OWASP / crAPI

completely ridiculous API (crAPI)
Apache License 2.0
1.13k stars 347 forks source link

[Snyk] Upgrade prop-types from 15.7.2 to 15.8.1 #143

Closed snyk-bot closed 1 year ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade prop-types from 15.7.2 to 15.8.1.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Improper Input Validation
SNYK-JS-URLPARSE-2407770
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Arbitrary Code Injection
SNYK-JS-SERIALIZEJAVASCRIPT-570062
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Prototype Pollution
SNYK-JS-OBJECTPATH-1585658
512/1000
Why? Proof of Concept exploit, CVSS 8.1
No Known Exploit
Prototype Pollution
SNYK-JS-OBJECTPATH-1017036
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Prototype Pollution
SNYK-JS-NODEFORGE-598677
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Remote Memory Exposure
SNYK-JS-DNSPACKET-1293563
512/1000
Why? Proof of Concept exploit, CVSS 8.1
No Known Exploit
Prototype Pollution
SNYK-JS-ASYNC-2441827
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Prototype Pollution
SNYK-JS-YARGSPARSER-560381
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Authorization Bypass Through User-Controlled Key
SNYK-JS-URLPARSE-2412697
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Authorization Bypass
SNYK-JS-URLPARSE-2407759
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Access Restriction Bypass
SNYK-JS-URLPARSE-2401205
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Open Redirect
SNYK-JS-URLPARSE-1533425
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Improper Input Validation
SNYK-JS-URLPARSE-1078283
512/1000
Why? Proof of Concept exploit, CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JS-SOCKJS-575261
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Prototype Pollution
SNYK-JS-OBJECTPATH-1569453
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2332181
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Information Exposure
SNYK-JS-EVENTSOURCE-2823375
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-2396346
512/1000
Why? Proof of Concept exploit, CVSS 8.1
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: prop-types
  • 15.8.1 - 2022-01-05
    • [Fix] fix crash when a custom propType return lacks .data; call hasOwnProperty properly (#370)
    • [meta] Fix formatting in CHANGELOG.md (#367)
    • [Tests] add missing test coverage (#370)
    • [Tests] convert normal it functions to arrow functions (#370)
    • [Tests] do not fail fast; add react 17 (#366)
    • [Dev Deps] update eslint
  • 15.8.0 - 2021-12-22
    • [New] add PropTypes.bigint (#365)
    • [New] oneOfType: Add expected types to warning (#198)
    • [New] Add type check for validator for 'shape' and 'exact' (#234)
    • [Fix] checkPropTypes: Friendlier message when using a type checker that is not a function (#51)
    • [Refactor] extract has (#261, #125, #124)
    • [readme] Fix branch name (master -> main) (#364)
    • [readme] Clarify usage of elementType (#335)
    • [docs] highlighted the func name (#321)
    • [docs] Typo fix in example (#300)
    • [docs] Add instructions for intentional inclusion of validation in production. (#262)
    • [docs] PropTypes.node: add link to react docs
    • [docs] Improve wording for checkPropTypes (#258)
    • [meta] Add a package sideEffects field. (#350)
    • [meta] use in-publish to avoid running the build on install
    • [deps] regenerate yarn.lock
    • [deps] update react-is (#347, #346, #345, #340, #338)
    • [eslint] enable some rules (#360)
    • [Tests] Use GH Actions (#363)
    • [Tests] Fix spelling (#318)
    • [Tests] Fixed typo: 'Any type should accept any value' (#281)
    • [Tests] fix broken tests; test the build process
    • [Dev Deps] update browserify, bundle-collapser, eslint, in-publish, react, uglifyify, uglifyjs
  • 15.7.2 - 2019-02-13

    v15.7.2

from prop-types GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs