sureng-ws-ibm / APISecurity-crAPI

Apache License 2.0
0 stars 0 forks source link

Update dependency react-scripts to v3.4.2 - autoclosed #20

Closed mend-for-github-com[bot] closed 2 years ago

mend-for-github-com[bot] commented 2 years ago

This PR contains the following updates:

Package Type Update Change
react-scripts dependencies patch 3.4.1 -> 3.4.2

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score CVE
High High 9.8 CVE-2020-15256
High High 9.8 CVE-2020-7774
High High 9.8 CVE-2021-23436
High High 9.8 CVE-2021-26707
High High 9.8 CVE-2021-3757
High High 9.8 CVE-2021-3918
High High 9.8 CVE-2022-0691
High High 9.1 CVE-2022-0686
High High 8.6 CVE-2021-23434
High High 8.1 CVE-2020-7660
High High 7.8 CVE-2021-43138
High High 7.7 CVE-2020-13822
High High 7.5 CVE-2020-28469
High High 7.5 CVE-2020-28469
High High 7.5 CVE-2020-28477
High High 7.5 CVE-2021-23343
High High 7.5 CVE-2021-23424
High High 7.5 CVE-2021-27290
High High 7.5 CVE-2021-27290
High High 7.5 CVE-2021-28092
High High 7.5 CVE-2021-29059
High High 7.5 CVE-2021-33502
High High 7.5 CVE-2021-33502
High High 7.5 CVE-2021-3777
High High 7.5 CVE-2021-3805
High High 7.5 CVE-2021-3807
High High 7.5 CVE-2022-24771
High High 7.5 CVE-2022-24772
High High 7.5 WS-2021-0152
High High 7.3 CVE-2020-7720
High High 7.3 CVE-2020-7788
Medium Medium 6.8 CVE-2020-28498
Medium Medium 6.6 WS-2022-0008
Medium Medium 6.5 CVE-2021-23386
Medium Medium 6.5 CVE-2022-0155
Medium Medium 6.1 CVE-2022-0122
Medium Medium 5.9 CVE-2022-0536
Medium Medium 5.9 WS-2019-0424
Medium Medium 5.6 CVE-2020-15366
Medium Medium 5.6 CVE-2020-7789
Medium Medium 5.6 CVE-2021-24033
Medium Medium 5.3 CVE-2020-7608
Medium Medium 5.3 CVE-2020-7693
Medium Medium 5.3 CVE-2021-23362
Medium Medium 5.3 CVE-2021-23364
Medium Medium 5.3 CVE-2021-23364
Medium Medium 5.3 CVE-2021-23368
Medium Medium 5.3 CVE-2021-23368
Medium Medium 5.3 CVE-2021-23382
Medium Medium 5.3 CVE-2021-23382
Medium Medium 5.3 CVE-2021-27515
Medium Medium 5.3 CVE-2021-29060
Medium Medium 5.3 CVE-2021-32640
Medium Medium 5.3 CVE-2021-32640
Medium Medium 5.3 CVE-2021-3664
Medium Medium 5.3 CVE-2022-0512
Medium Medium 5.3 CVE-2022-0639
Medium Medium 5.3 CVE-2022-24773

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score CVE
High High 8.6 CVE-2021-37701
High High 8.6 CVE-2021-37712
High High 8.6 CVE-2021-37713
High High 8.1 CVE-2021-32803
High High 8.1 CVE-2021-32804

Release Notes

facebook/create-react-app ### [`v3.4.2`](https://togithub.com/facebook/create-react-app/releases/v3.4.2) [Compare Source](https://togithub.com/facebook/create-react-app/compare/v3.4.1...v3.4.2) #### 3.4.2 (2020-08-11) v3.4.2 release bumps `webpack-dev-server` to a version for which `npm audit` does not report a vulnerability. Note that **this vulnerability did not affect Create React App projects**, so this change is only necessary to satisfy auditing tools. ##### Migrating from 3.4.1 to 3.4.2 Inside any created project that has not been ejected, run: ```sh npm install --save --save-exact react-scripts@3.4.2 ``` or ```sh yarn add --exact react-scripts@3.4.2 ```