et-nik / gameap

Game Admin Panel (GameAP) is the opensource game servers control panel.
https://gameap.com
99 stars 22 forks source link

[Snyk] Security upgrade laravel-mix from 5.0.9 to 6.0.0 #56

Closed et-nik closed 3 years ago

et-nik commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SSRI-1085630
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: laravel-mix The new version differs by 250 commits.
  • 5d7f345 6.0.0
  • ffc16fb Bump Playwright
  • a1af179 Remove outdated friendly errors plugin (#2668)
  • 292aa3c Fix processCssUrls for PostCSS (#2675)
  • b387d41 Fix HMR (#2669)
  • 927ba39 Remove SnoreToast message from notification in Windows 10 (#2672)
  • ea23b21 6.0.0-beta.17
  • 08bffce Add missing import (#2665)
  • f7dd5a0 6.0.0-beta.16
  • 155aa56 React: Add support to new JSX transform (#2655)
  • d0c50fc Fix reading files with query string (#2652)
  • 270eefa Apply webpack-dev-server 4.0 changes (#2660)
  • 40cb802 Update typescript types (#2606)
  • 1df4ddc Refactor test to check the PostCSS version (#2663)
  • b2777fc 6.0.0-beta.15
  • 4e3888b Add support for .pcss files (#2645)
  • a285e63 Fix HTML imports in .vue SFCs (#2646)
  • 99a0699 Ensure url rewriting can be turned off in Vue SFCs (#2644)
  • f20e338 [6.x] Install dependencies with yarn when using yarn (#2642)
  • f85ba94 Don’t report progress to non-terminal environments (#2637)
  • bfc72b8 Support custom NODE_ENV (#2636)
  • 67081b0 Correct vendor extraction priority with custom filenames (#2635)
  • ef59720 Update package.json (#2632)
  • b2c80d3 Build config asynchronously (#2608)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

et-nik commented 3 years ago

https://github.com/et-nik/gameap/pull/55