MethSarcus / visualeague

Webapp for fantasy football league stats
https://www.visualeague.com
4 stars 5 forks source link

[Snyk] Upgrade immer from 10.0.3 to 10.1.1 #396

Open MethSarcus opened 1 month ago

MethSarcus commented 1 month ago

snyk-top-banner

Snyk has created this PR to upgrade immer from 10.0.3 to 10.1.1.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Acceptance of Extraneous Untrusted Data With Trusted Data
SNYK-JS-NEXT-8025427
649 No Known Exploit
Release notes
Package name: immer
  • 10.1.1 - 2024-04-27

    10.1.1 (2024-04-27)

    Bug Fixes

  • 10.1.0 - 2024-04-27

    10.1.0 (2024-04-27)

    Features

    • performance: Make non-strict mode faster for classes. Addresses #1071 (53e3203). Immer 10.x solved slow iteration for plain JS objects. This update applies the same handling to class instances. In cases this makes class instance handling 3 times faster. Note that this slightly modifies the behavior of Immer with classes in obscure corner cases, in ways that match current documentation, but do not match previous behavior. If you run into issues with this release icmw. class instances, use setUseStrictShallowCopy("class_only") to revert to the old behavior. For more details see https://immerjs.github.io/immer/complex-objects#semantics-in-detail
  • 10.0.4 - 2024-03-09

    10.0.4 (2024-03-09)

    Bug Fixes

  • 10.0.4-beta - 2024-03-11
  • 10.0.3 - 2023-10-02

    10.0.3 (2023-10-02)

    Bug Fixes

from immer GitHub release notes

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

vercel[bot] commented 1 month ago

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
visualeague ✅ Ready (Inspect) Visit Preview 💬 Add feedback Oct 25, 2024 4:51am