ChurchCRM / CRM

ChurchCRM is an OpenSource Church CRM & Management Software.
https://ChurchCRM.io
MIT License
626 stars 444 forks source link

[Snyk] Upgrade react-datepicker from 7.3.0 to 7.4.0 #7184

Closed DawoudIO closed 1 week ago

DawoudIO commented 1 week ago

Snyk has created this PR to upgrade react-datepicker from 7.3.0 to 7.4.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Cross-site Scripting (XSS)
SNYK-JS-SUMMERNOTE-568471
226/1000
Why? CVSS 4.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: react-datepicker from react-datepicker GitHub release notes
Commit messages
Package name: react-datepicker
  • 5454eb6 Publish new API docs (automated commit)
  • ac5f224 7.4.0
  • 6903813 Merge pull request #5093 from Hacker0x01/dependabot/npm_and_yarn/lint-staged-15.2.10
  • 1a24832 Merge pull request #5094 from Hacker0x01/dependabot/npm_and_yarn/typescript-eslint/parser-8.6.0
  • becab92 Merge pull request #5095 from Hacker0x01/dependabot/npm_and_yarn/types/jest-29.5.13
  • 8619218 Merge pull request #5098 from Hacker0x01/dependabot/npm_and_yarn/docs-site/sass-1.79.1
  • 3e28fca Merge pull request #5100 from Qubitza/main
  • 342d370 fix: improved code readability
  • 017183d test: shows custom time caption
  • 2771fe4 test: hides time caption
  • aea8f6d feat: hide time caption
  • 3a8d7e4 chore(deps-dev): bump sass from 1.78.0 to 1.79.1 in /docs-site
  • c874de2 chore(deps-dev): bump @ types/jest from 29.5.12 to 29.5.13
  • c0b68ca chore(deps-dev): bump @ typescript-eslint/parser from 7.18.0 to 8.6.0
  • a5240d2 chore(deps-dev): bump lint-staged from 15.2.9 to 15.2.10
  • f75e1e6 Merge pull request #5089 from Hacker0x01/dependabot/npm_and_yarn/examples/hello-world/express-4.21.0
  • 50ceb5d Merge pull request #5090 from Hacker0x01/dependabot/npm_and_yarn/docs-site/express-4.21.0
  • e85adf3 Merge pull request #5092 from qburst/issue-4949/fix/placeholder-typo
  • 81ab24d ✏️ Fix the time input's placeholder typo
  • 18be5fa chore(deps): bump express from 4.19.2 to 4.21.0 in /docs-site
  • 5c5a7e0 chore(deps): bump express from 4.19.2 to 4.21.0 in /examples/hello-world
  • d080ec3 Merge pull request #5082 from Hacker0x01/dependabot/npm_and_yarn/sass-1.78.0
  • 553cdca Merge pull request #5086 from Hacker0x01/dependabot/npm_and_yarn/rollup-4.21.3
  • c0b68b1 Merge pull request #5087 from Hacker0x01/dependabot/npm_and_yarn/eslint-plugin-react-7.36.1
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

πŸ›  Adjust upgrade PR settings

πŸ”• Ignore this dependency or unsubscribe from future upgrade PRs