Strapi was made aware of a vulnerably that were patched in this release, for now we are going to delay the detailed disclosure of the exact details on how to exploit it and how it was patched to give time for users to upgrade before we do public disclosure.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the production group with 4 updates: @strapi/utils, @strapi/icons, @strapi/design-system and meilisearch.
Updates
@strapi/utils
from 4.24.0 to 4.24.4Release notes
Sourced from
@strapi/utils
's releases.Commits
bb2e16a
v4.24.4c80d4d9
[TS] Update position attribute to be optional in relation reordering types (#...8d33a8c
Merge tag 'v4.24.3' into developaa35157
v4.24.3bd269fa
feat: add missing attributes to Media in typescript generator (#19329)5277eaf
fix(ctb): validate pluralName and collectionName correctly (#20347)0c9f2e7
fix(chore): replace use-context-selector context with React Context (#20287)48a7b1e
chore: sync e2e tests with v5 branch (#20334)c413ad9
release: v4.24.2 to develop (#20280)53507a6
fix(cm): back button on ListSettingsView doesn't work (#20263)Updates
@strapi/icons
from 1.18.0 to 1.19.0Updates
@strapi/design-system
from 1.18.0 to 1.19.0Updates
meilisearch
from 0.38.0 to 0.40.0Release notes
Sourced from meilisearch's releases.
... (truncated)
Commits
cd61a8c
Merge #16539639f78
Merge #1652f53131f
Update src/package-version.ts45c5d96
Update package.jsone0b1e71
Update crypto statement to fix vite issue2f37b74
Merge #1650ba8e617
docs: update readme links to the documentation4475864
Merge #1648a756c11
Update src/package-version.tsb208992
Update package.jsonDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show