openlegaldata / oldp

Open Legal Data Platform
https://openlegaldata.io
MIT License
98 stars 17 forks source link

[Snyk] Security upgrade jquery-ui from 1.12.1 to 1.13.2 #109

Open snyk-bot opened 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 556/1000
Why? Recently disclosed, Has a fix available, CVSS 5.4
Cross-site Scripting (XSS)
SNYK-JS-JQUERYUI-2946728
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: jquery-ui The new version differs by 160 commits.
  • d6c028c 1.13.2
  • 8cc5bae Checkboxradio: Don't re-evaluate text labels as HTML
  • b53e7be All: Remove deprecated .click() usage in demos/tests
  • bb00536 Build: Update AUTHORS.txt
  • 9d1fc97 Datepicker: Capitalize some Indonesian words
  • 1f467ba Selectmenu: Remove a call to the deprecated .focus() method
  • ac1866f Build: Update AUTHORS.txt
  • 395aa7d Datepicker: Add missing localization for prevText and nextText
  • 218c6af Datepicker: Remove symbols in localization
  • 3126e12 Datepicker: Remove symbols in localization
  • e853971 Build(deps): Bump actions/checkout from 2 to 3
  • d55645c Build(deps): Bump actions/cache from 2 to 3
  • a4060a2 Build(deps): Bump actions/setup-node from 1 to 3
  • d66fdd5 Build: Add dependabot.yml config (GitHub Actions)
  • 50d35e6 Build: Update Grunt to resolve CVE-2022-1537
  • e21a254 Build: Include all the files published to the CDN in npm/Bower packages
  • 54074fc Build: Updating the main version to 1.13.2-pre.
  • d2779bd Build: Update some npm dependencies
  • 0c5becc Widget: Optimize attachment of the _untrackClassesElement listener
  • 4a7cec3 Build: Add Felix to .mailmap, update AUTHORS.txt
  • 933ce5d Autocomplete: Rewrite with a delay instead of appending the live region
  • e90096e Build: Add extra Github action job for PR required checks configuration
  • e0a78d4 Build: Switch from Travis to GitHub actions
  • ed637b0 Widget: Make contextless widget construction work
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)