SuperMap / vue-iclient

SuperMap iClient UI Components for Vue.js
https://iclient.supermap.io/web/apis/vue/
Apache License 2.0
193 stars 56 forks source link

[Snyk] Security upgrade ant-design-vue from 1.7.2 to 3.1.0 #33

Closed snyk-bot closed 1 year ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ASYNCVALIDATOR-2311201
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: ant-design-vue The new version differs by 250 commits.
  • 6d14732 release 3.1.0
  • 6222e43 release 3.1.0
  • 272430b fix: selectoption empty error
  • 3274896 release 3.1.0-rc.6
  • a154ecd fix: mentions cannot select, close #5432
  • fa76f5c fix: blur & focus lose argumnet, close #5434
  • 0d06ce2 feat: Modify the warning in the conductutil file for attention (#5424)
  • a298b00 fix: sticky scrollbar show when init
  • 9004644 perf: table hover & stickyScroll
  • 797a1c6 doc: update next to main
  • ec17787 fix: select option tootip error, close #5307
  • 669b22a fix: tabs auto overflow error for addIcon
  • 80342f4 release 3.0.0-rc.5
  • afd74c9 fix: table sticky scroll bar not reactive
  • 8e37ffb doc: update demo
  • def6a72 fix: form scrollToField not work form nest field, close #5404, #5407
  • 00dc2ad chore: update ts type (#5408)
  • 790f83f release 3.1.0-rc.5
  • 3613ece fix: select deep watch options, close #5398
  • e146b48 fix: menuItem custom icon lose custom class, close #5390
  • e9ba9fe doc: update changelog
  • 1258825 release 3.1.0-rc.3
  • b0042ab feat: support change base-primary for cssvar
  • e7fb72c fix: Dropdown not auto adjust placement, close #5391
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

stale[bot] commented 2 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.