18F / fedramp-dashboard

https://marketplace.fedramp.gov
Creative Commons Zero v1.0 Universal
21 stars 19 forks source link

[Snyk] Security upgrade uswds from 2.10.0 to 2.12.2 #146

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-USWDS-1656800
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: uswds The new version differs by 250 commits.
  • b913720 Merge pull request #4377 from uswds/release-2.12.2
  • 3dcf9f9 Create uswds-2.12.2-zip-hash.txt
  • 8d6b61f 2.12.2
  • b20a82e npm audit fix
  • 1d5789b Merge pull request #4376 from uswds/dw-update-references
  • 45c905c Update references to 2.12.2
  • 679369d Merge pull request #4375 from uswds/dw-update-notifications
  • 4e34998 Add notification about tooltip content
  • 2d24b92 Merge pull request #4373 from uswds/jm-update-deps
  • 3464df5 Update peer dependencies.
  • ef2d2fb Merge pull request #4313 from mahoneycm/cm-file-upload-test
  • fa8939b Merge branch 'develop' into cm-file-upload-test
  • 2c832b3 Merge pull request #4342 from aduth/aduth-rm-input-inline
  • 36b25d6 Merge pull request #4329 from uswds/gsq-xss-audit
  • 2d5b4b3 Merge pull request #4345 from fpigeonjr/patch-2
  • 9da0b06 Merge pull request #4349 from aduth/aduth-del-dev-dependency
  • 187c74c typo
  • ff30ee4 Merge branch 'develop' of github.com:uswds/uswds into gsq-xss-audit
  • 2065553 Move del to devDependencies
  • 37bce34 Merge branch 'gsq-xss-audit' of github.com:uswds/uswds into gsq-xss-audit
  • 07f9573 confirms aria-label returns as string
  • 03b45af updates MEDCoE sites
  • 3e6828f Run prettier on component js.
  • 2e19f8e Run prettier on unit tests.
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic