bdfinst / total-perspective-vortex

Value stream mapping is typically very manual and drawing tools are toilsome. This seeks to semi-automate the process.
https://vsm.bryanfinster.com
MIT License
6 stars 6 forks source link

[Snyk] Security upgrade react-flow-renderer from 9.6.0 to 9.6.1 #67

Closed snyk-bot closed 2 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-D3COLOR-1076592
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-flow-renderer The new version differs by 12 commits.
  • 2496a6e Merge branch 'main' of github.com:wbkd/react-flow into main
  • d480d25 refactor(controls): use button element for buttons instead of divs closes #1228
  • 290ba99 chore(deps): update
  • d8c88ee Merge pull request #1258 from wbkd/dependabot/npm_and_yarn/main/babel/preset-react-7.14.5
  • d24c58e Merge pull request #1259 from wbkd/dependabot/npm_and_yarn/main/d3-selection-3.0.0
  • fea40ae Merge pull request #1260 from wbkd/dependabot/npm_and_yarn/main/babel/runtime-7.14.5
  • 0fc9906 Merge pull request #1261 from wbkd/dependabot/npm_and_yarn/main/postcss-8.3.2
  • 0afbe8c chore(deps-dev): bump postcss from 8.3.0 to 8.3.2
  • ce0fe50 chore(deps): bump @ babel/runtime from 7.14.0 to 7.14.5
  • b1cf3d8 chore(deps): bump d3-selection from 2.0.0 to 3.0.0
  • 23b971d chore(deps-dev): bump @ babel/preset-react from 7.13.13 to 7.14.5
  • c956ac2 chore: release v9.6.0
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic