EmpathyTechnologies / CareerPlanToday-Frontend

3 stars 0 forks source link

[Snyk] Security upgrade @aws-amplify/ui-react from 5.0.7 to 6.0.5 #350

Open SomdattaPatra opened 8 months ago

SomdattaPatra commented 8 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json
⚠️ Warning ``` Failed to update the package-lock.json, please update manually before merging. ```
#### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **703/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.2 | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @aws-amplify/ui-react The new version differs by 250 commits.
  • 18cf2ee Version Packages (#4817)
  • 83ce160 chore(docs): bump glob version used in docs (#4816)
  • cc2740b fix(auth): fix refreshing page not hydrating custom formfields/services into the auth machine (#4823)
  • b254ec4 Update Android Liveness Version (#4826)
  • 477ee82 bumping style-dictionary (#4827)
  • 77cd45d chore: fix liveness pointing to aws-amplify v5 (#4820)
  • c526cf5 fix(liveness): add a11y tags to match indicator bar (#4802)
  • f370555 Version Packages (#4787)
  • afa9286 update changelog (#4812)
  • f549efc chore(docs): add a updated liveness error modal example (#4790)
  • 272a05e chore: update focus ring indicators (#4807)
  • fe68b66 fix: pass displayText through to LivenessCameraModule (#4792)
  • 04dc191 chore: add i18n for a11y video text (#4809)
  • 1327db0 chore: update liveness custom cdn to include older versions (#4806)
  • 6860190 chore: added aria label for video element on liveness (#4808)
  • ed55a6a fix(authenticator): exclude empty phone_number values from sign up submit (#4801)
  • cb7025e chore: add @ adobe/css-tools resolution (#4798)
  • 9d342b2 chore: decrease connected component size limits (#4796)
  • b390ae6 chore(e2e): ignore external links in link checker (#4791)
  • be0c8b2 chore: allow liveness cdn (#4793)
  • 91ffe63 fix: liveness fix customizing photosensitivity warning (#4770)
  • 587fa47 Version Packages (#4784)
  • 33256ee chore(liveness): update hold still text to show when matched (#4780)
  • d026557 Version Packages (#4768)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/markamiller90-tgi/project/7f83c33a-4b24-4b32-9949-70733e35ad2c?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/markamiller90-tgi/project/7f83c33a-4b24-4b32-9949-70733e35ad2c?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"4c6a2013-54cd-416b-8972-f8dc4f58bf4c","prPublicId":"4c6a2013-54cd-416b-8972-f8dc4f58bf4c","dependencies":[{"name":"@aws-amplify/ui-react","from":"5.0.7","to":"6.0.5"}],"packageManager":"npm","projectPublicId":"7f83c33a-4b24-4b32-9949-70733e35ad2c","projectUrl":"https://app.snyk.io/org/markamiller90-tgi/project/7f83c33a-4b24-4b32-9949-70733e35ad2c?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-INFLIGHT-6095116"],"upgrade":["SNYK-JS-INFLIGHT-6095116"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","pr-warning-shown","priorityScore"],"priorityScoreList":[703],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)