Samsung / qaboard

Experiment tracker: organize, visualize, compare and share runs. Removes toil from algorithm/performance R&D and tuning.
https://samsung.github.io/qaboard
Apache License 2.0
53 stars 14 forks source link

[Snyk] Security upgrade sanitize-html from 2.6.1 to 2.12.1 #88

Open arthur-flam opened 6 months ago

arthur-flam commented 6 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - webapp/package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **658/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 | Information Exposure
[SNYK-JS-SANITIZEHTML-6256334](https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-6256334) | No | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: sanitize-html The new version differs by 102 commits.
  • 4a7d7dd Merge pull request #654 from apostrophecms/release-2.12.1
  • f8e02be release 2.12.1
  • c5dbdf7 Merge pull request #650 from dylanarmstrong/fix/ignore-source-maps
  • 5a5a74e Merge pull request #652 from apostrophecms/add-thanks-to-changelog
  • ee71ff0 Add community contribution thanks you
  • a226fe7 Merge pull request #651 from apostrophecms/release-2.12.0
  • ff18600 release 2.12.0
  • 1e2294c test: added test for postcss map
  • c376501 doc: update changelog
  • 075499d fix: ignore source maps when processing with postcss
  • eb932f8 Merge pull request #646 from gkumar9891/allow-svg-element
  • 31def35 changes to documentation
  • b268d15 changes in documentation
  • 54a6ac2 allow svg element
  • c52a9f0 Merge pull request #634 from zhna123/empty-alt
  • 2c7ac45 Added more tests and modified CHANGELOG
  • 4f6cea6 Added 'allowedEmptyAttributes' option and kept empty 'alt' value by default.
  • cb6efe1 Merge pull request #628 from alfreema/patch-1
  • 9856e7b Delete .circleci directory
  • 1bde207 Update README.md - Remove circleci reference
  • b3400f2 Update README.md
  • c4491ea Merge pull request #625 from apostrophecms/2.11.0
  • 7bd3e3f release 2.11.0
  • 6c0e5fe thank you
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/arthur-flam/project/b10f75f2-5e5b-4368-bba3-16093e2720c7?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/arthur-flam/project/b10f75f2-5e5b-4368-bba3-16093e2720c7?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"d048fc98-1d4b-4afe-9470-434f613125a8","prPublicId":"d048fc98-1d4b-4afe-9470-434f613125a8","dependencies":[{"name":"sanitize-html","from":"2.6.1","to":"2.12.1"}],"packageManager":"npm","projectPublicId":"b10f75f2-5e5b-4368-bba3-16093e2720c7","projectUrl":"https://app.snyk.io/org/arthur-flam/project/b10f75f2-5e5b-4368-bba3-16093e2720c7?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-SANITIZEHTML-6256334"],"upgrade":["SNYK-JS-SANITIZEHTML-6256334"],"isBreakingChange":false,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[658],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)