Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @clerk/remix from 4.0.0-beta.41 to 4.0.5 #23

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

stilt0n
Copy link
Owner

@stilt0n stilt0n commented May 8, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 631/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @clerk/remix The new version differs by 149 commits.
  • bb6a13f chore(repo): Version packages (#3336)
  • 9f7788b chore(repo): Format
  • 9d7a798 Translated some phrases from English to Italian (#3314)
  • df4525f feat(localizations): add PL translations (#3342)
  • 12f7849 fix(clerk-js): UI fixes for phone input and OTP inputs (#3302)
  • 27d6126 fix(clerk-js): Set eTLD+1 as the domain for client_uat (#3318)
  • 503673b fix(e2e): Fix integration test user deletion using email (#3346)
  • 9a05b09 fix(remix): Ensure headers with the same name do not get overwritten (#3345)
  • 63b6733 fix(nextjs): Apply response headers on redirect (#3344)
  • 1662aaa feat(clerk-react,shared): Add telemetry events for React hooks (#3341)
  • bfcc5de refactor(elements): Reduce Sign In reliance on `useEffect` [SDK-1714] (#3320)
  • 4f4375e chore(backend): Fix JWKS cache (#3321)
  • 7c6146e chore(elements): Fix typos in README (#3335)
  • 3caaf40 chore(eslint-config-custom): Set package.json properties for publishing (#3340)
  • 4ae79af fix(nextjs): url-based session syncing for auth() helpers (#3334)
  • 39265d9 chore(repo): Remove eslint-config-custom from react's deps (#3307)
  • f70c885 refactor(types,shared,elements): Assign `telemetry` property to main Clerk interface (#3329)
  • f5804a2 fix(shared): Detection of legacy host in `apiUrlFromPublishableKey` (#3333)
  • 98c0ce6 chore(repo): Version packages (#3328)
  • 216e343 chore(elements): Add moduleResolution note to readme (#3330)
  • 12300e4 fix(elements): Update sign-up resend type to match sign-in (#3327)
  • 69df1ab chore(repo): Version packages (#3319)
  • 526b8fb fix(elements): add clip-path rule to otp input (#3317)
  • c13b29c chore(repo): Version packages (#3313)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
Copy link

vercel bot commented May 8, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
grits-greenbeans-and-grandmothers ❌ Failed (Inspect) May 8, 2024 10:39pm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants