VilnaCRM-Org / website

Creative Commons Zero v1.0 Universal
0 stars 0 forks source link

[Snyk] Security upgrade storybook from 6.5.16 to 7.1.0 #19

Closed Kravalg closed 6 months ago

Kravalg commented 6 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Issue | Breaking Change | Exploit Maturity :-------------------------:|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-GLOBPARENT-1016905](https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Open Redirect
[SNYK-JS-GOT-2932019](https://snyk.io/vuln/SNYK-JS-GOT-2932019) | Yes | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | Cross-site Scripting (XSS)
[SNYK-JS-SERIALIZEJAVASCRIPT-6147607](https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-6147607) | Yes | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-TRIM-1017038](https://snyk.io/vuln/SNYK-JS-TRIM-1017038) | Yes | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | Prototype Pollution
[SNYK-JS-UNSETVALUE-2400660](https://snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660) | Yes | No Known Exploit
Commit messages
Package name: storybook The new version differs by 250 commits.
  • 51608c8 Bump version from "7.1.0-rc.2" to "7.1.0" [skip ci]
  • 99088fd Merge pull request #23473 from storybookjs/version-prerelease-from-7.1.0-rc.2
  • 9e8912c Update CHANGELOG.md [skip ci]
  • 7862f9e Write changelog for 7.1.0
  • 80edfa4 Merge pull request #23475 from storybookjs/fix/lint-issue
  • 027ef0c remove unused import
  • fa8c5f6 Merge pull request #23472 from storybookjs/fix/improve-svelte-error
  • 29a1103 move error message from log to error
  • 4c371e0 Merge pull request #23471 from storybookjs/update-pr-template
  • 1161323 Update PULL_REQUEST_TEMPLATE.md
  • fdd07b7 fix typo
  • 36935e9 Restore prerelease changelogs before 7.1.0-alpha.30
  • 3531eb3 Merge pull request #23186 from re-taro/fix/jsdoc
  • 9f9070d Merge pull request #23444 from storybookjs/chore_docs_adds_mdx_video_callout
  • f88a170 Merge branch 'next' into chore_docs_adds_mdx_video_callout
  • 6c733aa Merge pull request #23439 from storybookjs/chore_docs_autodocs_toc
  • 2035c5f Addressing feedback
  • 59c3af4 Adds MDX video callout
  • cfcb363 Merge pull request #23442 from storybookjs/chore_docs_web_snippets_fix
  • 950218f Fixes autodocs webcomponents snippets
  • e7479e7 Bump version from "7.1.0-rc.1" to "7.1.0-rc.2" [skip ci]
  • c1b4e2e Merge pull request #23414 from storybookjs/version-prerelease-from-7.1.0-rc.1
  • 4124e95 Write changelog for 7.1.0-rc.2
  • 15f6768 Adds TOC documentation
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/kravalg/project/0c3303db-9fb9-435f-97a5-4250e16c1d5f?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/kravalg/project/0c3303db-9fb9-435f-97a5-4250e16c1d5f?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"3cdc70a6-2276-4b1e-88bf-2553bebdeea8","prPublicId":"3cdc70a6-2276-4b1e-88bf-2553bebdeea8","dependencies":[{"name":"storybook","from":"6.5.16","to":"7.1.0"}],"packageManager":"npm","projectPublicId":"0c3303db-9fb9-435f-97a5-4250e16c1d5f","projectUrl":"https://app.snyk.io/org/kravalg/project/0c3303db-9fb9-435f-97a5-4250e16c1d5f?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-GLOBPARENT-1016905","SNYK-JS-GOT-2932019","SNYK-JS-INFLIGHT-6095116","SNYK-JS-SERIALIZEJAVASCRIPT-6147607","SNYK-JS-TRIM-1017038","SNYK-JS-UNSETVALUE-2400660"],"upgrade":["SNYK-JS-GLOBPARENT-1016905","SNYK-JS-GOT-2932019","SNYK-JS-INFLIGHT-6095116","SNYK-JS-SERIALIZEJAVASCRIPT-6147607","SNYK-JS-TRIM-1017038","SNYK-JS-UNSETVALUE-2400660"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title"],"priorityScoreList":[null,null,417,null,null,null],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr) 🦉 [Open Redirect](https://learn.snyk.io/lesson/open-redirect/?loc=fix-pr) 🦉 [Cross-site Scripting (XSS)](https://learn.snyk.io/lesson/dom-based-xss/?loc=fix-pr) 🦉 [More lessons are available in Snyk Learn](https://learn.snyk.io/?loc=fix-pr)
codecov[bot] commented 6 months ago

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 78.57%. Comparing base (77cfd5a) to head (579104a). Report is 19 commits behind head on main.

Additional details and impacted files ```diff @@ Coverage Diff @@ ## main #19 +/- ## ======================================= Coverage 78.57% 78.57% ======================================= Files 1 1 Lines 42 42 Branches 8 8 ======================================= Hits 33 33 Misses 8 8 Partials 1 1 ```

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.