react-molin
react-molin copied to clipboard
[Snyk] Fix for 1 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 551/1000 Why? Recently disclosed, Has a fix available, CVSS 5.3 |
Improper Input Validation SNYK-JS-POSTCSS-5926692 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: css-loader
The new version differs by 250 commits.- 1351e3a chore(release): 5.0.0
- 747d62b feat: allow named exports to have underscores in names (#1209)
- 7bfe85d chore(deps): update (#1208)
- b5c9379 feat: postcss@8 (#1204)
- 92fe103 docs: context is localIdentContext in README (#1202)
- e5a9272 chore(deps): update (#1203)
- 63b41be refactor: emoji deprecate
- 9f974be feat: reduce runtime
- d779eb1 feat: escape getLocalIdent by default (#1196)
- dd52931 feat: hide warning on no plugins (#1195)
- 52412f6 feat: improve error message
- 0f95841 feat: add fallback if custom getLocalIdent returns null (#1193)
- 2f1573f feat: auto enable icss modules
- df111b8 test: import with file protocol
- cfe669f refactor: remove icss option (#1189)
- 57eb505 chore(release): 4.3.0
- 3ddcc7b chore(deps): update deps (#1186)
- 88b8ddc fix: line breaks in `url` function
- 8b865fe test: source map (#1180)
- ec58a7c feat: the `importLoaders` can be `string` (#1178)
- df490c7 test: sass-loader next (#1177)
- 26a3062 chore(release): 4.2.2
- e42f046 refactor: improve sources handling in source maps (#1176)
- 4ce556a docs: fix type (#1174)
Package name: optimize-css-assets-webpack-plugin
The new version differs by 2 commits.Package name: svg-sprite-loader
The new version differs by 136 commits.- 3364249 2.0.1
- c21fc48 Update examples
- 6d202f2 Refactoring
- 03b2353 Use browser sprite by default
- e7e56fd Update README.md
- c237eec 2.0.0
- a2947e8 Add toc to readme
- 4dbf434 Merge branch '2.0'
- 36f48fe Update README
- 39a1922 Update 2.0 overview
- b2aa0ab Restore missed section in overview
- 85ce360 Add 2.0 overview
- ca52ed6 Update README
- fe5158c Update config
- 72b152d Fix bluebird warning (https://snyk.io/redirect/github/kisenka/svg-sprite-loader/issues/91#issuecomment-297690801)
- e5d2afc Runtime compat
- a7ef2e8 Update yarn lock
- f21f87b Update yarn lock
- d42e03a Update yarn lock
- f5066ff Update yarn lock
- dedbba6 Update webpack-toolkit
- e7c307b Update set-env script
- e1b9030 Update dependencies
- 1e3cc72 Refactoring
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: