Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , , autoprefixer, axios #37

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

WontonSam
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@commercelayer/react-components
from 4.2.2 to 4.15.9 | 185 versions ahead of your current version | 23 days ago
on 2024-08-23
@tailwindcss/forms
from 0.4.1 to 0.5.7 | 8 versions ahead of your current version | 10 months ago
on 2023-11-10
autoprefixer
from 10.4.5 to 10.4.20 | 15 versions ahead of your current version | a month ago
on 2024-08-02
axios
from 0.26.1 to 0.28.1 | 5 versions ahead of your current version | 6 months ago
on 2024-03-28

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
676 Proof of Concept
high severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-7361793
676 Proof of Concept
high severity Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
676 Proof of Concept
Release notes
Package name: @commercelayer/react-components
  • 4.15.9 - 2024-08-23

    What's Changed

    🐛 Bug Fix

    • Update Order: Set customer address using the invertAddresses prop by @ acasazza in #574
    • Display Braintree 3DS Error Messages by @ acasazza in #575

    Full Changelog: v4.15.8...v4.15.9

  • 4.15.9-beta.3 - 2024-08-21

    Full Changelog: v4.15.9-beta.2...v4.15.9-beta.3

  • 4.15.9-beta.2 - 2024-08-14

    Full Changelog: v4.15.9-beta.1...v4.15.9-beta.2

  • 4.15.9-beta.1 - 2024-08-13

    Full Changelog: v4.15.9-beta.0...v4.15.9-beta.1

  • 4.15.9-beta.0 - 2024-08-12

    Full Changelog: v4.15.8...v4.15.9-beta.0

  • 4.15.8 - 2024-08-09

    What's Changed

    🐛 Bug Fix

    Full Changelog: v4.15.7...v4.15.8

  • 4.15.8-beta.1 - 2024-08-09

    Full Changelog: v4.15.8-beta.0...v4.15.8-beta.1

  • 4.15.8-beta.0 - 2024-08-08

    Full Changelog: v4.15.7...v4.15.8-beta.0

  • 4.15.7 - 2024-08-07

    What's Changed

    🐛 Bug Fix

    Full Changelog: v4.15.6...v4.15.7

  • 4.15.7-beta.1 - 2024-08-07

    Full Changelog: v4.15.7-beta.0...v4.15.7-beta.1

  • 4.15.7-beta.0 - 2024-08-06
  • 4.15.6 - 2024-08-04
  • 4.15.6-beta.0 - 2024-08-02
  • 4.15.5 - 2024-07-31
  • 4.15.5-beta.0 - 2024-07-31
  • 4.15.4 - 2024-07-31
  • 4.15.3 - 2024-07-30
  • 4.15.3-beta.3 - 2024-07-30
  • 4.15.3-beta.2 - 2024-07-30
  • 4.15.3-beta.1 - 2024-07-30
  • 4.15.3-beta.0 - 2024-07-30
  • 4.15.2 - 2024-07-29
  • 4.15.1 - 2024-07-25
  • 4.15.0 - 2024-07-25
  • 4.15.0-beta.3 - 2024-07-25
  • 4.15.0-beta.2 - 2024-07-19
  • 4.15.0-beta.1 - 2024-07-18
  • 4.15.0-beta.0 - 2024-07-16
  • 4.14.5 - 2024-07-12
  • 4.14.4 - 2024-07-12
  • 4.14.4-beta.0 - 2024-07-11
  • 4.14.3 - 2024-07-10
  • 4.14.3-beta.1 - 2024-07-09
  • 4.14.3-beta.0 - 2024-07-08
  • 4.14.2 - 2024-06-27
  • 4.14.1 - 2024-06-25
  • 4.14.0 - 2024-06-20
  • 4.13.6 - 2024-06-10
  • 4.13.6-beta.1 - 2024-05-29
  • 4.13.6-beta.0 - 2024-05-24
  • 4.13.5 - 2024-05-21
  • 4.13.5-beta.2 - 2024-05-20
  • 4.13.5-beta.1 - 2024-05-20
  • 4.13.5-beta.0 - 2024-05-16
  • 4.13.4 - 2024-05-15
  • 4.13.4-beta.0 - 2024-05-15
  • 4.13.3 - 2024-05-14
  • 4.13.2 - 2024-05-14
  • 4.13.1 - 2024-05-14
  • 4.13.1-beta.9 - 2024-05-14
  • 4.13.1-beta.8 - 2024-05-10
  • 4.13.1-beta.7 - 2024-05-09
  • 4.13.1-beta.6 - 2024-04-30
  • 4.13.1-beta.5 - 2024-04-22
  • 4.13.1-beta.4 - 2024-04-19
  • 4.13.1-beta.3 - 2024-04-19
  • 4.13.1-beta.2 - 2024-04-16
  • 4.13.1-beta.1 - 2024-04-15
  • 4.13.1-beta.0 - 2024-04-11
  • 4.13.0 - 2024-04-08
  • 4.12.0 - 2024-03-25
  • 4.12.0-beta.1 - 2024-03-22
  • 4.12.0-beta.0 - 2024-03-20
  • 4.11.3 - 2024-03-14
  • 4.11.3-beta.1 - 2024-03-14
  • 4.11.3-beta.0 - 2024-03-12
  • 4.11.2 - 2024-03-08
  • 4.11.2-beta.8 - 2024-03-07
  • 4.11.2-beta.7 - 2024-03-07
  • 4.11.2-beta.6 - 2024-03-07
  • 4.11.2-beta.5 - 2024-03-07
  • 4.11.2-beta.4 - 2024-03-07
  • 4.11.2-beta.3 - 2024-03-07
  • 4.11.2-beta.2 - 2024-03-06
  • 4.11.2-beta.1 - 2024-03-06
  • 4.11.2-beta.0 - 2024-03-05
  • 4.11.1 - 2024-03-05
  • 4.11.1-beta.3 - 2024-03-05
  • 4.11.1-beta.2 - 2024-03-04
  • 4.11.1-beta.1 - 2024-03-04
  • 4.11.0 - 2024-02-27
  • 4.10.2 - 2024-02-26
  • 4.10.1 - 2024-02-16
  • 4.10.0 - 2024-02-15
  • 4.10.0-beta.0 - 2024-02-07
  • 4.9.0 - 2024-02-05
  • 4.9.0-beta.4 - 2024-02-02
  • 4.9.0-beta.3 - 2024-01-30
  • 4.9.0-beta.2 - 2024-01-19
  • 4.9.0-beta.1 - 2024-01-18
  • 4.9.0-beta.0 - 2024-01-18
  • 4.8.8 - 2024-01-25
  • 4.8.7 - 2024-01-18
  • 4.8.6 - 2024-01-11
  • 4.8.6-beta.2 - 2024-01-11
  • 4.8.6-beta.1 - 2024-01-10
  • 4.8.6-beta.0 - 2024-01-09
  • 4.8.5 - 2024-01-04
  • 4.8.5-beta.0 - 2024-01-04
  • 4.8.4 - 2023-12-22
  • 4.8.4-beta.1 - 2024-01-03
  • 4.8.4-beta.0 - 2023-12-22
  • 4.8.3 - 2023-12-21
  • 4.8.2 - 2023-12-21
  • 4.8.1 - 2023-12-20
  • 4.8.1-beta.2 - 2023-12-20
  • 4.8.1-beta.1 - 2023-12-19
  • 4.8.1-beta.0 - 2023-12-18
  • 4.8.0 - 2023-12-11
  • 4.8.0-beta.4 - 2023-12-04
  • 4.8.0-beta.3 - 2023-11-20
  • 4.8.0-beta.2 - 2023-10-16
  • 4.8.0-beta.1 - 2023-10-11
  • 4.8.0-beta.0 - 2023-10-10
  • 4.7.11 - 2023-11-16
  • 4.7.10 - 2023-11-15
  • 4.7.9 - 2023-11-15
  • 4.7.9-beta.1 - 2023-11-13
  • 4.7.9-beta.0 - 2023-11-13
  • 4.7.8 - 2023-11-08
  • 4.7.7 - 2023-11-07
  • 4.7.7-beta.0 - 2023-11-06
  • 4.7.6 - 2023-11-03
  • 4.7.5 - 2023-11-02
  • 4.7.5-beta.3 - 2023-11-02
  • 4.7.5-beta.2 - 2023-11-02
  • 4.7.5-beta.1 - 2023-10-31
  • 4.7.5-beta.0 - 2023-10-31
  • 4.7.4 - 2023-10-25
  • 4.7.4-beta.0 - 2023-10-24
  • 4.7.3 - 2023-10-24
  • 4.7.3-beta.1 - 2023-10-23
  • 4.7.3-beta.0 - 2023-10-23
  • 4.7.2 - 2023-10-23
  • 4.7.2-beta.0 - 2023-10-17
  • 4.7.1 - 2023-10-13
  • 4.7.1-beta.0 - 2023-10-13
  • 4.7.0 - 2023-10-10
  • 4.6.0 - 2023-10-02
  • 4.6.0-beta.1 - 2023-09-29
  • 4.6.0-beta.0 - 2023-09-28
  • 4.5.2-beta.2 - 2023-09-21
  • 4.5.2-beta.1 - 2023-09-21
  • 4.5.2-beta.0 - 2023-09-21
  • 4.5.1 - 2023-09-12
  • 4.5.0-beta.16 - 2023-09-01
  • 4.5.0-beta.13 - 2023-08-21
  • 4.5.0-beta.12 - 2023-08-19
  • 4.5.0-beta.11 - 2023-08-18
  • 4.5.0-beta.10 - 2023-08-18
  • 4.5.0-beta.9 - 2023-08-17
  • 4.5.0-beta.8 - 2023-08-16
  • 4.5.0-beta.7 - 2023-08-10
  • 4.5.0-beta.6 - 2023-08-09
  • 4.5.0-beta.5 - 2023-08-08
  • 4.5.0-beta.4 - 2023-08-08
  • 4.5.0-beta.3 - 2023-08-01
  • 4.5.0-beta.2 - 2023-06-20
  • 4.5.0-beta.1 - 2023-06-19
  • 4.5.0-beta.0 - 2023-06-14
  • 4.4.4 - 2023-05-23
  • 4.4.4-beta.2 - 2023-05-23
  • 4.4.4-beta.0 - 2023-05-23
  • 4.4.3 - 2023-05-23
  • 4.4.2 - 2023-05-22
  • 4.4.1 - 2023-05-22
  • 4.4.0 - 2023-05-08
  • 4.4.0-beta.8 - 2023-04-28
  • 4.4.0-beta.7 - 2023-04-27
  • 4.4.0-beta.6 - 2023-04-27
  • 4.4.0-beta.5 - 2023-04-26
  • 4.4.0-beta.4 - 2023-04-21
  • 4.4.0-beta.2 - 2023-03-30
  • 4.3.6 - 2023-05-24
  • 4.3.5 - 2023-03-27
  • 4.3.5-beta.1 - 2023-03-27
  • 4.3.5-beta.0 - 2023-03-24
  • 4.3.4 - 2023-03-23
  • 4.3.3 - 2023-03-22
  • 4.3.2 - 2023-03-20
  • 4.3.1 - 2023-03-10
  • 4.3.0 - 2023-03-10
  • 4.2.3-beta.2 - 2023-03-09
  • 4.2.3-beta.1 - 2023-03-07
  • 4.2.3-beta.0 - 2023-02-22
  • 4.2.2 - 2023-02-08
from @commercelayer/react-components GitHub release notes
Package name: @tailwindcss/forms
  • 0.5.7 - 2023-11-10

    Fixed

    • Use normal checkbox and radio appearance in forced-colors mode (#152)
  • 0.5.6 - 2023-08-28

    Fixed

    • Fix date time bottom spacing on MacOS Safari (#146)
  • 0.5.5 - 2023-08-22

    Fixed

    • Fix text alignment on date and time inputs on iOS (#144)
  • 0.5.4 - 2023-07-13

    Fixed

    • Remove chevron for selects with a non-default size (#137)
    • Allow for without type (#141)
  • 0.5.3 - 2022-09-02

    Fixed

    • Update TypeScript types (#126)
  • 0.5.2 - 2022-05-18

    Added

    • Add TypeScript type declarations (#118)
  • 0.5.1 - 2022-05-03

    Fixed

    • Remove duplicate outline property (#116)
    • Fix autoprefixer warning about color-adjust (#115)
  • 0.5.0 - 2022-03-02

    Changed

    • Generate both global styles and classes by default (#71)
  • 0.4.1 - 2022-03-02
from @tailwindcss/forms GitHub release notes
Package name: autoprefixer
  • 10.4.20 - 2024-08-02
    • Fixed fit-content prefix for Firefox.
  • 10.4.19 - 2024-03-20
    • Removed end value has mixed support, consider using flex-end warning since end/start now have good support.
  • 10.4.18 - 2024-03-01
    • Fixed removing -webkit-box-orient on -webkit-line-clamp (@ Goodwine).
  • 10.4.17 - 2024-01-17
    • Fixed user-select: contain prefixes.
  • 10.4.16 - 2023-09-20
  • 10.4.15 - 2023-08-13
  • 10.4.14 - 2023-03-09
    • Improved startup time and reduced JS bundle size (by @ Knagis).
  • 10.4.13 - 2022-10-27
    • Fixed missed prefixes on vendor prefixes in name of CSS Custom Property.
  • 10.4.12 - 2022-09-20
    • Fixed support of unit-less zero angle in backgrounds (by @ yisibl).
  • 10.4.11 - 2022-09-14
    • Fixed text-decoration prefixes by moving to MDN data (by @ romainmenke).
  • 10.4.10 - 2022-09-13
  • 10.4.9 - 2022-09-11
  • 10.4.8 - 2022-07-29
  • 10.4.7 - 2022-05-02
  • 10.4.6 - 2022-05-01
  • 10.4.5 - 2022-04-23
from autoprefixer GitHub release notes
Package name: axios
  • 0.28.1 - 2024-03-28

    Release notes:

    Release notes:

    Bug Fixes

    • fix(backport): custom params serializer support (#6263)
    • fix(backport): uncaught ReferenceError req is not defined (#6307)
  • 0.28.0 - 2024-02-12

    Release notes:

    Bug Fixes

    Backports from v1.x:

    • Allow null indexes on formSerializer and paramsSerializer v0.x (#4961)
    • Fixing content-type header repeated #4745
    • Fixed timeout error message for HTTP 4738
    • Added axios.formToJSON method (#4735)
    • URL params serializer (#4734)
    • Fixed toFormData Blob issue on node>v17 #4728
    • Adding types for progress event callbacks #4675
    • Fixed max body length defaults #4731
    • Added data URL support for node.js (#4725)
    • Added isCancel type assert (#4293)
    • Added the ability for the url-encoded-form serializer to respect the formSerializer config (#4721)
    • Add string[] to AxiosRequestHeaders type (#4322)
    • Allow type definition for axios instance methods (#4224)
    • Fixed AxiosError stack capturing; (#4718)
    • Fixed AxiosError status code type; (#4717)
    • Adding Canceler parameters config and request (#4711)
    • fix(types): allow to specify partial default headers for instance creation (#4185)
    • Added blob to the list of protocols supported by the browser (#4678)
    • Fixing Z_BUF_ERROR when no content (#4701)
    • Fixed race condition on immediate requests cancellation (#4261)
    • Added a clear() function to the request and response interceptors object so a user can ensure that all interceptors have been removed from an Axios instance #4248
    • Added generic AxiosAbortSignal TS interface to avoid importing AbortController polyfill (#4229)
    • Fix TS definition for AxiosRequestTransformer (#4201)
    • Use type alias instead of interface for AxiosPromise (#4505)
    • Include request and config when creating a CanceledError instance (#4659)
    • Added generic TS types for the exposed toFormData helper (#4668)
    • Optimized the code that checks cancellation (#4587)
    • Replaced webpack with rollup (#4596)
    • Added stack trace to AxiosError (#4624)
    • Updated AxiosError.config to be optional in the type definition (#4665)
    • Removed incorrect argument for NetworkError constructor (#4656)
  • 0.27.2 - 2022-04-27
  • 0.27.1 - 2022-04-26
  • 0.27.0 - 2022-04-25
  • 0.26.1 - 2022-03-09
from axios GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - @commercelayer/react-components from 4.2.2 to 4.15.9.
    See this package in npm: https://www.npmjs.com/package/@commercelayer/react-components
  - @tailwindcss/forms from 0.4.1 to 0.5.7.
    See this package in npm: https://www.npmjs.com/package/@tailwindcss/forms
  - autoprefixer from 10.4.5 to 10.4.20.
    See this package in npm: https://www.npmjs.com/package/autoprefixer
  - axios from 0.26.1 to 0.28.1.
    See this package in npm: https://www.npmjs.com/package/axios

See this project in Snyk:
https://app.snyk.io/org/googlecloud-fD9E4u83kGB6j2zHM2NDFc/project/27a7ceba-d8f5-419f-a07a-b5c6d66a2a70?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

google-cla bot commented Sep 15, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants