Watemlifts / redash

Make Your Company Data Driven. Connect to any data source, easily visualize, dashboard and share your data.
http://redash.io/
BSD 2-Clause "Simplified" License
1 stars 0 forks source link

[Snyk] Security upgrade antd from 3.13.6 to 3.16.4 #231

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-NODEFETCH-2342118
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: antd The new version differs by 250 commits.
  • 08beabf chore: fix remote checking
  • f6c1582 docs: use star emoji
  • bb90c4f Bump 3.16.4
  • e521b32 Merge pull request #16206 from ant-design/release-3.16.4
  • 4f0403c Add 3.16.4 changelog
  • 8ec3831 Merge pull request #16203 from saxenanihal95/code_refactor
  • 1569ab3 prettier md demo (#16188)
  • 2b0723f update script (#16204)
  • 73188ac fix: Table `rowSelection.columnWidth` should work (#16180)
  • 9fd4b2d Refactor: created InputIcon of common code in RangePicker and WeekPicker
  • 5987792 fix: typescript definition update (#16202)
  • 35da7ce Merge pull request #16197 from ant-design/chores
  • 4b17591 :memo: Remove webpack@1 instruction
  • ac5868c :up: upgrade stylelint-order
  • 27045c5 Merge pull request #16196 from aaroncawte/master
  • 4cd0c74 Documentation - Tree Component
  • 7333506 Documentation - Timeline Component
  • 8833f0b Documentation - Tag Component
  • 719aff7 Documentation - Table Component
  • 0c7b3ce Documentation - List Component
  • a89c228 Documentation - Comment Component
  • e8e29f7 Documentation - Collapse Component
  • 0fc9b86 Documentation - Badge Component
  • f30aee5 Documentation - Avatar Component
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: šŸ§ View latest project report

šŸ›  Adjust project settings

šŸ“š Read more about Snyk's upgrade and patch logic