hubtype / botonic

Build chatbots and conversational experiences using React
https://botonic.io
MIT License
519 stars 76 forks source link

[Snyk] Upgrade react-json-tree from 0.15.2 to 0.19.0 #2891

Closed gbarba closed 1 month ago

gbarba commented 1 month ago

snyk-top-banner

Snyk has created this PR to upgrade react-json-tree from 0.15.2 to 0.19.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-7361793
619 Proof of Concept
Release notes
Package name: react-json-tree
  • 0.19.0 - 2024-04-07
  • 0.18.0 - 2023-01-05
  • 0.17.0 - 2022-05-30
  • 0.16.2 - 2022-04-04
  • 0.16.1 - 2022-01-25
  • 0.16.0 - 2022-01-10
  • 0.15.2 - 2022-01-08
from react-json-tree GitHub release notes

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information: