leighs-hammer / shopify-app-boilerplate-nextjs-redux-nosql

serverless shopify app boilerplate using react typescript redux polaris mongoDB
https://shopify-app-boilerplate-v2.now.sh
31 stars 3 forks source link

[Snyk] Security upgrade next from 9.3.4 to 9.5.3 #33

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NORMALIZEURL-1296539
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: next The new version differs by 250 commits.
  • b6df810 v9.5.3
  • 48ce4de v9.5.3-canary.27
  • e34e5e0 Revert #14580 (#16757)
  • 808d6b9 [EXAMPLE] with-framer-motion: fix broken images (#16714)
  • 1c45f70 [test] Update hydration marker for React 17 (#16756)
  • d20dbd6 Export return type for GetStaticPaths (#16580)
  • d59f12c v9.5.3-canary.26
  • 91a50d3 Revert "fix: Promise.prototype.finally is object (#16620)" (#16753)
  • f921b4f Auto enable React's new JSX transform on 17.x (#16603)
  • 6f60a22 fix: fix hashing algo and locale value hydration (#16692)
  • f1c4cb8 Update preview mode docs to include API Routes (#16705)
  • ce99436 Add cross-env to ensure examples work on Windows 10 (#16694)
  • ba2fbc2 Update _app.js to use a function component. (#16683)
  • 6926ab7 fix: Promise.prototype.finally is object (#16620)
  • f17d435 Ensure all examples are MIT licensed (#16691)
  • d6188a8 Clarify sending to Google Analytics in reportWebVitals (#16664)
  • c03d493 Simplify example usage instructions (#16678)
  • 97d8e07 [Example] fix with-firebase-hosting (#16577)
  • 694ccc7 Upgrade typescript to 4.0 (#16673)
  • 04c9906 Update with-typescript-graphql (#16101)
  • 624b748 Add missing gitignore files
  • 7e731a8 Update README.mb (#16676)
  • a2d8395 Add with-mdx-remote example (#16613)
  • 8217597 Add activeClassName to Link examples (#16658)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

vercel[bot] commented 3 years ago

This pull request is being automatically deployed with Vercel (learn more).
To see the status of your deployment, click below or on the icon next to each commit.

🔍 Inspect: https://vercel.com/leighbarnes/shopify-app-boilerplate-v2/7QupngvXb6TiNfUEBPdn7g9Qf4zq
✅ Preview: Failed

[Deployment for 64ba7e4 failed]