Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: react, react-dom, body-parser, express, redux-thunk, sanitize-html #61

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

s-w-high
Copy link
Owner

@s-w-high s-w-high commented Sep 7, 2024

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

react
from 15.6.2 to 15.7.0 | 1 version ahead of your current version | 4 years ago
on 2020-10-14
react-dom
from 15.6.2 to 15.7.0 | 1 version ahead of your current version | 4 years ago
on 2020-10-14
body-parser
from 1.19.0 to 1.20.2 | 5 versions ahead of your current version | 2 years ago
on 2023-02-22
express
from 4.17.1 to 4.19.2 | 9 versions ahead of your current version | 5 months ago
on 2024-03-25
redux-thunk
from 2.3.0 to 2.4.2 | 3 versions ahead of your current version | 2 years ago
on 2022-11-04
sanitize-html
from 1.27.4 to 1.27.5 | 1 version ahead of your current version | 4 years ago
on 2020-09-23

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Poisoning
SNYK-JS-QS-3153490
519 Proof of Concept
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
519 No Known Exploit
Release notes
Package name: react from react GitHub release notes
Package name: react-dom from react-dom GitHub release notes
Package name: body-parser from body-parser GitHub release notes
Package name: express from express GitHub release notes
Package name: redux-thunk
  • 2.4.2 - 2022-11-04

    This release removes an unused TS type that caused errors when users were type-checking libraries in node_modules.

    What's Changed

    Full Changelog: v2.4.1...v2.4.2

  • 2.4.1 - 2021-11-26

    This release adds an explicit plain action overload to the ThunkDispatch TS type to better handle inference of the return value in some cases.

    What's Changed

    Full Changelog: v2.4.0...v2.4.1

  • 2.4.0 - 2021-10-26

    This very overdue release makes several major improvements to the TypeScript types, and converts the actual source to TypeScript. Sorry for the delay!

    Changelog

    TypeScript Improvements

    This release fixes several outstanding issues that had been reported with the types. An extra overload has been added to let TS correctly understand some generically-typed values being passed to dispatch, and the overloads have been reworked for additional compatibility.

    There's also a new ThunkActionDispatch type that can be used to represent how bindActionCreators turns bound thunks into (arg) => thunkReturnValue.

    Additionally, all of the generic args have been giving meaningful names instead of one-letter abbreviations (S -> State, E -> ExtraArgument, etc), and we've added descriptive comments in the type definitions for clarity.

    Optional Global Dispatch Type Extension

    Most Redux apps have the thunk middleware enabled, but the default Dispatch and bindActionCreator types only know about the standard behavior of a basic Redux store without any middleware. The thunk middleware types add to that type behavior, so that Dispatch knows dispatching a thunk can actually return a value such as a Promise.

    We generally recommend inferring the type of dispatch and using that to create reusable types, including creating pre-typed hooks. However, some users may prefer to globally augment the Dispatch type to always use the additional thunk behavior.

    You can now import 'redux-thunk/extend-redux' to globally augment the Dispatch type as an opt-in change in behavior.

    Codebase Converted to TypeScript

    We've gone ahead and converted the actual source to TS. Since the source was only 15-ish lines to begin with, most of the "conversion" time was just trying to convince TS that assigning thunk.extraArgument = createThunkMiddleware was a legal operation :)

    We also updated the build tooling:

    • Babel updates
    • Rollup for the UMDs instead of Webpack
    • Github Actions for CI instead of Travis

    Finally, the README has been updated with newer instructions and usage information.

    What's Changed

    New Contributors

Snyk has created this PR to upgrade:
  - react from 15.6.2 to 15.7.0.
    See this package in npm: https://www.npmjs.com/package/react
  - react-dom from 15.6.2 to 15.7.0.
    See this package in npm: https://www.npmjs.com/package/react-dom
  - body-parser from 1.19.0 to 1.20.2.
    See this package in npm: https://www.npmjs.com/package/body-parser
  - express from 4.17.1 to 4.19.2.
    See this package in npm: https://www.npmjs.com/package/express
  - redux-thunk from 2.3.0 to 2.4.2.
    See this package in npm: https://www.npmjs.com/package/redux-thunk
  - sanitize-html from 1.27.4 to 1.27.5.
    See this package in npm: https://www.npmjs.com/package/sanitize-html

See this project in Snyk:
https://app.snyk.io/org/s.w.1213high/project/bd062ad4-dba4-4b60-9e77-8bbfd64807e9?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants