ChocPanda / cat-pun

MIT License
0 stars 1 forks source link

[Snyk] Security upgrade buefy from 0.7.10 to 0.8.18 #54

Closed snyk-bot closed 3 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

✨What is Merge Advice? We check thousands of dependency upgrade pull requests and CI tests every day to see which upgrades were successfully merged. After crunching this data, we give a recommendation on how safe we think the change is for you to merge without causing issues. Learn more, and share your feedback to help improve this feature. 🙏

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Cross-site Scripting (XSS)
SNYK-JS-BUEFY-567814
No No Known Exploit
Commit messages
Package name: buefy The new version differs by 250 commits.
  • 451b382 0.8.18
  • 68acce2 Update package.json
  • bcc3111 #1872 add static class when append-to-body
  • 1cfaf32 Update vetur
  • 8294b67 Update docs
  • b301ddb Close #2495 add defaultTabsAnimatedd constructor options
  • 9f0e2da Feature: add close-type prop to tag component (#2492)
  • 7b18d14 Fix #2493 clean hovered on select
  • 4dfc611 Fix listen props change on carousel list
  • 35ad2d5 Update changelog and docs
  • 08a1510 Add bulma variables external link
  • a9eeb87 Fix #2485 datepicker and timepicker shadow when not editable
  • 941eb20 Close #2487 add native event as parameter to select event
  • 5b494ba Merge branch 'dev' of https://github.com/rafaelpimpa/buefy into dev
  • 4419cbf Fix #2489 dropdown item padding on mobile when has-link
  • eeccd2d Add expand-on-hover-fixed prop to sidebar
  • edbf594 Autocomplete typo (#2482)
  • 63d0a7b shallow copy in watcher (#2481)
  • 56812ac Remove 'recommended' from Full Bundle (#2480)
  • 044c478 Remove data attribute
  • c5c6614 Close #2462 init sort when mulitple
  • 0263ceb Fix #2469 mantain sort during search
  • 066b9f8 Close #2474 add icon-click event to autcomplete
  • 7d139db Fix unit tests
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic