BlueBaseJS / plugin-material-ui

😎 Material UI (web) comes to BlueBase!
https://bluebasejs.github.io/plugin-material-ui/
Apache License 2.0
0 stars 0 forks source link

build(deps): [security] bump markdown-to-jsx from 6.11.0 to 6.11.4 #342

Open dependabot-preview[bot] opened 3 years ago

dependabot-preview[bot] commented 3 years ago

Bumps markdown-to-jsx from 6.11.0 to 6.11.4. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

Cross-Site Scripting in markdown-to-jsx Versions of markdown-to-jsx prior to 6.11.4 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization the package may render output containing malicious JavaScript. This vulnerability can be exploited through input of links containing data or VBScript URIs and a base64-encoded payload.

Recommendation

Upgrade to version 6.11.4 or later.

Affected versions: < 6.11.4

Release notes

Sourced from markdown-to-jsx's releases.

6.11.4: Mitigates security vulnerability where maliciously crafted markdown links could use data: or vbscript: urls to trigger an xss injection ( #306 / https://www.npmjs.com/advisories/1219 ), even when using options.disableParsingRawHTML

Note that currently, the default options.disableParsingRawHTML = false should still only be used for trusted input, as arbitrary html, including script tags.

6.11.3 has no changes (I held the publish script upside down; the only change from 6.11.2 is the version number 😅)

6.11.2

[FIX] - Footnote references (#304) thanks @csantos1113

6.11.1

Fix: Support empty style attribute (#296) thanks @cribbles

Commits
Maintainer changes

This version was pushed to npm by ariabuckles, a new releaser for markdown-to-jsx since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired)
codecov[bot] commented 3 years ago

Codecov Report

:exclamation: No coverage uploaded for pull request base (master@ba6918f). Click here to learn what that means. The diff coverage is n/a.

Impacted file tree graph

@@            Coverage Diff            @@
##             master     #342   +/-   ##
=========================================
  Coverage          ?   98.85%           
=========================================
  Files             ?       92           
  Lines             ?      700           
  Branches          ?       97           
=========================================
  Hits              ?      692           
  Misses            ?        6           
  Partials          ?        2           
Impacted Files Coverage Δ
src/components/Avatar/index.ts 100.00% <0.00%> (ø)
src/components/IconButton/IconButton.tsx 100.00% <0.00%> (ø)
src/components/Menu/MenuItem.tsx 100.00% <0.00%> (ø)
src/components/DrawerSection/DrawerSection.tsx 100.00% <0.00%> (ø)
src/components/ListIcon/index.ts 100.00% <0.00%> (ø)
src/components/DrawerSection/index.ts 100.00% <0.00%> (ø)
src/components/TableFooter/index.tsx 100.00% <0.00%> (ø)
src/components/Picker/Picker.tsx 94.28% <0.00%> (ø)
src/components/ListAvatar/ListAvatar.tsx 80.00% <0.00%> (ø)
src/withRtl.tsx 100.00% <0.00%> (ø)
... and 82 more

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update ba6918f...3a20fe0. Read the comment docs.