theamazingfedex / owod-cs

A digital character sheet for the Old World of Darkness pen and paper games.
MIT License
2 stars 0 forks source link

[Snyk] Security upgrade styled-jsx from 3.2.1 to 5.0.0 #30

Open snyk-bot opened 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 551/1000
Why? Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LOADERUTILS-3105943
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: styled-jsx The new version differs by 70 commits.
  • 13bd38d docs: update issue template
  • 75ee544 docs: add changelog and update readme (#775)
  • 104ab76 docs: update ssr and nextjs (#771)
  • 36fe10a perf: Pre-compile dependencies to reduce install size/time (#770)
  • b7832e9 perf: fallback to module level registry in browser (#768)
  • 9956457 doc: update issue template asking for nextjs version (#765)
  • b67b0d9 fix: use string for nonce typing (#766)
  • d43074f fix: typo acceps -> accepts (#760)
  • 9951745 typing: return JSX.Element for registry.styles (#759)
  • 6e224a9 feat: opt in insertion effect hook when available (#753)
  • dcadf5d fix: Make `JSXStyle` return a noop if the registry context is not provided (#749)
  • 174a186 chore: setup beta release
  • 45753c3 fix: zeit -> vercel (#746)
  • 48faf00 feat: contextual styles (#744)
  • 8b585d5 chore: update npm token (#743)
  • 69a76f2 fix: mark @ babel/core as optional peer dependency (#739)
  • 2a1bb87 chore: format files with prettier (#740)
  • 2428d38 test: remove broken test input (#738)
  • 8f4404a chore: use modern eslint and limit engines (#735)
  • 7c04667 docs: remove old Spectrum link from the README (#734)
  • d591ce2 perf: drop babel 6 support (#730)
  • 48a2599 feat: use react hooks to manage styles injection (#720)
  • b7f7dc3 chore: auto publish when merging to alpha (#727)
  • 452d2e8 fix: update test snapshots (#729)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)