ExtensionEngine / tailor

Content authoring platform
MIT License
31 stars 10 forks source link

[Snyk] Security upgrade vuetify from 2.6.9 to 2.6.10 #1017

Closed snyk-bot closed 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 623/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 4.6
Cross-site Scripting (XSS)
SNYK-JS-VUETIFY-3019858
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: vuetify The new version differs by 18 commits.
  • fdfb6fc chore(release): publish v2.6.10
  • cd193e4 fix(VSelectList): correct mask class
  • f50a808 chore: update commit message template
  • 89e3850 fix(VDialog): don't try to focus tabindex="-1" or hidden inputs
  • 4468e3c refactor(VSelect): render highlight with vnodes instead of innerHTML
  • ade1434 fix(VCalendar): prevent XSS from eventName function
  • 1be5260 docs(SystemBar): add new promotion
  • 69eefd9 chore(ci): set percy base branch
  • ac45c98 fix(web-types): add support for VDataTable pattern slots (#15694)
  • 464529a fix(VMenu): disabled activatorFixed when attach is enabled (#15709)
  • 381fdb5 docs: use "id" in item-value of autocomplete example (#15740)
  • a455163 chore: update commit message template
  • c8dbfa5 chore(ci): run percy tests on next with nightly build
  • 0c90436 docs(i18n): remove the additional Arabic word for "language" (#15662)
  • 3680756 docs(support.md): implement kintell booking
  • 25a3474 docs(text-fields): clarify that readonly does not affect clearable
  • 7a51ad0 fix(VTextField): only show clear icon on hover or when focused
  • f8ee680 fix(VTextField): prevent tabbing to clear button
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

droguljic commented 1 year ago

Resolved as a part of #1076