rikasun / Bagquest

A faithful clone of Pinterest
0 stars 0 forks source link

[Snyk] Upgrade react-spinners from 0.4.7 to 0.13.8 #5

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to upgrade react-spinners from 0.4.7 to 0.13.8.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Arbitrary Code Execution
SNYK-JS-JSYAML-174129
405/1000
Why? CVSS 8.1
No Known Exploit
Denial of Service (DoS)
SNYK-JS-JSYAML-173999
405/1000
Why? CVSS 8.1
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: react-spinners
  • 0.13.8 - 2023-01-19

    What's Changed

    New Contributors

    Full Changelog: v0.13.7...v0.13.8

  • 0.13.7 - 2022-12-03

    What's Changed

    fix: PacmanLoader container height/width to adjust with size prop

  • 0.13.6 - 2022-10-08

    0.13.6

  • 0.13.5 - 2022-10-04

    0.13.5

  • 0.13.4 - 2022-07-30
  • 0.13.3 - 2022-07-01

    0.13.3

  • 0.13.2 - 2022-06-28

    0.13.2

  • 0.13.1 - 2022-06-25

    0.13.1

  • 0.13.0 - 2022-06-25

    Major Changes

    Feature: Removed @ emotion/react as a dependency and rewrote all components as functional components. This library now has ZERO dependencies.

    This resulted in a huge component size reduction. As compared between 0.12.0 and 0.13.0

    0.13.0
    Screen Shot 2022-06-25 at 4 20 30 PM
    0.12.0
    Screen Shot 2022-06-25 at 4 20 34 PM

    Feature: Add support for custom props such as aria-label
    Feature: Updated RiseLoader rise amount to be the same as size prop instead of hard coded 30px

    Breaking Change: css prop is renamed to cssOverride to avoid conflicts with css-in-js libraries

    Storybook is introduced to better demo the components. The demo site is simplified to only allow color changes.

    Minor Changes

    • replaced enzyme with react testing library
    • bugfix: add display: inherit to the default styles to fix the rendering issue
    • bugfix: GridLoader's rendering issue
  • 0.13.0-beta.7 - 2022-06-25
  • 0.13.0-beta.6 - 2022-06-25
  • 0.13.0-beta.5 - 2022-06-07
  • 0.13.0-beta.4 - 2022-06-05
  • 0.13.0-beta.3 - 2022-05-26
  • 0.13.0-beta.2 - 2022-05-26
  • 0.13.0-beta.1 - 2022-05-26
  • 0.13.0-alpha.5 - 2022-05-22
  • 0.13.0-alpha.4 - 2022-05-22
  • 0.13.0-alpha.3 - 2022-05-16
  • 0.13.0-alpha.1 - 2022-05-16
  • 0.12.0 - 2022-05-16

    Major Changes

    • Feature: output commonjs, es module, and umd file types.
    • Feature: add support for react 18 #464

    Minor Changes

    • bugfix: Update pragma to /** @ jsxImportSource @ emotion/react */ to fix issue with the new jsx runtime.
  • 0.12.0-beta.1 - 2022-05-16
  • 0.12.0-alpha.3 - 2022-05-03
  • 0.12.0-alpha.2 - 2021-10-06
  • 0.12.0-alpha.1 - 2021-09-25
  • 0.11.0 - 2021-05-21
  • 0.11.0-beta.1 - 2021-05-02
  • 0.11.0-alpha.8 - 2021-03-21
  • 0.11.0-alpha.7 - 2021-03-21
  • 0.11.0-alpha.6 - 2021-02-22
  • 0.11.0-alpha.5 - 2021-02-21
  • 0.11.0-alpha.4 - 2021-02-21
  • 0.11.0-alpha.3 - 2021-02-21
  • 0.11.0-alpha.2 - 2020-12-31
  • 0.11.0-alpha.1 - 2020-12-30
  • 0.10.6 - 2021-02-13
  • 0.10.4 - 2021-01-02
  • 0.10.3 - 2021-01-02
  • 0.10.2 - 2021-01-02
  • 0.10.1 - 2020-12-30
  • 0.10.0 - 2020-12-30
  • 0.10.0-beta.3 - 2020-12-30
  • 0.10.0-beta.2 - 2020-12-30
  • 0.10.0-beta.1 - 2020-12-30
  • 0.10.0-alpha.3 - 2020-12-27
  • 0.10.0-alpha.2 - 2020-10-06
  • 0.10.0-alpha.1 - 2020-10-06
  • 0.9.0 - 2020-06-20
  • 0.8.3 - 2020-05-02
  • 0.8.2 - 2020-05-02
  • 0.8.1 - 2020-03-08
  • 0.8.0 - 2020-01-02
  • 0.7.2 - 2019-12-25
  • 0.7.1 - 2019-12-21
  • 0.7.0 - 2019-12-21
  • 0.7.0-beta.1 - 2019-11-30
  • 0.7.0-alpha.5 - 2019-11-29
  • 0.7.0-alpha.4 - 2019-11-27
  • 0.7.0-alpha.3 - 2019-11-27
  • 0.7.0-alpha.2 - 2019-11-25
  • 0.7.0-alpha.1 - 2019-11-24
  • 0.6.1 - 2019-08-23
  • 0.6.0 - 2019-08-19
  • 0.6.0-beta.1 - 2019-08-13
  • 0.6.0-alpha.10 - 2019-08-11
  • 0.6.0-alpha.9 - 2019-08-11
  • 0.6.0-alpha.8 - 2019-08-07
  • 0.6.0-alpha.7 - 2019-08-07
  • 0.6.0-alpha.6 - 2019-08-06
  • 0.6.0-alpha.5 - 2019-08-06
  • 0.6.0-alpha.4 - 2019-08-06
  • 0.6.0-alpha.3 - 2019-08-04
  • 0.6.0-alpha.2 - 2019-07-28
  • 0.6.0-alpha.1 - 2019-07-20
  • 0.5.13 - 2019-07-19
  • 0.5.12 - 2019-07-15
  • 0.5.11 - 2019-07-15
  • 0.5.9 - 2019-07-15
  • 0.5.8 - 2019-07-07
  • 0.5.7 - 2019-07-07
  • 0.5.6 - 2019-07-07
  • 0.5.5 - 2019-07-04
  • 0.5.4 - 2019-04-06
  • 0.5.3 - 2019-03-04
  • 0.5.2 - 2019-03-04
  • 0.5.1 - 2019-01-06
  • 0.5.0 - 2019-01-06
  • 0.4.8 - 2018-12-19
  • 0.4.7 - 2018-10-16
from react-spinners GitHub release notes
Commit messages
Package name: react-spinners
  • 61ad627 0.13.8
  • b4f044d add changelog for 0.13.8
  • 38448c5 docs: fix radius prop type in storybook to be number instead of object (#561)
  • b33fb0d Remove Animation Fill Mode from CircleLoader to fix SSR (#558)
  • 1ef6575 Bump json5 from 1.0.1 to 1.0.2 (#559)
  • b8eb6ca chore: update devDependencies to latest versions (#556)
  • 536c4eb Bump decode-uri-component from 0.2.0 to 0.2.2 (#555)
  • 0b83da8 0.13.7
  • d575a3e fix PacmanLoader container height/width to adjust with size prop
  • 388e04d Bump loader-utils from 1.4.1 to 1.4.2 (#554)
  • a6c877e Bump deep-object-diff from 1.1.7 to 1.1.9 (#553)
  • c6da343 Bump terser from 4.8.0 to 4.8.1 (#552)
  • 409beec Bump loader-utils from 1.4.0 to 1.4.1 (#551)
  • b3827ba fix blog link in footer
  • 3859e8f 0.13.6
  • 87c512f improve readme format of example code
  • f6e91fc fix gh pages action when cache does not exist (#547)
  • 84c83b9 0.13.5
  • 814f524 update readme with include info on additional html props
  • f87bde7 fix fork on github banner cause footer style issues
  • a77fe1e move script into docs code instead of standpoint script
  • 9b8a475 add google adsense to demo & storybook
  • 4c69b22 fix darkmode on storybook (#544)
  • 393b126 add darkmode to storybook, add canoical link, cleanup babel plugins (#543)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs