Skip to content
This repository was archived by the owner on Mar 13, 2025. It is now read-only.

[Snyk] Fix for 1 vulnerabilities #29

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-NODEFETCH-2342118
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: isomorphic-fetch The new version differs by 12 commits.
  • fc5e0d0 3.0.0
  • 496fa43 Add version that was previously uncomitted to the package.json due to the previous release process
  • 9f5a8b6 Add a list of alternatives
  • 49280e6 Resolve minor security issue
  • 0f5edd0 Explain why Isomorphic Fetch is needed in docs (#135)
  • e32b006 Fix travis (#190)
  • db0aa8c Update to latest version
  • 8bf02c4 Bump node-fetch from 1.7.3 to 2.6.1 (#189)
  • 89c7e70 Merge pull request #93 from paulmelnikow/fetch_ponyfill
  • 25e3cab Add link to fetch-ponyfill
  • 8d33aba Merge pull request #90 from josiah0/update-lintspaces-cli
  • c22fcda Update lintspaces-cli

See the full diff

Package name: react-tag-input The new version differs by 59 commits.
  • 0b3fb4b Add yarn.lock in .gitignore
  • 0b23a1e build: reduce bundle size by 60%, 29.4KB => 11.84KB(gzipped)
  • 2bccbb9 chore(package): Update prettier to the latest version 🚀 (#468)
  • f3f7c01 fix: Remove the call for more contributors. Fix #197 (#466)
  • 503f0a0 chore(package): Update eslint-plugin-react to the latest version 🚀 (#462)
  • 13b6da7 chore(package):Update eslint to the latest version 🚀 (#463)
  • c11cd76 chore(package): Update sinon to the latest version 🚀 (#464)
  • a331566 fix: Remove import '../styles/react-tags.scss' and add inline style
  • 5d890a8 fix: Update class (#456)
  • aa5797c feat: Add custom suggestion as a render prop (#450)
  • 885fbed chore(package):Update eslint-plugin-jest to the latest version 🚀 (#459)
  • 2f9536c chore(package): Update eslint-plugin-react to the latest version 🚀 (#457)
  • 8bc64af Added custom styling certain tags (#453)
  • b05103d chore(package): Update css-loader to the latest version 🚀 (#445)
  • c2655cf chore(package): Update eslint-plugin-jest to the latest version 🚀 (#442)
  • 4ba802a chore(package): Update core-js to the latest version 🚀 (#443)
  • 9705964 chore:(package): Update prettier to the latest version 🚀 (#440)
  • d39e6fd Fix: Escape suggestions before including them in HTML (#414)
  • 6c42f92 chore(package): Update npm-run-all to the latest version 🚀 (#438)
  • 7207a2a fix: maxLength issue on pasting text (#426)
  • 8117c83 chore(package): Update raf to the latest version 🚀 (#433)
  • a83acd9 fix(ReactTags.js): Add default value of tags
  • d24fe45 Fix(ReactTags): Remove UNSAFE component lifecycles
  • f8de725 feat: Making drag and drop optional

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant