar, marked, moment, mri, p-limit, primer-support, react-transition-group, react-virtualized, registry-js, source-map-support, textarea-caret, tslib, untildify, uuid, winston #29
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
react
from 16.8.4 to 16.14.0 | 13 versions ahead of your current version | 4 years ago
on 2020-10-14
react-dom
from 16.8.4 to 16.14.0 | 13 versions ahead of your current version | 4 years ago
on 2020-10-14
chalk
from 2.3.0 to 2.4.2 | 5 versions ahead of your current version | 6 years ago
on 2019-01-05
codemirror
from 5.60.0 to 5.65.17 | 29 versions ahead of your current version | 2 months ago
on 2024-07-20
deep-equal
from 1.0.1 to 1.1.2 | 3 versions ahead of your current version | 10 months ago
on 2023-11-09
dompurify
from 2.3.3 to 2.5.6 | 26 versions ahead of your current version | 2 months ago
on 2024-07-05
dugite
from 1.104.0 to 1.110.0 | 6 versions ahead of your current version | 2 years ago
on 2022-07-12
event-kit
from 2.4.0 to 2.5.3 | 4 versions ahead of your current version | 6 years ago
on 2018-11-14
focus-trap-react
from 8.1.0 to 8.11.3 | 24 versions ahead of your current version | 2 years ago
on 2022-06-09
fs-admin
from 0.19.0 to 0.20.0 | 1 version ahead of your current version | 3 years ago
on 2022-02-10
fs-extra
from 9.0.1 to 9.1.0 | 1 version ahead of your current version | 4 years ago
on 2021-01-19
keytar
from 7.7.0 to 7.9.0 | 2 versions ahead of your current version | 3 years ago
on 2022-02-17
marked
from 3.0.7 to 3.0.8 | 1 version ahead of your current version | 3 years ago
on 2021-10-24
moment
from 2.24.0 to 2.30.1 | 14 versions ahead of your current version | 9 months ago
on 2023-12-27
mri
from 1.1.0 to 1.2.0 | 7 versions ahead of your current version | 3 years ago
on 2021-09-12
p-limit
from 2.2.0 to 2.3.0 | 3 versions ahead of your current version | 4 years ago
on 2020-04-05
primer-support
from 4.3.0 to 4.7.2 | 482 versions ahead of your current version | 6 years ago
on 2019-01-11
react-transition-group
from 4.4.1 to 4.4.5 | 4 versions ahead of your current version | 2 years ago
on 2022-08-01
react-virtualized
from 9.20.0 to 9.22.5 | 10 versions ahead of your current version | a year ago
on 2023-04-17
registry-js
from 1.15.0 to 1.16.0 | 2 versions ahead of your current version | 7 months ago
on 2024-03-01
source-map-support
from 0.4.18 to 0.5.21 | 22 versions ahead of your current version | 3 years ago
on 2021-11-19
textarea-caret
from 3.0.2 to 3.1.0 | 1 version ahead of your current version | 7 years ago
on 2018-02-20
tslib
from 2.0.0 to 2.7.0 | 18 versions ahead of your current version | a month ago
on 2024-08-23
untildify
from 3.0.2 to 3.0.3 | 1 version ahead of your current version | 6 years ago
on 2018-05-19
uuid
from 3.1.0 to 3.4.0 | 6 versions ahead of your current version | 5 years ago
on 2020-01-16
winston
from 2.3.1 to 2.4.7 | 8 versions ahead of your current version | 2 years ago
on 2022-11-15
Issues fixed by the recommended upgrade:
SNYK-JS-DOMPURIFY-7984421
SNYK-JS-MOMENT-2440688
SNYK-JS-MOMENT-2944238
SNYK-JS-DOMPURIFY-6474511
SNYK-JS-NODEFETCH-2342118
SNYK-JS-NODEFETCH-674311
Release notes
Package name: react
-
16.14.0 - 2020-10-14
- Add support for the new JSX transform. (@ lunaruan in #18299)
-
16.13.1 - 2020-03-19
- Fix bug in legacy mode Suspense where effect clean-up functions are not fired. This only affects users who use Suspense for data fetching in legacy mode, which is not technically supported. (@ acdlite in #18238)
- Revert warning for cross-component updates that happen inside class render lifecycles (
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
-
16.13.0 - 2020-02-26
- Warn when a string ref is used in a manner that's not amenable to a future codemod (@ lunaruan in #17864)
- Deprecate
- Warn when changes in
- Warn when a function component is updated during another component's render phase (@ acdlite in #17099)
- Deprecate
- Fix
- Call
- Add
- Don't call
- Show component stacks in more warnings (@ gaearon in #17922, #17586)
- Warn for problematic usages of
- Remove
- Don't group Idle/Offscreen work with other work (@ sebmarkbage in #17456)
- Adjust
- Add missing event plugin priorities (@ trueadm in #17914)
- Fix
- Fix
- Don't warn when suspending at the wrong priority (@ gaearon in #17971)
- Fix a bug with rebasing updates (@ acdlite and @ sebmarkbage in #17560, #17510, #17483, #17480)
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
-
16.12.0 - 2019-11-14
- Fix passive effects (
- Fix
-
16.11.0 - 2019-10-22
-
16.10.2 - 2019-10-03
-
16.10.1 - 2019-09-28
-
16.10.0 - 2019-09-27
-
16.9.0 - 2019-08-08
-
16.9.0-rc.0 - 2019-08-05
-
16.9.0-alpha.0 - 2019-04-03
-
16.8.6 - 2019-03-28
-
16.8.5 - 2019-03-22
-
16.8.4 - 2019-03-05
from react GitHub release notesReact
React DOM
componentWillReceiveProps,shouldComponentUpdate, and so on). (@ gaearon in #18330)Artifacts
React
React.createFactory()(@ trueadm in #17878)React DOM
stylemay cause an unexpected collision (@ sophiebits in #14181, #18002)unstable_createPortal(@ trueadm in #17880)onMouseEnterbeing fired on disabled buttons (@ AlfredoGJ in #17675)shouldComponentUpdatetwice when developing inStrictMode(@ bvaughn in #17942)versionproperty to ReactDOM (@ ealush in #15780)toString()ofdangerouslySetInnerHTML(@ sebmarkbage in #17773)Concurrent Mode (Experimental)
ReactDOM.createRoot()(@ trueadm in #17937)ReactDOM.createRoot()callback params and added warnings on usage (@ bvaughn in #17916)SuspenseListCPU bound heuristic (@ sebmarkbage in #17455)isPendingonly being true when transitioning from inside an input event (@ acdlite in #17382)React.memocomponents dropping updates when interrupted by a higher priority update (@ acdlite in #18091)Artifacts
React DOM
useEffect) not being fired in a multi-root app. (@ acdlite in #17347)React Is
lazyandmemotypes considered elements instead of components (@ bvaughn in #17278)Artifacts
• react: https://unpkg.com/[email protected]/umd/
• react-art: https://unpkg.com/[email protected]/umd/
• react-dom: https://unpkg.com/[email protected]/umd/
• react-is: https://unpkg.com/[email protected]/umd/
• react-test-renderer: https://unpkg.com/[email protected]/umd/
• scheduler: https://unpkg.com/[email protected]/umd/
Package name: react-dom
-
16.14.0 - 2020-10-14
- Add support for the new JSX transform. (@ lunaruan in #18299)
-
16.13.1 - 2020-03-19
- Fix bug in legacy mode Suspense where effect clean-up functions are not fired. This only affects users who use Suspense for data fetching in legacy mode, which is not technically supported. (@ acdlite in #18238)
- Revert warning for cross-component updates that happen inside class render lifecycles (
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
-
16.13.0 - 2020-02-26
- Warn when a string ref is used in a manner that's not amenable to a future codemod (@ lunaruan in #17864)
- Deprecate
- Warn when changes in
- Warn when a function component is updated during another component's render phase (@ acdlite in #17099)
- Deprecate
- Fix
- Call
- Add
- Don't call
- Show component stacks in more warnings (@ gaearon in #17922, #17586)
- Warn for problematic usages of
- Remove
- Don't group Idle/Offscreen work with other work (@ sebmarkbage in #17456)
- Adjust
- Add missing event plugin priorities (@ trueadm in #17914)
- Fix
- Fix
- Don't warn when suspending at the wrong priority (@ gaearon in #17971)
- Fix a bug with rebasing updates (@ acdlite and @ sebmarkbage in #17560, #17510, #17483, #17480)
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
-
16.12.0 - 2019-11-14
- Fix passive effects (
- Fix
-
16.11.0 - 2019-10-22
-
16.10.2 - 2019-10-03
-
16.10.1 - 2019-09-28
-
16.10.0 - 2019-09-27
-
16.9.0 - 2019-08-08
-
16.9.0-rc.0 - 2019-08-05
-
16.9.0-alpha.0 - 2019-04-03
-
16.8.6 - 2019-03-28
-
16.8.5 - 2019-03-22
-
16.8.4 - 2019-03-05
from react-dom GitHub release notesReact
React DOM
componentWillReceiveProps,shouldComponentUpdate, and so on). (@ gaearon in #18330)Artifacts
React
React.createFactory()(@ trueadm in #17878)React DOM
stylemay cause an unexpected collision (@ sophiebits in #14181, #18002)unstable_createPortal(@ trueadm in #17880)onMouseEnterbeing fired on disabled buttons (@ AlfredoGJ in #17675)shouldComponentUpdatetwice when developing inStrictMode(@ bvaughn in #17942)versionproperty to ReactDOM (@ ealush in #15780)toString()ofdangerouslySetInnerHTML(@ sebmarkbage in #17773)Concurrent Mode (Experimental)
ReactDOM.createRoot()(@ trueadm in #17937)ReactDOM.createRoot()callback params and added warnings on usage (@ bvaughn in #17916)SuspenseListCPU bound heuristic (@ sebmarkbage in #17455)isPendingonly being true when transitioning from inside an input event (@ acdlite in #17382)React.memocomponents dropping updates when interrupted by a higher priority update (@ acdlite in #18091)Artifacts
React DOM
useEffect) not being fired in a multi-root app. (@ acdlite in #17347)React Is
lazyandmemotypes considered elements instead of components (@ bvaughn in #17278)Artifacts
• react: https://unpkg.com/[email protected]/umd/
• react-art: https://unpkg.com/[email protected]/umd/
• react-dom: https://unpkg.com/[email protected]/umd/
• react-is: https://unpkg.com/[email protected]/umd/
• react-test-renderer: https://unpkg.com/[email protected]/umd/
• scheduler: https://unpkg.com/[email protected]/umd/
Package name: chalk
-
2.4.2 - 2019-01-05
- Strict mode in Flow definition (#309) f95d9ec
-
2.4.1 - 2018-04-26
- Improved Flow type definition for CommonJS interop.
-
2.4.0 - 2018-04-17
- Added Flow type definitions. 7c6f83f
-
2.3.2 - 2018-03-02
- Fixed detection of color support for VSCode debug console. chalk/supports-color@b764af9
- Fixed detection of 24M colors in Konsole. chalk/supports-color@d6e08c8
- Fixed using
-
2.3.1 - 2018-02-11
- Calculate proper
- Detect 16m color support on Windows >=10.0.14931. chalk/supports-color@cf7bd05
-
2.3.0 - 2017-10-24
- Added a
- TypeScript type definitions improvements. 7be154c
from chalk GitHub release notesThis release is done from the
v2-releasebranch, asmasterbranch targets the work-in-progress v3 release.v2.4.0...v2.4.1
v2.3.2...v2.4.0
chalk.ansi256when in a terminal with 256-color level support. chalk/ansi-styles@1ac7472v2.3.1...v2.3.2
levelwhen forcing color. chalk/supports-color@b16e9a4v2.3.0...v2.3.1
.visible()method for emitting text only when Chalk is enabled. This can be useful for purely cosmetic content that shouldn't be shown when there are no colors, like when piping the output. dc092b4v2.2.0...v2.3.0
Package name: codemirror
-
5.65.17 - 2024-07-20
-
5.65.16 - 2023-11-20
-
5.65.15 - 2023-08-29
-
5.65.14 - 2023-07-17
-
5.65.13 - 2023-04-27
-
5.65.12 - 2023-02-20
-
5.65.11 - 2022-12-20
-
5.65.10 - 2022-11-20
-
5.65.9 - 2022-09-20
-
5.65.8 - 2022-08-20
-
5.65.7 - 2022-07-20
-
5.65.6 - 2022-06-20
-
5.65.5 - 2022-05-30
-
5.65.4 - 2022-05-20
-
5.65.3 - 2022-04-20
-
5.65.2 - 2022-02-21
-
5.65.1 - 2022-01-20
-
5.65.0 - 2021-12-20
-
5.64.0 - 2021-11-20
-
5.63.3 - 2021-10-12
-
5.63.2 - 2021-10-11
-
5.63.1 - 2021-09-29
-
5.63.0 - 2021-09-20
-
5.62.3 - 2021-08-20
-
5.62.2 - 2021-07-21
-
5.62.1 - 2021-07-20
-
5.62.0 - 2021-06-21
-
5.61.1 - 2021-05-20
-
5.61.0 - 2021-04-20
-
5.60.0 - 2021-03-20
from codemirror GitHub release notesPackage name: deep-equal
-
1.1.2 - 2023-11-09
-
1.1.1 - 2019-11-12
-
1.1.0 - 2019-08-28
-
1.0.1 - 2015-08-29
from deep-equal GitHub release notesv1.1.2
Package name: dompurify
-
2.5.6 - 2024-07-05
- Fixed an issue with the execution logic of attribute hooks to prevent bypasses, thanks @ kevin-mizu
- Fixed a minor problem with the bower file pointing to the wrong dist path
- Updated several development dependencies
-
2.5.5 - 2024-05-31
- Fixed a minor issue with the dist paths in
- Fixed a minor issue with sanitizing HTML coming from copy&paste Word content, thanks @ kakao-bishop-cho
-
2.5.4 - 2024-05-20
- Fixed a bug with latest
- Fixed the tests for MSIE and fixed related test-runner
-
2.5.3 - 2024-05-11
- Fixed several mXSS variations found by and thanks to @ kevin-mizu & @ Ry0taK
- Added better configurability for comment scrubbing default behavior
- Added better hardening against Prototype Pollution attacks, thanks @ kevin-mizu
- Fixed some smaller issues in README and other documentation
-
2.5.2 - 2024-04-30
- Addressed and fixed a mXSS variation found by @ kevin-mizu
- Addressed and fixed a mXSS variation found by Adam Kues of Assetnote
- Updated tests for older Safari and Chrome versions
-
2.5.1 - 2024-04-26
-
2.5.0 - 2024-04-07
-
2.4.9 - 2024-03-21
-
2.4.8 - 2024-03-19
-
2.4.7 - 2023-07-11
-
2.4.6 - 2023-07-10
-
2.4.5 - 2023-03-01
-
2.4.4 - 2023-02-13
-
2.4.3 - 2023-01-06
-
2.4.2 - 2023-01-05
-
2.4.1 - 2022-11-10
-
2.4.0 - 2022-08-24
-
2.3.12 - 2022-08-23
-
2.3.11 - 2022-08-23
-
2.3.10 - 2022-07-18
-
2.3.9 - 2022-07-11
-
2.3.8 - 2022-05-13
-
2.3.7 - 2022-05-11
-
2.3.6 - 2022-02-16
-
2.3.5 - 2022-01-26
-
2.3.4 - 2021-12-07
-
2.3.3 - 2021-09-20
from dompurify GitHub release notesbower.js, thanks @ HakumenNCisNaNchecks affecting MSIE, thanks @ tulachPackage name: dugite
-
1.110.0 - 2022-07-12
-
1.109.0 - 2022-04-20
-
1.108.0 - 2022-04-15
-
1.107.0 - 2022-04-13
-
1.106.0 - 2022-04-13
-
1.105.0 - 2022-04-12
-
1.104.0 - 2021-09-21
- Bumps dugite-native in order to get Git 2.32.0 and Git LFS 2.13.3 - #457
from dugite GitHub release notesUpdates Git to 2.35.4 and G4W to 2.35.4.windows.1.
Also updates the unsafe directory error as it changed with this update and adds error handling for path exists but not in the ref.
Updates Git LFS to 3.1.4
Bumps dugite-native in order to bump Git 2.35.2
This fixes several patterns for errors which have changed subtly in between 2.32 and 2.35 - #469
Bumps dugite-native in order to get Git 2.35.2 and Git LFS 3.1.2 - #468
Bumps dugite-native to 2.32.1 in order to bump git to 2.32.1 and g4w to 2.32.1.windows.1
Package name: event-kit
-
2.5.3 - 2018-11-14
-
2.5.2 - 2018-10-23
-
2.5.1 - 2018-09-14
-
2.5.0 - 2018-05-17
-
2.4.0 - 2017-09-12
from event-kit GitHub release notes2.5.3
2.5.2
2.5.1
2.4.0
Package name: focus-trap-react
-
8.11.3 - 2022-06-09
- 9947461: Bump focus-trap dependency to v6.9.4 to get typings fix.
- 519e5a5: Fix setReturnFocus option as function not being passed node focused prior to activation.
-
8.11.2 - 2022-05-25
- 7547d93: Bumps focus-trap to v6.9.3 to pick-up some small bug fixes from underlying tabbable.
-
8.11.1 - 2022-05-06
- 040813a: Bumps focus-trap to v6.9.1 to pick-up a fix to tabbable in v5.3.2 regarding the
-
8.11.0 - 2022-04-28
- 7495680: Bump focus-trap to v6.9.0 to get bug fixes and new features to help fix some bugs.
- 7495680: Fix onDeactivate, onPostDeactivate, and checkCanReturnFocus options not being called consistently on deactivation.
- 7495680: Fix focus not being allowed to remain on outside node post-deactivation when
-
8.10.0 - 2022-04-22
- 659d44e: Bumps focus-trap to v6.8.1. The big new feature is opt-in Shadow DOM support in focus-trap (in tabbable), and new tabbable options exposed in a new
-
8.9.2 - 2022-02-12
- 83e283c: Update focus-trap to v6.7.3 for bug fix related to elements with a negative
-
8.9.1 - 2022-01-12
- 3eb9421: Bump focus-trap to v6.7.2 for bug fix.
-
8.9.0 - 2021-12-11
- 83097a5: Delay trap creation until it should be active. This is a change in behavior, however it should not break existing behavior. The delay now allows you to set
- 16d1ae1: Fix bug where global document was being accessed instead of first checking for
-
8.8.2 - 2021-10-14
- 08a9449: Use
-
8.8.1 - 2021-09-27
- a2806a0: Fix SSR issues when accessing
-
8.8.0 - 2021-09-27
-
8.7.1 - 2021-08-14
-
8.7.0 - 2021-07-03
-
8.6.0 - 2021-06-19
-
8.5.1 - 2021-06-08
-
8.5.0 - 2021-04-21
-
8.4.2 - 2021-02-06
-
8.4.1 - 2021-01-19
-
8.4.0 - 2021-01-16
-
8.3.2 - 2020-12-02
-
8.3.1 - 2020-11-25
-
8.3.0 - 2020-11-18
-
8.2.0 - 2020-11-17
-
8.1.1 - 2020-10-31
-
8.1.0 - 2020-09-26
from focus-trap-react GitHub release notesPatch Changes
Patch Changes
Patch Changes
displayCheck=full(default) option behavior that caused issues with detached nodes.Minor Changes
Patch Changes
clickOutsideDeactivatesis true or returns true.Minor Changes
focusTrapOptions.tabbableOptionsconfiguration option.Patch Changes
tabindex.Patch Changes
Minor Changes
active=falseuntil you have thefocusTrapOptionsset correctly. #539Patch Changes
focusTrapOptions.documentoption. #539Patch Changes
preventScrolloption on deactivation if returning focus.Patch Changes
documentobject (#482)Package name: fs-admin
-
0.20.0 - 2022-02-10
-
0.19.0 - 2021-04-27
- Ported native module to N-API - #105
- Switch to N-API prebuilds - #106
- Bump
- Bump
from fs-admin GitHub release notesNo content.
Infrastructure
dependenciesupdatesprebuild-installfrom6.0.1to6.1.1devDependenciesupdatesnode-gypfrom7.1.2to8.0.0Package name: fs-extra
-
9.1.0 - 2021-01-19
-
9.0.1 - 2020-06-04
from fs-extra GitHub release notes9.1.0
9.0.1
Package name: keytar
-
7.9.0 - 2022-02-17
- Prebuild binaries for armv7l - #446, thanks @ nzapponi!
- Bump
-
7.8.0 - 2022-02-02
- Fix CI builds from latest macOS runners - #442
- Fix CI builds for Linux, by bumping to Ubuntu 20.04 runners - #442
- Guard against
- Bump
- Bump
- Bump
- Bump
- Bump
- Bump
-
7.7.0 - 2021-04-27
- Switch to N-API prebuilds - #331, thanks @ dennisameling!
from keytar GitHub release notesInfrastructure
devDependenciesupdatesprebuildfrom11.0.2to11.0.3Infrastructure
Fixed
NULLfilter finding credentials on Windows - #426, thanks @ sbatten!dependenciesupdatesprebuild-installfrom6.0.1to7.0.1node-addon-apifrom3.1.0to4.3.0lodashfrom4.17.19to4.17.21devDependenciesupdatesnode-gypfrom7.1.2to8.4.1chaifrom4.3.4to4.3.6mochafrom8.3.2to9.2.0Infrastructure
Package name: marked
-
3.0.8 - 2021-10-24
- walkTokens uses marked as this (#2251) (2da5885)
-
3.0.7 - 2021-10-07
- use named exports only for ESM build (#2226)
from marked GitHub release notes3.0.8 (2021-10-24)
Bug Fixes
3.0.7 (2021-10-07)
Bug Fixes
Package name: moment
2.30.1
2.30.0
2.29.4
2.29.3
2.29.2
2.29.1
2....