Rebolon / php-sf-flex-webpack-encore-vuejs

A simple app skeleton to try to make every components work together : symfony 5.* (latest stable at the date, but work with sf 4 and 3.3+ if you pull the right tag), symfony/flex, webpack-encore, vuejs 2.5.x, boostrap 4 sass
https://www.richard.icu/
MIT License
114 stars 31 forks source link

[Snyk] Security upgrade @api-platform/admin from 0.6.2 to 2.0.0 #212

Open Rebolon opened 1 year ago

Rebolon commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **556/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 5.4 | Cross-site Scripting (XSS)
[SNYK-JS-RAUIMATERIALUI-3319446](https://snyk.io/vuln/SNYK-JS-RAUIMATERIALUI-3319446) | Yes | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **556/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 5.4 | Cross-site Scripting (XSS)
[SNYK-JS-REACTADMIN-3319447](https://snyk.io/vuln/SNYK-JS-REACTADMIN-3319447) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @api-platform/admin The new version differs by 149 commits.
  • 59e2df5 v2.0.0
  • 1262fd2 Old version
  • ad5ea22 React-admin 3 (#263)
  • 66258a1 Update CONTRIBUTING.md (#261)
  • fcf6ac0 1.0.2
  • 3fc0d75 Merge pull request #253 from quentinus95/patch-1
  • f50ca44 apply prettier recommendations
  • df974d1 check for the value to be defined before checking the position of the prefix
  • 24534ef Merge pull request #251 from jfthuillier/guesser-logs
  • 856524f Merge pull request #252 from alanpoulain/fix-nested-array-filters
  • 3bed170 Add console logs in guessers to improve DX
  • 735cdbb Fix nested search filters and search filter for collection
  • dd2e39e Merge pull request #247 from silvia-odwyer/add_gif
  • d7b1e62 Added GIF to the README.
  • 0feae74 Merge pull request #240 from tienvx/allow-to-disable-filters
  • 8b121c1 Allow to disable filters
  • 8a77d87 Merge pull request #242 from sumitkharche/master
  • bc8e6c8 Removed License badge from README.md file
  • 65fb88e Merge pull request #239 from tienvx/pass-down-initial-props
  • f9e74c0 Merge pull request #231 from toofff/feat-remove-template-pull-request
  • 3924b80 Feat: remove template PR
  • 0f0b029 Pass down initial props
  • 7fc04c2 v1.0.1
  • 9289910 Merge pull request #237 from tienvx/inject-api-document-parser
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/rebolon/project/16f76dab-7d62-4ad8-aefb-07836ed264c9?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/rebolon/project/16f76dab-7d62-4ad8-aefb-07836ed264c9?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"6f1b6c11-d655-47c9-9728-cefd329ac107","prPublicId":"6f1b6c11-d655-47c9-9728-cefd329ac107","dependencies":[{"name":"@api-platform/admin","from":"0.6.2","to":"2.0.0"}],"packageManager":"npm","projectPublicId":"16f76dab-7d62-4ad8-aefb-07836ed264c9","projectUrl":"https://app.snyk.io/org/rebolon/project/16f76dab-7d62-4ad8-aefb-07836ed264c9?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-RAUIMATERIALUI-3319446","SNYK-JS-REACTADMIN-3319447"],"upgrade":["SNYK-JS-RAUIMATERIALUI-3319446","SNYK-JS-REACTADMIN-3319447"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[556,556]}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Cross-site Scripting (XSS)](https://learn.snyk.io/lessons/dom-based-xss/javascript/?loc=fix-pr) 🦉 [Cross-site Scripting (XSS)](https://learn.snyk.io/lessons/dom-based-xss/javascript/?loc=fix-pr)