YIZHUANG / react-multi-carousel

A lightweight production-ready Carousel that rocks supports multiple items and server-side rendering with no dependency. Bundle size 2kb.
MIT License
1.25k stars 286 forks source link

[Snyk] Security upgrade next from 8.0.3 to 8.0.4 #311

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 593/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 4
Information Exposure
SNYK-JS-NANOID-2332193
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: next The new version differs by 233 commits.
  • e6e4a15 v8.0.4
  • 25deefb Avoid "ad" anywhere in the buildId (#6854)
  • 742f29f buildId is not an ad (#6851)
  • e25312b Make sure error isn't swallowed for production test on CircleCi (#6848)
  • 14eef58 Re-add chromedriver retrying from previous webdriver setup (#6846)
  • 8cd7bd1 Fix wrong anchors and add missing link (#6845)
  • 3a7caa6 v8.0.4-canary.31
  • c864ab9 Added useBuiltIns to babel object-rest-spread (#6805)
  • 41da136 v8.0.4-canary.30
  • f6786b4 v8.0.4-canary.29
  • 99023b9 v8.0.4-canary.28
  • 71680fb Fix typo in workflow (#6838)
  • e48610e v8.0.4-canary.27
  • f6439ae Add workflow to generate stats for release (#6836)
  • 6bb8327 Exclude transform-typeof-symbol (#6812)
  • f81e5f4 Added babel-plugin-dynamic-import-node (#6811)
  • 26a4eb8 Add dropping of custom scripts in AMP mode (#6830)
  • b6b0db1 Update env variables for CircleCi (#6834)
  • 8b5906c Add error catching to firefox url query workaround (#6833)
  • 533018f Update tests for BrowserStack (#6810)
  • 9c2f690 Fix typo by replacing `compatability` with `compatibility` (#6831)
  • a750d1c NODE_ENV is set to undefined before running a test command (#6823)
  • 2f325e0 Add example with astroturf (Zero runtime CSS-in-JS) (#6821)
  • 51b1541 The custom build test now runs in production mode (#6818)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic