antvis / G

💥 A flexible rendering engine for visualization.
https://g.antv.antgroup.com/
1.07k stars 198 forks source link

[Snyk] Security upgrade gatsby from 2.32.13 to 4.22.0 #1687

Closed Yanyan-Wang closed 4 months ago

Yanyan-Wang commented 4 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Uncontrolled resource consumption
[SNYK-JS-BRACES-6838727](https://snyk.io/vuln/SNYK-JS-BRACES-6838727) | Yes | No Known Exploit ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Inefficient Regular Expression Complexity
[SNYK-JS-MICROMATCH-6838728](https://snyk.io/vuln/SNYK-JS-MICROMATCH-6838728) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: gatsby The new version differs by 250 commits.
  • 78f8c7a chore(release): Publish
  • 4dcdeb1 chore(gatsby): Add env log for build and remove incorrect log for functions (#36462) (#36466)
  • 41de1f0 feat(gatsby): add partial hydration flag (#36436)
  • b8c2072 fix(gatsby-source-graphql): add dataLoaderOptions validation to gatsby-source-graphql (#36112)
  • b45debc chore(docs): fix incorrect closing tag in tutorial (#36459)
  • 222793d chore(docs): Update plugin count in part 3 of the tutorial (#36455)
  • 3222684 chore(docs): Fix page link to page 6 of remark tutorial (#36437)
  • 0b458e6 chore(docs): Fix some typos (#36431)
  • 1bf2358 fix(gatsby): remove resource query from warnings (#36439)
  • 0d896ae chore(gatsby-plugin-sharp,gatsby-plugin-utils,gatsby-remark-images,gatsby-transformer-sharp): bump min potrace version (#36443)
  • a21510e docs: plugin image / image cdn (#36423)
  • 8043d7e feat(docs): add webiny to headless cms list (#36388)
  • 240dfac chore: update using-image-processing example (#36421)
  • b361081 chore(gatsby): drop eslint-plugin-graphql (#36364)
  • 2e67161 chore(docs): Update tutorial to Head API (#36378)
  • 77190f4 fix(deps): update starters and examples - gatsby (#36416)
  • c92404b chore(changelogs): update changelogs (#36417)
  • b7b3577 fix(gatsby-plugin-react-helmet): Typo in `onPreInit` warning (#36419)
  • 7b3286c chore(docs): Add note about query name to MDX
  • dc283d7 chore: Use GCS for pipeline tests (#36413)
  • 3760a0e feat(gatsby): Add option to emit TS types during build (#36405)
  • c01806e chore(release): Publish next
  • a05201e fix(gatsby): Prevent errors if `Head` has root text node (#36402)
  • 9d737b6 fix(gatsby): close parcel cache db before clearing cache and retrying (#36377)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/yanyan-wang/project/0caf92f6-8e8f-43f0-be82-2b283b4fd42f?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/yanyan-wang/project/0caf92f6-8e8f-43f0-be82-2b283b4fd42f?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"d31ef26f-4f62-4330-b9c0-a77f56490a16","prPublicId":"d31ef26f-4f62-4330-b9c0-a77f56490a16","dependencies":[{"name":"gatsby","from":"2.32.13","to":"4.22.0"}],"packageManager":"npm","projectPublicId":"0caf92f6-8e8f-43f0-be82-2b283b4fd42f","projectUrl":"https://app.snyk.io/org/yanyan-wang/project/0caf92f6-8e8f-43f0-be82-2b283b4fd42f?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"upgrade":["SNYK-JS-BRACES-6838727","SNYK-JS-MICROMATCH-6838728"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[661,661],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Uncontrolled resource consumption](https://learn.snyk.io/lesson/redos/?loc=fix-pr)