Mugetsu15 / corona

Corona incidence viewer
https://corona.maxuniverse.de
Apache License 2.0
1 stars 0 forks source link

[Snyk] Upgrade @vue/cli-plugin-babel from 4.5.11 to 4.5.13 #18

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade @vue/cli-plugin-babel from 4.5.11 to 4.5.13.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1246392
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1085630
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1246392
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1085630
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Remote Memory Exposure
SNYK-JS-DNSPACKET-1293563
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1090595
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1243891
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1085627
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @vue/cli-plugin-babel
  • 4.5.13 - 2021-05-08

    šŸ› Bug Fix

    • @ vue/babel-preset-app
      • #6459 fix: fix modern mode optional chaining syntax tranpilation (@ sodatea)
    • @ vue/cli-plugin-unit-mocha
    • @ vue/cli-service

    Others

    • #6300 chore: remove the word "Preview" from vue 3 preset (@ sodatea)

    Committers: 3

  • 4.5.12 - 2021-03-17
    • bump vue-codemod to work around an NPM hoisting bug
    • bump minimum required JSX preset / plugin versions, fixes vuejs/jsx#183
    • bump default typescript version to 4.1 and prettier version to 2.x for new projects, fixes #6299
  • 4.5.11 - 2021-01-22

    šŸ› Bug Fix

    Committers: 1

from @vue/cli-plugin-babel GitHub release notes
Commit messages
Package name: @vue/cli-plugin-babel
  • 6e0d846 v4.5.13
  • 9a125a2 fix(v4): fix modern mode optional chaining syntax tranpilation (#6459)
  • b39726e fix(mocha): workaround the SVGElement issue in Vue (#6400)
  • d41fb55 chore: remove the word "Preview" from vue 3 preset (#6310)
  • 5a135f6 chore: remove the word "Preview" from vue 3 preset (#6300)
  • 0e0ae95 fix(v4): get rid of ssri vulnerability warnings (#6455)
  • b0de229 v4.5.12
  • 87c35a0 feat: bump default prettier version to 2.x
  • fae7ee8 fix: revert to ts 4.2.3 to fix failing ci tests
  • 106c323 feat: use TS 4.2+ in newly created projects
  • 9ea68a8 chore: bump minimum required jsx preset / plugin versions
  • 82ab316 chore: bump vue-codemod to work around a npm hoisting bug
  • bef2375 chore: vue-cli-plugin-apollo can be listed as a dev dep
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

šŸ§ View latest project report

šŸ›  Adjust upgrade PR settings

šŸ”• Ignore this dependency or unsubscribe from future upgrade PRs