haysclark / gatsby-starter-casper

The Casper theme v1.4 ported to GatsbyJS
https://haysclark.github.io/gatsby-starter-casper/
MIT License
199 stars 54 forks source link

[Snyk] Fix for 1 vulnerabilities #69

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

⚠️ Warning ``` Failed to update the package-lock.json, please update manually before merging. ```

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 481/1000
Why? Recently disclosed, Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: gatsby-plugin-manifest The new version differs by 250 commits.
  • cfc6413 Unused variable and wrong propTypes (#22426)
  • 56023e8 chore(release): Publish
  • 79e6bbe chore(gatsby): Update sharp and remove Promise shim for Node 8 (#22432)
  • ec8e2f9 chore(release): Publish
  • cf4f2db chore(docs): Fix Markdown formatting (#22423)
  • 07b1434 chore(gatsby): upgrade `null-loader` (#22410)
  • e1a7313 chore(gatsby-source-filesystem): update got dependency (#18857)
  • 7f197c0 chore(release): Publish
  • 83d681a feat(gatsby): bump node min version to 10.13.0 (#22400)
  • 72c91f5 chore(release): Publish
  • f345985 chore(docs): 🧹 remove trailing whitespace from Markdown. (#22369)
  • e0933f8 fix missing link of frontmatter (#22366)
  • 2205811 fix(plugin-netlify-cms): use 'netlify-identity.js' instead of 'netlify-identity-widget.js' (#22387)
  • 9b7b6bb chore: adjust renovate config (#22355)
  • 341cc5b Blog post feature flags (#22405)
  • a55329b Fix the setup() function in the documentation (#22368)
  • 5496e6b fix(gatsby): Incorrect PackageJson type (#22406)
  • 3ce7083 Showcase erudicat update (#22407)
  • 39282ca fix(docs): 404 link to workers.dev (#22365)
  • 43ad085 chore(gatsby): Convert local-eslint-config-finder to typescript (#22403)
  • 0700cd5 chore(gatsby): migrate test-require-error to typescript (#22265)
  • 7d73604 chore(gatsby): migrate webpack-hmr-hooks-patch to TypeScript (#22280)
  • 101e322 chore(starters): add gatsby-minimalistic-dmin (#22375)
  • d9c6415 Fixed eslint url path (#22399)
See the full diff
Package name: gatsby-plugin-sharp The new version differs by 250 commits.
  • cfc6413 Unused variable and wrong propTypes (#22426)
  • 56023e8 chore(release): Publish
  • 79e6bbe chore(gatsby): Update sharp and remove Promise shim for Node 8 (#22432)
  • ec8e2f9 chore(release): Publish
  • cf4f2db chore(docs): Fix Markdown formatting (#22423)
  • 07b1434 chore(gatsby): upgrade `null-loader` (#22410)
  • e1a7313 chore(gatsby-source-filesystem): update got dependency (#18857)
  • 7f197c0 chore(release): Publish
  • 83d681a feat(gatsby): bump node min version to 10.13.0 (#22400)
  • 72c91f5 chore(release): Publish
  • f345985 chore(docs): 🧹 remove trailing whitespace from Markdown. (#22369)
  • e0933f8 fix missing link of frontmatter (#22366)
  • 2205811 fix(plugin-netlify-cms): use 'netlify-identity.js' instead of 'netlify-identity-widget.js' (#22387)
  • 9b7b6bb chore: adjust renovate config (#22355)
  • 341cc5b Blog post feature flags (#22405)
  • a55329b Fix the setup() function in the documentation (#22368)
  • 5496e6b fix(gatsby): Incorrect PackageJson type (#22406)
  • 3ce7083 Showcase erudicat update (#22407)
  • 39282ca fix(docs): 404 link to workers.dev (#22365)
  • 43ad085 chore(gatsby): Convert local-eslint-config-finder to typescript (#22403)
  • 0700cd5 chore(gatsby): migrate test-require-error to typescript (#22265)
  • 7d73604 chore(gatsby): migrate webpack-hmr-hooks-patch to TypeScript (#22280)
  • 101e322 chore(starters): add gatsby-minimalistic-dmin (#22375)
  • d9c6415 Fixed eslint url path (#22399)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic