newrelic / nr1-github

NR1 Github allows you to create more context to your entities by having access to the GitHub repository, contributors and README.
https://github.com/newrelic/nr1-github/discussions
Apache License 2.0
19 stars 27 forks source link

[Snyk] Security upgrade react-markdown from 4.3.1 to 5.0.0 #53

Closed snyk-bot closed 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TRIM-1017038
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-markdown The new version differs by 18 commits.
  • 45b9977 5.0.0
  • eeea3c2 Update `changelog.md`
  • 5d6c9f1 Refactor scripts
  • d29478f Add type tests
  • 4f5dbe2 Add note
  • 7a5e3a1 Add `allowDangerousHtml`, preferred over `escapeHtml`
  • 2675ae2 Remove docs on `source`
  • 34b0883 Change default branch to `main`
  • 22a5e49 Refactor and test for 100% coverage
  • b3aa6e0 Rewrite readme for unified, more examples
  • a9f163d Move demo to `website` branch
  • 4f1a407 Change to clean project, update, refactor scripts
  • ebebf51 Upgrade remark to version 8, unified to version 9
  • e400f6f Upgrade to remark-parse@6
  • 3260f57 Run tests on node 12
  • 6eff8d1 Pass AST node to all non-tag/non-fragment renderers as prop
  • ca25be1 Fix link to demo in readme
  • 9b4eb84 Updated remark-parse github link (#447)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

CLAassistant commented 4 years ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.