[Snyk] Upgrade: , , vue, bootstrap, dropzone, jquery, jsdom, material-table, react-bootstrap, react-scripts, react-table, simplebar, styled-components #258
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@material-ui/core
from 4.11.0 to 4.12.4 | 11 versions ahead of your current version | 2 years ago
on 2022-04-03
@material-ui/icons
from 4.9.1 to 4.11.3 | 2 versions ahead of your current version | 2 years ago
on 2022-04-03
vue
from 2.6.12 to 2.7.16 | 41 versions ahead of your current version | 9 months ago
on 2023-12-24
bootstrap
from 4.5.3 to 4.6.2 | 3 versions ahead of your current version | 2 years ago
on 2022-07-19
dropzone
from 5.7.2 to 5.9.3 | 10 versions ahead of your current version | 3 years ago
on 2021-09-21
jquery
from 3.5.1 to 3.7.1 | 7 versions ahead of your current version | a year ago
on 2023-08-28
jsdom
from 16.4.0 to 16.7.0 | 6 versions ahead of your current version | 3 years ago
on 2021-08-01
material-table
from 1.69.1 to 1.69.3 | 2 versions ahead of your current version | 3 years ago
on 2021-04-21
react-bootstrap
from 1.4.0 to 1.6.8 | 15 versions ahead of your current version | 9 months ago
on 2023-12-22
react-scripts
from 4.0.0 to 4.0.3 | 3 versions ahead of your current version | 4 years ago
on 2021-02-22
react-table
from 7.6.2 to 7.8.0 | 3 versions ahead of your current version | 2 years ago
on 2022-05-16
simplebar
from 6.2.5 to 6.2.7 | 2 versions ahead of your current version | 3 months ago
on 2024-06-13
styled-components
from 5.2.1 to 5.3.11 | 16 versions ahead of your current version | a year ago
on 2023-05-26
Issues fixed by the recommended upgrade:
SNYK-JS-JSONSCHEMA-1920922
SNYK-JS-IMMER-1019369
SNYK-JS-QS-3153490
SNYK-JS-QS-3153490
SNYK-JS-IP-6240864
SNYK-JS-ASYNC-2441827
SNYK-JS-BODYPARSER-7926860
SNYK-JS-WS-7266574
SNYK-JS-WS-7266574
SNYK-JS-DNSPACKET-1293563
SNYK-JS-URLPARSE-2407770
SNYK-JS-EXPRESS-6474509
SNYK-JS-EXPRESS-7926867
SNYK-JS-REACTDEVUTILS-1083268
SNYK-JS-REQUEST-3361831
SNYK-JS-EVENTSOURCE-2823375
SNYK-JS-TOUGHCOOKIE-5672873
SNYK-JS-TOUGHCOOKIE-5672873
SNYK-JS-NANOID-2332193
SNYK-JS-WS-1296835
SNYK-JS-URLPARSE-1078283
SNYK-JS-URLPARSE-1533425
SNYK-JS-URLPARSE-2401205
SNYK-JS-URLPARSE-2407759
SNYK-JS-SEND-7926862
SNYK-JS-SERVESTATIC-7926865
SNYK-JS-BABELTRAVERSE-5962462
SNYK-JS-WS-1296835
SNYK-JS-URLPARSE-2412697
SNYK-JS-MINIMIST-2429795
npm:debug:20170905
npm:debug:20170905
Release notes
Package name: @material-ui/core
Package name: @material-ui/icons
Package name: vue
Package name: bootstrap
Highlights
color-adjust
withprint-color-adjust
in our Sass files as part of the Autoprefixer v10.4.6 issues. This should quiet the issues folks have seen from that dependency change. If you're using our distribution CSS files, likebootstrap.min.css
, you may still see the warning.small
and.small
to compute to a whole pixel value (was12.8px
and now is14px
).role
attributes.What's Changed
color-adjust
withprint-color-adjust
by @ AdrianCurtin in #36283role="group"
from some split drop* buttons by @ julien-deramond in #36254accessibility.md
by @ patrickhlauke in #36492New Contributors
Full Changelog: v4.6.1...v4.6.2
What's changed
divide()
function by @ mdo in #34571moz-focusring
by @ kremit in #32821SAFE_URL_PATTERN
regex for use with test method of regexes by @ nikonthethird in #33153sms
in theSAFE_URL_PATTERN
for sanitizer by @ XhmikosR in #35074select.form-control
by @ mdo in #33206add()
&subtract()
by @ ffoodd in #34047add()
andsubtract()
by @ ffoodd in #34432aria-haspopup
from dropdowns by @ patrickhlauke in #33624.dropdown-item
wrapped in<li>
tags by @ cpsievert in #33649vertical-align
in spinners by @ XhmikosR in #338070.x
with negative margins in utilities by @ k-utsumi in #33593thead
rule by @ coliff in #34426show
event disabling modals with fade class from being displayed again by @ alpadev in #34087Full changelog
v4.6.0...v4.6.1
Package name: dropzone
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Please check the changelog for a list of changes
Package name: jquery
https://blog.jquery.com/2023/08/28/jquery-3-7-1-released-reliable-table-row-dimensions/
https://blog.jquery.com/2023/05/11/jquery-3-7-0-released-staying-in-order/
https://blog.jquery.com/2023/03/08/jquery-3-6-4-released-selector-forgiveness/
https://blog.jquery.com/2022/12/20/jquery-3-6-3-released-a-quick-selector-fix/
https://blog.jquery.com/2022/12/13/jquery-3-6-2-released/
https://blog.jquery.com/2022/08/26/jquery-3-6-1-maintenance-release/
https://blog.jquery.com/2021/03/02/jquery-3-6-0-released/
3.5.1
Package name: jsdom
Package name: material-table
Package name: react-bootstrap
1.6.8 (2023-12-22)
Bug Fixes
1.6.7 (2023-05-03)
Bug Fixes
content
prop error (#6612) (3d1df53)Package name: react-scripts
Package name: simplebar
No content.
Package name: styled-components
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"","from":"material-ui/core","to":"material-ui/core"},{"name":"","from":"material-ui/icons","to":"material-ui/icons"},{"name":"vue","from":"2.6.12","to":"2.7.16"},{"name":"bootstrap","from":"4.5.3","to":"4.6.2"},{"name":"dropzone","from":"5.7.2","to":"5.9.3"},{"name":"jquery","from":"3.5.1","to":"3.7.1"},{"name":"jsdom","from":"16.4.0","to":"16.7.0"},{"name":"material-table","from":"1.69.1","to":"1.69.3"},{"name":"react-bootstrap","from":"1.4.0","to":"1.6.8"},{"name":"react-scripts","from":"4.0.0","to":"4.0.3"},{"name":"react-table","from":"7.6.2","to":"7.8.0"},{"name":"simplebar","from":"6.2.5","to":"6.2.7"},{"name":"styled-components","from":"5.2.1","to":"5.3.11"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-JSONSCHEMA-1920922","issue_id":"SNYK-JS-JSONSCHEMA-1920922","priority_score":644,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.6","score":430},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Prototype Pollution"},{"exploit_maturity":"proof-of-concept","id...