firespring / givesource

Other
13 stars 2 forks source link

[Snyk] Security upgrade @claviska/jquery-minicolors from 2.2.6 to 2.3.6 #90

Closed snyk-bot closed 1 year ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-CLAVISKAJQUERYMINICOLORS-1930824
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @claviska/jquery-minicolors The new version differs by 74 commits.
  • f5383d1 Merge branch 'master' of https://github.com/claviska/jquery-minicolors
  • 0e824c4 update version
  • 7054efe 2.3.6
  • ef13482 fix XSS vuln
  • 0a878dd remove broken demo link
  • cc3c141 Merge pull request #298 from majko96/master
  • d06d85d Fix scrolling on mobile devices
  • 707b803 Improve border colors
  • 11200a1 Merge pull request #294 from sangar82/master
  • 8d120a0 Merge pull request #290 from claviska/dependabot/npm_and_yarn/ini-1.3.7
  • 8fe6e28 Fix transparent watches #293
  • 6cb04a5 Merge pull request #292 from limenet/patch-1
  • 6301df9 Refactor jQuery 3.x deprecations
  • 41240d2 Bump ini from 1.3.5 to 1.3.7
  • d38eaaa Add funding config
  • ed2758a Bump version to 2.3.5
  • 66c8b92 Merge pull request #285 from bytestream/gulpjs
  • 320a6d2 Merge pull request #284 from bytestream/#282
  • 81f5cc6 Merge branch 'master' into #282
  • 735a818 Merge pull request #283 from bytestream/indentation
  • 84c5d14 Updated to gulp 4
  • 26ee722 revert whitespace changes
  • 07bfdbe Fixes #282
  • 965c41c Fixed code indentation
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic