craftcms / spoke-and-chain

Craft CMS + Craft Commerce demo site.
https://craftcms.com/demo?kind=spokeandchain
BSD Zero Clause License
53 stars 28 forks source link

[Snyk] Upgrade tailwindcss from 2.2.7 to 2.2.16 #61

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade tailwindcss from 2.2.7 to 2.2.16.

merge advice As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-SWIPER-1088062
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1314294
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: tailwindcss
  • 2.2.16 - 2021-09-26

    Fixed

    • JIT: Properly handle animations that use CSS custom properties (#5602)
  • 2.2.15 - 2021-09-10

    Fixed

    • Ensure using CLI without -i for input file continues to work even though deprecated (#5464)
  • 2.2.14 - 2021-09-08

    Fixed

    • Only use @ defaults in JIT, switch back to clean-css in case there's any meaningful differences in the output (bf248cb)
  • 2.2.13 - 2021-09-08

    Fixed

    • Fix broken CDN build
  • 2.2.12 - 2021-09-08

    Fixed

    • Ensure that divide utilities inject a default border color (#5438)
  • 2.2.11 - 2021-09-07

    Fixed

    • Rebundle to fix missing CLI peer dependencies
  • 2.2.10 - 2021-09-06

    Fixed

    • Fix build error when using presets: [] in config file (#4903)

    Added

    • Reintroduce universal selector optimizations under experimental optimizeUniversalDefaults flag (a9e160c)
  • 2.2.9 - 2021-08-30

    Fixed

    • JIT: Fix @ applying utilities that contain variants + the important modifier (#4854)
    • JIT: Don't strip "null" when parsing tracked file paths (#5008)
    • Pin clean-css to v5.1.4 to fix empty CSS variables in CDN builds (#5338)
  • 2.2.8 - 2021-08-27
  • 2.2.7 - 2021-07-23
from tailwindcss GitHub release notes
Commit messages
Package name: tailwindcss Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs