ChocPanda / cat-pun

MIT License
0 stars 1 forks source link

[Snyk] Security upgrade buefy from 0.7.10 to 0.9.0 #56

Closed snyk-bot closed 3 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 521/1000
Why? Recently disclosed, Has a fix available, CVSS 4.7
Cross-site Scripting (XSS)
SNYK-JS-BUEFY-598386
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: buefy The new version differs by 250 commits.
  • 17d2005 0.9.0
  • 1da3dcf Fix build scss
  • e2f6c7c Fix datepicker test
  • e8b8774 Update docs
  • 349189b Update default value
  • e659cec Vue 2.6+ is min version
  • e81ad61 Deprecate .sync (except of table)
  • 41679e9 Breaking: rename is-active prop to navbar
  • 6ac5191 Update changelog
  • d2ab09a Restore #2596
  • 2158540 Update changelog (part 2)
  • fc27891 0.9.0 Changelog (#2745)
  • 0bbad82 Add dialog promise example
  • a9b0a3a Add trigger example to datepicker docs
  • 91fbe52 Add link to 0.8 and 0.9 Bulma versions
  • 00a84ce Init Changelog...
  • bdd971b Close #2479 add check-all wher table cards
  • 87dc958 Merge branch 'dev' of https://github.com/rafaelpimpa/buefy into dev
  • f170b08 Fix #2732 upload when same file
  • 1dfd792 Fixed path Bulma css-var (#2742)
  • 47d2250 Fix xss on programmatic components
  • d1c41c7 Fix typo doc update (#2743)
  • 1f98af2 Fix rounded buttons on number input
  • 3d2ae3e Fix icon examples
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic