JaredReisinger / react-crossword

A flexible, responsive, and easy-to-use crossword component for React apps.
https://react-crossword.jaredreisinger.com
MIT License
171 stars 84 forks source link

[Snyk] Security upgrade gh-pages from 4.0.0 to 5.0.0 #496

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-GHPAGES-3042993
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gh-pages The new version differs by 19 commits.
  • f729b97 5.0.0
  • 51534c7 Log changes
  • ace063b Merge pull request #438 from Vicropht/patch-1
  • 58e54be Merge pull request #459 from tschaub/dependabot/npm_and_yarn/async-3.2.4
  • 2189df3 Bump async from 2.6.4 to 3.2.4
  • 051846e Merge pull request #454 from tschaub/dependabot/npm_and_yarn/email-addresses-5.0.0
  • 5c91c67 Merge pull request #455 from tschaub/dependabot/github_actions/actions/setup-node-3
  • fe0ad83 Merge pull request #453 from tschaub/dependabot/github_actions/actions/checkout-3
  • b89287d Merge pull request #445 from Nezteb/patch-1
  • e890bd1 Bump email-addresses from 3.0.1 to 5.0.0
  • f041e67 Bump actions/setup-node from 1 to 3
  • ca63d1d Bump actions/checkout from 2 to 3
  • f323e23 Merge pull request #452 from tschaub/updates
  • bdc342b Stop testing on 12, start testing on 18
  • 90ee644 Dependabot config
  • e1374b3 Update dependencies and always return a promise
  • fc04b25 Use set for unique dirs
  • 2ebfb74 Update docs to clarify project site configuration
  • a634d5e Remove quotation marks
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution