videojs / videojs-errors

A video.js plugin that displays error messages to video viewers.
Other
86 stars 28 forks source link

[Snyk] Security upgrade video.js from 7.11.8 to 7.14.3 #210

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-JS-VIDEOJS-1533429
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: video.js The new version differs by 68 commits.
  • 3777f94 7.14.3
  • b483a76 fix: don't add anchor to DOM for getAbsoluteURL (#7336)
  • b3acf66 fix: remove IE8 url parsing workaround (#7334)
  • bba6e17 7.14.2
  • 2990cc7 fix(dom): in removeClass, check element for null in case of a disposed player (#6701)
  • 9ef0c5a 7.14.1
  • fff0611 fix(package): update to VHS 2.9.2 (#7320)
  • 2360236 docs(react): Added a functional React component using React.useEffect (#7203)
  • 14da28d fix: remove loading spinner on ended (#7311)
  • 508a424 fix: all !important properties of vjs-lock-showing (#7312)
  • 3921b7f fix: properly return promise from requestFullscreen and exitFullscreen (#7299)
  • fab6e87 chore: use setup-node cache and remove individual cache step (#7310)
  • a8a5e02 7.14.0
  • c74c27d feat: add ended getter middleware (#7287)
  • 8caeda9 7.13.4
  • fbcfb7b fix(lang): add some translations to es.json (#6822)
  • f9fb1d3 fix: throw error on muted resolution rejection during autoplay (#7293)
  • 0f70787 fix(lang): improve Hungarian translation (#7289)
  • a221be1 fix(event): event polyfill detection compatibility with react-native-web (#7286)
  • 4cecbda chore: add a code coverage ci workflow (#7282)
  • 9cfc15c 7.13.3
  • 4b50f82 chore: republish with VHS 2.9.1
  • a5f40d0 7.13.2
  • cee5fa3 fix(package): update to VHS 2.9.1 (#7284)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic