bdfinst / total-perspective-vortex

Value stream mapping is typically very manual and drawing tools are toilsome. This seeks to semi-automate the process.
https://vsm.bryanfinster.com
MIT License
6 stars 6 forks source link

[Snyk] Upgrade web-vitals from 2.0.0 to 2.1.4 #99

Closed bdfinst closed 1 month ago

bdfinst commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade web-vitals from 2.0.0 to 2.1.4.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **6 versions** ahead of your current version. - The recommended version was released **a year ago**, on 2022-01-21. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Information Exposure
[SNYK-JS-FOLLOWREDIRECTS-2332181](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-2332181) | **372/1000**
**Why?** Proof of Concept exploit, CVSS 5.3 | Proof of Concept | Information Exposure
[SNYK-JS-FOLLOWREDIRECTS-2396346](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-2396346) | **372/1000**
**Why?** Proof of Concept exploit, CVSS 5.3 | No Known Exploit | Prototype Pollution
[SNYK-JS-MINIMIST-2429795](https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795) | **372/1000**
**Why?** Proof of Concept exploit, CVSS 5.3 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: web-vitals
  • 2.1.4 - 2022-01-21

    Release v2.1.4

      </li>
      <li>
        <b>2.1.3</b> - <a href="https://snyk.io/redirect/github/GoogleChrome/web-vitals/releases/tag/v2.1.3">2022-01-07</a></br><p>Release v2.1.3</p>
      </li>
      <li>
        <b>2.1.2</b> - <a href="https://snyk.io/redirect/github/GoogleChrome/web-vitals/releases/tag/v2.1.2">2021-10-11</a></br><p>Release v2.1.2</p>
      </li>
      <li>
        <b>2.1.1</b> - <a href="https://snyk.io/redirect/github/GoogleChrome/web-vitals/releases/tag/v2.1.1">2021-10-07</a></br><p>Release v2.1.1</p>
      </li>
      <li>
        <b>2.1.0</b> - <a href="https://snyk.io/redirect/github/GoogleChrome/web-vitals/releases/tag/v2.1.0">2021-07-01</a></br><p>Release v2.1.0</p>
      </li>
      <li>
        <b>2.0.1</b> - <a href="https://snyk.io/redirect/github/GoogleChrome/web-vitals/releases/tag/v2.0.1">2021-06-02</a></br><p>Release v2.0.1</p>
      </li>
      <li>
        <b>2.0.0</b> - <a href="https://snyk.io/redirect/github/GoogleChrome/web-vitals/releases/tag/v2.0.0">2021-06-02</a></br><p>Release v2.0.0</p>
      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/GoogleChrome/web-vitals/releases">web-vitals GitHub release notes</a>

Commit messages
Package name: web-vitals
  • 71ac4a0 Release v2.1.4
  • 43706b3 Update CHANGELOG
  • 6574306 Update dependencies
  • e6236d7 Merge pull request #201 from GoogleChrome/ttfb-bfcache
  • 2b4a155 Prevent TTFB from reporting after bfcache restore
  • c38944c Release v2.1.3
  • 00fed4e Update CHANGELOG
  • dbb92f4 Update dev dependencies
  • 9dd5fd2 Merge pull request #197 from monis0395/lcp_report
  • 789c51e report LCP only if the value changes
  • 6a51624 Merge pull request #189 from malchata/updates-ttfb-link
  • fc3c1e8 Updates the TTFB link in the README to the web.dev metric page.
  • ee6adc1 Release v2.1.2
  • 8b7a8d5 Update CHANGELOG
  • 0020d02 Merge pull request #187 from GoogleChrome/invalid-ttfb
  • f7d38b4 Ensure reported values are less than page time
  • 225ed14 Release v2.1.1
  • f6ce49b Update CHANGELOG
  • 9a40499 Merge pull request #186 from GoogleChrome/support-presto
  • 0940652 Add checks to support Opera mini in presto mode
  • ba12418 Merge pull request #183 from MananTank/main
  • f3931fc Fix type declaration of `FirstInputPolyfillEntry`
  • 1aa4659 Fix README example
  • ad735bf Fix formatting
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs