Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @primer/react from 35.26.1 to 35.27.0 #39

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

skemex
Copy link
Owner

@skemex skemex commented May 13, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
No No Known Exploit
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @primer/react The new version differs by 66 commits.
  • 2a8190a Version Packages (#3493)
  • 90bb7c9 Fix: Typo on Primer CSS link in 'getting-started.md' (#3572)
  • 9b03a0b chore(deps-dev): bump mdast-util-mdx from 2.0.1 to 3.0.0 (#3577)
  • 1fd9bc5 chore(deps-dev): bump @ testing-library/jest-dom from 5.16.5 to 5.17.0 (#3576)
  • 5e65520 Add truncation features to the LabelGroup component (#3264)
  • d8bbbb3 Revert "Upgrade styled-components to v5 (#3397)" (#3567)
  • a90350c Styled component bug cleanup (#3540)
  • 7716b31 Take the listing html structure back to its original structure (#3559)
  • 430a203 fix(PageLayout): Remove `warning` for the deprecated `position` prop (#3545)
  • 397938d Upgrade styled-components to v5 (#3397)
  • 5379184 Update `useSyntheticChange` to only call `execCommand` if input is focused (#3562)
  • 7ef802e Prevents body scroll when Dialog is open (#3547)
  • 6c9c3df Fix source links (#3560)
  • ab2ecfb chore(deps-dev): bump @ babel/preset-typescript from 7.21.5 to 7.22.5 (#3550)
  • 158b905 Fix Storybook Axe issues (#3555)
  • c736e8e 3003 autocomplete when in dialog intercepts escape keypresses and click outside (#3087)
  • ddf8ebf chore(deps-dev): bump @ babel/preset-react from 7.18.6 to 7.22.5 (#3551)
  • dbbc91e chore(deps-dev): bump jest and @ types/jest (#3553)
  • 3db1f91 Stories: Add reproduction for conditional Dialog.Footer bug (#3546)
  • 02d806f chore(deps): update storybook deps to 7.1 (#3543)
  • cf9d8a5 Add aria attributes to the progress bar (#3517)
  • feb81e7 chore(deps): remove chromatic from deps (#3529)
  • 33b6055 Fixed: Ensure Header component uses proper semantic header HTML tag (#3533)
  • 311c8c9 [checkbox] Show Checkmark to users with reduced-motion enabled (#3537)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled resource consumption

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants