Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: chalk, postcss, cssnano, eslint, git-parse, lunr, mustache, postcss-cli, simple-git, tailwindcss #21

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

WontonSam
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

Name Versions Released on

chalk
from 4.1.0 to 5.3.0 | 9 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-06-29
postcss
from 7.0.32 to 8.4.41 | 102 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-05
cssnano
from 4.1.10 to 7.0.5 | 53 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-09
eslint
from 5.16.0 to 9.9.0 | 143 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-09
git-parse
from 1.0.4 to 3.0.1 | 6 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 years ago
on 2022-11-09
lunr
from 2.3.8 to 2.3.9 | 1 version ahead of your current version | 4 years ago
on 2020-08-19
mustache
from 4.0.1 to 4.2.0 | 4 versions ahead of your current version | 3 years ago
on 2021-03-28
postcss-cli
from 7.1.1 to 11.0.0 | 13 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 9 months ago
on 2023-12-05
simple-git
from 2.7.2 to 3.25.0 | 89 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
on 2024-06-10
tailwindcss
from 1.4.6 to 3.4.10 | 180 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-13

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-Y18N-1021887
63 Proof of Concept
high severity Prototype Pollution
SNYK-JS-AJV-584908
63 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
63 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
63 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
63 Proof of Concept
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
63 Proof of Concept
high severity Command Injection
SNYK-JS-GITPARSE-1290380
63 Proof of Concept
high severity Code Injection
SNYK-JS-LODASH-1040724
63 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-567746
63 Proof of Concept
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
63 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
63 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
63 Proof of Concept
high severity Command Injection
SNYK-JS-SIMPLEGIT-2421199
63 Proof of Concept
high severity Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
SNYK-JS-SIMPLEGIT-2434306
63 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3112221
63 Proof of Concept
high severity Remote Code Execution (RCE)
SNYK-JS-SIMPLEGIT-3177391
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1090595
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1085627
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISSVG-1243891
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
63 Proof of Concept
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
63 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
63 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
63 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
63 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
63 Proof of Concept
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
63 No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
63 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
63 Proof of Concept
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
63 Proof of Concept
Release notes
Package name: chalk from chalk GitHub release notes
Package name: postcss
  • 8.4.41 - 2024-08-05
  • 8.4.40 - 2024-07-24
    • Moved to getter/setter in nodes types to help Sass team (by @ nex3).
  • 8.4.39 - 2024-06-29
  • 8.4.38 - 2024-03-20
  • 8.4.37 - 2024-03-19
    • Fixed original.column are not numbers error in another case.
  • 8.4.36 - 2024-03-17
    • Fixed original.column are not numbers error on broken previous source map.
  • 8.4.35 - 2024-02-07
  • 8.4.34 - 2024-02-05
  • 8.4.33 - 2024-01-04
  • 8.4.32 - 2023-12-02
  • 8.4.31 - 2023-09-28
  • 8.4.30 - 2023-09-18
  • 8.4.29 - 2023-08-29
  • 8.4.28 - 2023-08-15
  • 8.4.27 - 2023-07-21
  • 8.4.26 - 2023-07-13
  • 8.4.25 - 2023-07-06
  • 8.4.24 - 2023-05-28
  • 8.4.23 - 2023-04-19
  • 8.4.22 - 2023-04-16
  • 8.4.21 - 2023-01-06
  • 8.4.20 - 2022-12-11
  • 8.4.19 - 2022-11-10
  • 8.4.18 - 2022-10-12
  • 8.4.17 - 2022-09-30
  • 8.4.16 - 2022-08-06
  • 8.4.15 - 2022-08-06
  • 8.4.14 - 2022-05-18
  • 8.4.13 - 2022-04-30
  • 8.4.12 - 2022-03-16
  • 8.4.11 - 2022-03-15
  • 8.4.10 - 2022-03-15
  • 8.4.9 - 2022-03-15
  • 8.4.8 - 2022-03-07
  • 8.4.7 - 2022-02-24
  • 8.4.6 - 2022-02-01
  • 8.4.5 - 2021-12-13
  • 8.4.4 - 2021-11-27
  • 8.4.3 - 2021-11-26
  • 8.4.2 - 2021-11-26
  • 8.4.1 - 2021-11-24
  • 8.4.0 - 2021-11-24
  • 8.3.11 - 2021-10-21
  • 8.3.10 - 2021-10-20
  • 8.3.9 - 2021-10-04
  • 8.3.8 - 2021-09-25
  • 8.3.7 - 2021-09-22
  • 8.3.6 - 2021-07-21
  • 8.3.5 - 2021-06-17
  • 8.3.4 - 2021-06-14
  • 8.3.3 - 2021-06-14
  • 8.3.2 - 2021-06-11
  • 8.3.1 - 2021-06-09
  • 8.3.0 - 2021-05-21
  • 8.2.15 - 2021-05-10
  • 8.2.14 - 2021-05-05
  • 8.2.13 - 2021-04-26
  • 8.2.12 - 2021-04-22
  • 8.2.11 - 2021-04-22
  • 8.2.10 - 2021-04-11
  • 8.2.9 - 2021-03-30
  • 8.2.8 - 2021-03-09
  • 8.2.7 - 2021-03-03
  • 8.2.6 - 2021-02-10
  • 8.2.5 - 2021-02-06
  • 8.2.4 - 2021-01-09
  • 8.2.3 - 2021-01-07
  • 8.2.2 - 2020-12-29
  • 8.2.1 - 2020-12-09
  • 8.2.0 - 2020-12-08
  • 8.1.14 - 2020-12-04
  • 8.1.13 - 2020-12-03
  • 8.1.12 - 2020-12-03
  • 8.1.11 - 2020-12-03
  • 8.1.10 - 2020-11-23
  • 8.1.9 - 2020-11-21
  • 8.1.8 - 2020-11-19
  • 8.1.7 - 2020-11-10
  • 8.1.6 - 2020-11-05
  • 8.1.5 - 2020-11-05
  • 8.1.4 - 2020-10-24
  • 8.1.3 - 2020-10-23
  • 8.1.2 - 2020-10-19
  • 8.1.1 - 2020-09-28
  • 8.1.0 - 2020-09-26
  • 8.0.9 - 2020-09-23
  • 8.0.8 - 2020-09-23
  • 8.0.7 - 2020-09-22
  • 8.0.6 - 2020-09-20
  • 8.0.5 - 2020-09-17
  • 8.0.4 - 2020-09-16
  • 8.0.3 - 2020-09-15
  • 8.0.2 - 2020-09-15
  • 8.0.1 - 2020-09-15
  • 8.0.0 - 2020-09-15
  • 7.0.39 - 2021-10-04
  • 7.0.38 - 2021-09-25
  • 7.0.37 - 2021-09-25
  • 7.0.36 - 2021-06-11
  • 7.0.35 - 2020-09-28
  • 7.0.34 - 2020-09-17
  • 7.0.33 - 2020-09-16
  • 7.0.32 - 2020-06-02
from postcss GitHub release notes
Package name: cssnano
  • 7.0.5 - 2024-08-09
  • 7.0.4 - 2024-07-05

    stylehacks@7.0.4

  • 7.0.3 - 2024-06-19

    postcss-unique-selectors@7.0.3

  • 7.0.2 - 2024-06-05
  • 7.0.1 - 2024-04-26
  • 7.0.0 - 2024-04-24
  • 6.1.2 - 2024-03-25
  • 6.1.1 - 2024-03-20
  • 6.1.0 - 2024-03-06
  • 6.0.5 - 2024-02-24
  • 6.0.4 - 2024-02-22
  • 6.0.3 - 2024-01-03
  • 6.0.2 - 2023-12-14
  • 6.0.1 - 2023-04-30
  • 6.0.0 - 2023-03-27
  • 5.1.15 - 2023-02-15
  • 5.1.14 - 2022-10-28
  • 5.1.13 - 2022-08-12
  • 5.1.12 - 2022-06-18
  • 5.1.11 - 2022-06-03
  • 5.1.10 - 2022-05-29
  • 5.1.9 - 2022-05-20
  • 5.1.8 - 2022-05-16
  • 5.1.7 - 2022-04-01
  • 5.1.6 - 2022-04-01
  • 5.1.5 - 2022-03-21
  • 5.1.4 - 2022-03-13
  • 5.1.3 - 2022-03-11
  • 5.1.2 - 2022-03-10
  • 5.1.1 - 2022-03-08
  • 5.1.0 - 2022-03-01
  • 5.0.17 - 2022-02-07
  • 5.0.16 - 2022-01-23
  • 5.0.15 - 2022-01-07
  • 5.0.14 - 2021-12-20
  • 5.0.13 - 2021-12-15
  • 5.0.12 - 2021-11-27
  • 5.0.11 - 2021-11-16
  • 5.0.10 - 2021-11-06
  • 5.0.9 - 2021-11-02
  • 5.0.8 - 2021-08-18
  • 5.0.7 - 2021-07-21
  • 5.0.6 - 2021-06-10
  • 5.0.5 - 2021-05-28
  • 5.0.4 - 2021-05-21
  • 5.0.3 - 2021-05-19
  • 5.0.2 - 2021-04-28
  • 5.0.1 - 2021-04-13
  • 5.0.0 - 2021-04-10
  • 5.0.0-rc.2 - 2021-03-15
  • 5.0.0-rc.1 - 2021-03-05
  • 5.0.0-rc.0 - 2021-02-19
  • 4.1.11 - 2021-04-06
  • 4.1.10 - 2019-02-14
from cssnano GitHub release notes
Package name: eslint
  • 9.9.0 - 2024-08-09

    Features

    • 41d0206 feat: Add support for TS config files (#18134) (Arya Emami)
    • 3a4eaf9 feat: add suggestion to require-await to remove async keyword (#18716) (Dave)

    Documentation

    • 9fe068c docs: how to author plugins with configs that extend other configs (#18753) (Alec Gibson)
    • 48117b2 docs: add version support page in the side navbar (#18738) (Amaresh S M)
    • fec2951 docs: add version support page to the dropdown (#18730) (Amaresh S M)
    • 38a0661 docs: Fix typo (#18735) (Zaina Al Habash)
    • 3c32a9e docs: Update yarn command for creating ESLint config (#18739) (Temitope Ogunleye)
    • f9ac978 docs: Update README (GitHub Actions Bot)

    Chores

    • 461b2c3 chore: upgrade to @ eslint/js@9.9.0 (#18765) (Francesco Trotta)
    • 59dba1b chore: package.json update for @ eslint/js release (Jenkins)
    • fea8563 chore: update dependency @ eslint/core to ^0.3.0 (#18724) (renovate[bot])
    • aac191e chore: update dependency @ eslint/json to ^0.3.0 (#18760) (renovate[bot])
    • b97fa05 chore: update wdio dependencies for more stable tests (#18759) (Christian Bromann)
  • 9.8.0 - 2024-07-26

    Features

    • 13d0bd3 feat: Add and use SourceCode#getLoc/getRange (#18703) (Nicholas C. Zakas)

    Bug Fixes

    • ab0ff27 fix: Throw error when invalid flags passed (#18705) (Nicholas C. Zakas)
    • 70dc803 fix: basePath directory can never be ignored (#18711) (Milos Djermanovic)

    Documentation

    Build Related

    • 4514424 build: Enable JSON linting (#18681) (Nicholas C. Zakas)

    Chores

    • deee448 chore: upgrade to @ eslint/js@9.8.0 (#18720) (Francesco Trotta)
    • 4aaf2b3 chore: package.json update for @ eslint/js release (Jenkins)
    • 8e1a627 chore: update dependency @ eslint/core to ^0.2.0 (#18700) (renovate[bot])
  • 9.7.0 - 2024-07-12

    Features

    • 7bd9839 feat: add support for es2025 duplicate named capturing groups (#18630) (Yosuke Ota)
    • 1381394 feat: add regex option in no-restricted-imports (#18622) (Nitin Kumar)

    Bug Fixes

    • 14e9f81 fix: destructuring in catch clause in no-unused-vars (#18636) (Francesco Trotta)

    Documentation

    • 9f416db docs: Add Powered by Algolia label to the search. (#18633) (Amaresh S M)
    • c8d26cb docs: Open JS Foundation -> OpenJS Foundation (#18649) (Milos Djermanovic)
    • 6e79ac7 docs: loadESLint does not support option cwd (#18641) (Francesco Trotta)

    Chores

    • 793b718 chore: upgrade @ eslint/js@9.7.0 (#18680) (Francesco Trotta)
    • 7ed6f9a chore: package.json update for @ eslint/js release (Jenkins)
    • 7bcda76 refactor: Add type references (#18652) (Nicholas C. Zakas)
    • 51bf57c chore: add tech sponsors through actions (#18624) (Strek)
    • 6320732 refactor: don't use parent property in NodeEventGenerator (#18653) (Milos Djermanovic)
    • 9e6d640 refactor: move "Parsing error" prefix adding to Linter (#18650) (Milos Djermanovic)
  • 9.6.0 - 2024-06-28

    Features

    • e2b16e2 feat: Implement feature flags (#18516) (Nicholas C. Zakas)
    • 8824aa1 feat: add ecmaVersion: 2025, parsing duplicate named capturing groups (#18596) (Milos Djermanovic)

    Bug Fixes

    • 1613e2e fix: Allow escaping characters in config patterns on Windows (#18628) (Milos Djermanovic)
    • 21d3766 fix: no-unused-vars include caught errors pattern in report message (#18609) (Kirk Waiblinger)
    • d7a7736 fix: improve no-unused-vars message on unused caught errors (#18608) (Kirk Waiblinger)
    • f9e95d2 fix: correct locations of invalid /* eslint */ comments (#18593) (Milos Djermanovic)

    Documentation

    • 13dbecd docs: Limit search to just docs (#18627) (Nicholas C. Zakas)
    • 375227f docs: Update getting-started.md - add pnpm to init eslint config (#18599) (Kostiantyn Ochenash)
    • 44915bb docs: Update README (GitHub Actions Bot)
    • d50db7b docs: Update vscode-eslint info (#18595) (Nicholas C. Zakas)

    Chores

    • b15ee30 chore: upgrade @ eslint/js@9.6.0 (#18632) (Milos Djermanovic)
    • d655503 chore: package.json update for @ eslint/js release (Jenkins)
    • 7c78ad9 refactor: Use language.visitorKeys and check for non-JS SourceCode (#18625) (Nicholas C. Zakas)
    • 69ff64e refactor: Return value of applyInlineConfig() (#18623) (Nicholas C. Zakas)
    • d2d06f7 refactor: use / separator when adjusting ignorePatterns on Windows (#18613) (Milos Djermanovic)
    • 6421973 refactor: fix disable directives for languages with 0-based lines (#18605) (Milos Djermanovic)
    • 0a13539 refactor: Allow optional methods for languages (

Snyk has created this PR to upgrade:
  - chalk from 4.1.0 to 5.3.0.
    See this package in npm: https://www.npmjs.com/package/chalk
  - postcss from 7.0.32 to 8.4.41.
    See this package in npm: https://www.npmjs.com/package/postcss
  - cssnano from 4.1.10 to 7.0.5.
    See this package in npm: https://www.npmjs.com/package/cssnano
  - eslint from 5.16.0 to 9.9.0.
    See this package in npm: https://www.npmjs.com/package/eslint
  - git-parse from 1.0.4 to 3.0.1.
    See this package in npm: https://www.npmjs.com/package/git-parse
  - lunr from 2.3.8 to 2.3.9.
    See this package in npm: https://www.npmjs.com/package/lunr
  - mustache from 4.0.1 to 4.2.0.
    See this package in npm: https://www.npmjs.com/package/mustache
  - postcss-cli from 7.1.1 to 11.0.0.
    See this package in npm: https://www.npmjs.com/package/postcss-cli
  - simple-git from 2.7.2 to 3.25.0.
    See this package in npm: https://www.npmjs.com/package/simple-git
  - tailwindcss from 1.4.6 to 3.4.10.
    See this package in npm: https://www.npmjs.com/package/tailwindcss

See this project in Snyk:
https://app.snyk.io/org/cachiman/project/1747a2fb-43af-4fcf-b6a7-ec57cebd4d8a?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

google-cla bot commented Sep 9, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants