LabZoneSK / labzone-gatsby

BSD Zero Clause License
2 stars 0 forks source link

[Snyk] Upgrade @sentry/gatsby from 6.19.6 to 6.19.7 #145

Closed snyk-bot closed 1 year ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade @sentry/gatsby from 6.19.6 to 6.19.7.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Remote Code Execution (RCE)
SNYK-JS-SHELLQUOTE-1766506
619/1000
Why? Has a fix available, CVSS 8.1
No Known Exploit
Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
619/1000
Why? Has a fix available, CVSS 8.1
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
619/1000
Why? Has a fix available, CVSS 8.1
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-DEVCERT-2808183
619/1000
Why? Has a fix available, CVSS 8.1
No Known Exploit
Undesired Behavior
SNYK-JS-EVENTSOURCEPOLYFILL-2429580
619/1000
Why? Has a fix available, CVSS 8.1
Mature
Prototype Pollution
SNYK-JS-IMMER-1540542
619/1000
Why? Has a fix available, CVSS 8.1
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
619/1000
Why? Has a fix available, CVSS 8.1
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @sentry/gatsby
  • 6.19.7 - 2022-04-26
    • fix(react): Add children prop type to ErrorBoundary component (#4966)
    • fix(serverless): Re-add missing modules in Node AWS Lambda Layer (#4982)
    • fix(tracing): Target tracing bundles for side effects (#4955)

    Work in this release contributed by @ cameronaziz and @ kpdecker. Thank you for your contributions!

  • 6.19.6 - 2022-04-07
    • fix(typing): Fix typing API in CaptureConsle (#4879)
from @sentry/gatsby GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs