hikerpig / gatsby-project-kb

Developing gatsby-theme-kb, a Gatsby theme for publishing Knowledge Base.
https://gatsby-project-kb.vercel.app/
MIT License
62 stars 15 forks source link

[Snyk] Security upgrade gatsby-plugin-purgecss from 5.0.0 to 6.0.0 #25

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1090595
Yes Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
Yes Proof of Concept
Commit messages
Package name: gatsby-plugin-purgecss The new version differs by 250 commits.
  • cf8f26d Release 6.0.0
  • fbedfdf docs: add gatsby v3 info
  • 9e76865 build: using webpack 4 types
  • be1f095 build: move tests to gatsby v3
  • 1a5050e Merge pull request #950 from anantoghosh/v6
  • 5661856 docs: add tailwind note
  • d14a717 ci: list correct sass package
  • 75cbe97 ci: try again
  • ec64e48 ci: return 1 on error
  • f2596da ci: solve peer dep install issue
  • 1354846 ci: throw on error
  • e3d9c53 tests: add tailwind ci tests
  • 92fc852 chore: add editor config
  • be9793e test: add initial tailwind test folder
  • 4f38c6a build: update release-it config
  • 07efd88 ci: update test script
  • 98ec9c5 build: update renovate config
  • 6a4a4bc docs: update options
  • 0ec8735 build: remove unused scripts
  • 732e825 feat: remove reject option, add printSummary
  • f7602e3 fix: update tailwind regex
  • 5476e59 build: remove unneeded packages
  • b7443ed feat: update test build and scripts
  • 5651c2b fix: set default content path
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic