Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , , , , , , , , , , , , , , , , , check-password-strength, chokidar, chrono-node, codemirror, diff, dompurify, electron, electron-dl, fs, fuse.js, graphology, ignore, interactjs, jszip, katex, mldoc, photoswipe, url, pixi.js, posthog-js, react-grid-layout, react-intersection-observer, react-textarea-autosize, react-transition-group, remove-accents, threads, yargs-parser #811

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Bad3r
Copy link
Owner

@Bad3r Bad3r commented Sep 17, 2024

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@capacitor/android
from 5.4.1 to 5.7.8 | 38 versions ahead of your current version | a month ago
on 2024-08-07
@capacitor/app
from 5.0.6 to 5.0.8 | 85 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/camera
from 5.0.7 to 5.0.10 | 67 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/clipboard
from 5.0.6 to 5.0.8 | 85 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/core
from 5.4.1 to 5.7.8 | 38 versions ahead of your current version | a month ago
on 2024-08-07
@capacitor/filesystem
from 5.1.4 to 5.2.2 | 37 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/haptics
from 5.0.6 to 5.0.8 | 85 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/ios
from 5.4.1 to 5.7.8 | 38 versions ahead of your current version | a month ago
on 2024-08-07
@capacitor/keyboard
from 5.0.6 to 5.0.9 | 87 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/share
from 5.0.6 to 5.0.8 | 85 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/splash-screen
from 5.0.6 to 5.0.8 | 85 versions ahead of your current version | 3 months ago
on 2024-06-13
@capacitor/status-bar
from 5.0.6 to 5.0.8 | 85 versions ahead of your current version | 3 months ago
on 2024-06-13
@capgo/capacitor-navigation-bar
from 6.0.6 to 6.1.42 | 49 versions ahead of your current version | 22 days ago
on 2024-08-26
@excalidraw/excalidraw
from 0.16.1 to 0.17.6 | 72 versions ahead of your current version | 5 months ago
on 2024-04-17
@highlightjs/cdn-assets
from 10.4.1 to 10.7.3 | 6 versions ahead of your current version | 3 years ago
on 2021-06-04
@logseq/react-tweet-embed
from 1.3.1-1 to 1.3.1 | 1 version ahead of your current version | 3 years ago
on 2022-02-18
@tippyjs/react
from 4.2.5 to 4.2.6 | 1 version ahead of your current version | 3 years ago
on 2021-10-29
check-password-strength
from 2.0.7 to 2.0.10 | 3 versions ahead of your current version | 6 months ago
on 2024-03-07
chokidar
from 3.5.1 to 3.6.0 | 3 versions ahead of your current version | 7 months ago
on 2024-02-06
chrono-node
from 2.2.4 to 2.7.6 | 33 versions ahead of your current version | 4 months ago
on 2024-06-01
codemirror
from 5.65.13 to 5.65.17 | 4 versions ahead of your current version | 2 months ago
on 2024-07-20
diff
from 5.0.0 to 5.2.0 | 2 versions ahead of your current version | 7 months ago
on 2024-02-12
dompurify
from 2.4.0 to 2.5.6 | 16 versions ahead of your current version | 2 months ago
on 2024-07-05
electron
from 28.3.1 to 28.3.3 | 2 versions ahead of your current version | 4 months ago
on 2024-05-23
electron-dl
from 3.3.0 to 3.5.2 | 6 versions ahead of your current version | 7 months ago
on 2024-02-03
fs
from 0.0.1-security to 0.0.2 | 1 version ahead of your current version | 10 years ago
on 2014-09-12
fuse.js
from 6.4.6 to 6.6.2 | 7 versions ahead of your current version | 2 years ago
on 2022-05-11
graphology
from 0.20.0 to 0.25.4 | 15 versions ahead of your current version | a year ago
on 2023-08-01
ignore
from 5.1.8 to 5.3.2 | 9 versions ahead of your current version | a month ago
on 2024-08-12
interactjs
from 1.10.19 to 1.10.27 | 8 versions ahead of your current version | 6 months ago
on 2024-03-28
jszip
from 3.8.0 to 3.10.1 | 4 versions ahead of your current version | 2 years ago
on 2022-08-02
katex
from 0.16.10 to 0.16.11 | 1 version ahead of your current version | 2 months ago
on 2024-07-02
mldoc
from 1.5.7 to 1.5.9 | 2 versions ahead of your current version | a month ago
on 2024-08-03
photoswipe
from 5.4.1 to 5.4.4 | 3 versions ahead of your current version | 4 months ago
on 2024-05-24
url
from 0.11.3 to 0.11.4 | 1 version ahead of your current version | 2 months ago
on 2024-07-26
pixi.js
from 6.2.0 to 6.5.10 | 22 versions ahead of your current version | a year ago
on 2023-07-06
posthog-js
from 1.10.2 to 1.158.1 | 487 versions ahead of your current version | 22 days ago
on 2024-08-26
react-grid-layout
from 0.16.6 to 0.18.3 | 6 versions ahead of your current version | 5 years ago
on 2020-03-16
react-intersection-observer
from 9.5.2 to 9.13.0 | 15 versions ahead of your current version | 2 months ago
on 2024-07-11
react-textarea-autosize
from 8.3.3 to 8.5.3 | 7 versions ahead of your current version | a year ago
on 2023-08-22
react-transition-group
from 4.3.0 to 4.4.5 | 6 versions ahead of your current version | 2 years ago
on 2022-08-01
remove-accents
from 0.4.2 to 0.5.0 | 3 versions ahead of your current version | a year ago
on 2023-08-08
threads
from 1.6.5 to 1.7.0 | 1 version ahead of your current version | 3 years ago
on 2021-09-25
yargs-parser
from 20.2.4 to 20.2.9 | 4 versions ahead of your current version | 3 years ago
on 2021-06-20

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Type Confusion
SNYK-JS-ELECTRON-6689290
484 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-6689293
484 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-6689295
484 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-6815427
484 No Known Exploit
high severity Use After Free
SNYK-JS-ELECTRON-6913435
484 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-POSTHOGJS-5595549
484 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-EXCALIDRAWEXCALIDRAW-6619754
484 Proof of Concept
medium severity Template Injection
SNYK-JS-DOMPURIFY-6474511
484 Proof of Concept

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - @capacitor/android from 5.4.1 to 5.7.8.
    See this package in yarn: 
  - @capacitor/app from 5.0.6 to 5.0.8.
    See this package in yarn: 
  - @capacitor/camera from 5.0.7 to 5.0.10.
    See this package in yarn: 
  - @capacitor/clipboard from 5.0.6 to 5.0.8.
    See this package in yarn: 
  - @capacitor/core from 5.4.1 to 5.7.8.
    See this package in yarn: 
  - @capacitor/filesystem from 5.1.4 to 5.2.2.
    See this package in yarn: 
  - @capacitor/haptics from 5.0.6 to 5.0.8.
    See this package in yarn: 
  - @capacitor/ios from 5.4.1 to 5.7.8.
    See this package in yarn: 
  - @capacitor/keyboard from 5.0.6 to 5.0.9.
    See this package in yarn: 
  - @capacitor/share from 5.0.6 to 5.0.8.
    See this package in yarn: 
  - @capacitor/splash-screen from 5.0.6 to 5.0.8.
    See this package in yarn: 
  - @capacitor/status-bar from 5.0.6 to 5.0.8.
    See this package in yarn: 
  - @capgo/capacitor-navigation-bar from 6.0.6 to 6.1.42.
    See this package in yarn: 
  - @excalidraw/excalidraw from 0.16.1 to 0.17.6.
    See this package in yarn: 
  - @highlightjs/cdn-assets from 10.4.1 to 10.7.3.
    See this package in yarn: 
  - @logseq/react-tweet-embed from 1.3.1-1 to 1.3.1.
    See this package in yarn: 
  - @tippyjs/react from 4.2.5 to 4.2.6.
    See this package in yarn: 
  - check-password-strength from 2.0.7 to 2.0.10.
    See this package in yarn: 
  - chokidar from 3.5.1 to 3.6.0.
    See this package in yarn: 
  - chrono-node from 2.2.4 to 2.7.6.
    See this package in yarn: 
  - codemirror from 5.65.13 to 5.65.17.
    See this package in yarn: 
  - diff from 5.0.0 to 5.2.0.
    See this package in yarn: 
  - dompurify from 2.4.0 to 2.5.6.
    See this package in yarn: 
  - electron from 28.3.1 to 28.3.3.
    See this package in yarn: 
  - electron-dl from 3.3.0 to 3.5.2.
    See this package in yarn: 
  - fs from 0.0.1-security to 0.0.2.
    See this package in yarn: 
  - fuse.js from 6.4.6 to 6.6.2.
    See this package in yarn: 
  - graphology from 0.20.0 to 0.25.4.
    See this package in yarn: 
  - ignore from 5.1.8 to 5.3.2.
    See this package in yarn: 
  - interactjs from 1.10.19 to 1.10.27.
    See this package in yarn: 
  - jszip from 3.8.0 to 3.10.1.
    See this package in yarn: 
  - katex from 0.16.10 to 0.16.11.
    See this package in yarn: 
  - mldoc from 1.5.7 to 1.5.9.
    See this package in yarn: 
  - photoswipe from 5.4.1 to 5.4.4.
    See this package in yarn: 
  - url from 0.11.3 to 0.11.4.
    See this package in yarn: 
  - pixi.js from 6.2.0 to 6.5.10.
    See this package in yarn: 
  - posthog-js from 1.10.2 to 1.158.1.
    See this package in yarn: 
  - react-grid-layout from 0.16.6 to 0.18.3.
    See this package in yarn: 
  - react-intersection-observer from 9.5.2 to 9.13.0.
    See this package in yarn: 
  - react-textarea-autosize from 8.3.3 to 8.5.3.
    See this package in yarn: 
  - react-transition-group from 4.3.0 to 4.4.5.
    See this package in yarn: 
  - remove-accents from 0.4.2 to 0.5.0.
    See this package in yarn: 
  - threads from 1.6.5 to 1.7.0.
    See this package in yarn: 
  - yargs-parser from 20.2.4 to 20.2.9.
    See this package in yarn: 

See this project in Snyk:
https://app.snyk.io/org/logseq-shared/project/5a3d2338-cdfe-4786-a6d7-222f2c01c29e?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants