[Snyk] Fix for 22 vulnerabilities - #480
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-AXIOS-15252993 - https://snyk.io/vuln/SNYK-JS-AXIOS-16298058 - https://snyk.io/vuln/SNYK-JS-AXIOS-16299923 - https://snyk.io/vuln/SNYK-JS-AXIOS-17172681 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18313044 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280 - https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-18854715 - https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-18856271 - https://snyk.io/vuln/SNYK-JS-JSYAML-17900054 - https://snyk.io/vuln/SNYK-JS-JSYAML-18593780 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-15309438 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-15353389 - https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789767 - https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789769 - https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789771 - https://snyk.io/vuln/SNYK-JS-NODEFORGE-15789773 - https://snyk.io/vuln/SNYK-JS-QS-14724253 - https://snyk.io/vuln/SNYK-JS-SHELLQUOTE-16799355 - https://snyk.io/vuln/SNYK-JS-SHELLQUOTE-17457810 - https://snyk.io/vuln/SNYK-JS-TMP-16881240 - https://snyk.io/vuln/SNYK-JS-TMP-17315641 - https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-570062
|
This upgrade contains major breaking changes, primarily from the react-scripts: 3.0.1 → 5.0.0 (HIGH RISK)This is a two-step major version upgrade (v3 → v4 → v5) with significant breaking changes at each step. It introduces modern tooling but requires careful migration. Key Breaking Changes:
Recommendation:
axios: 0.21.4 → 0.32.0 (LOW RISK)This is a minor version upgrade. While the version range is wide, the changes primarily consist of security fixes and patches. Version 0.32.0 specifically addresses several vulnerabilities related to proxy handling and regular expression denial of service. For most use cases, this upgrade should not introduce functional breaking changes. Source: React Scripts v4 Changelog, React Scripts v5 Release Notes
|
Snyk has created this PR to fix 22 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-AXIOS-15252993
SNYK-JS-AXIOS-16298058
SNYK-JS-AXIOS-16299923
SNYK-JS-AXIOS-17172681
SNYK-JS-BRACEEXPANSION-18313044
SNYK-JS-BRACEEXPANSION-18512280
SNYK-JS-BROWSERSLIST-18854715
SNYK-JS-BROWSERSLIST-18856271
SNYK-JS-JSYAML-17900054
SNYK-JS-JSYAML-18593780
SNYK-JS-MINIMATCH-15309438
SNYK-JS-MINIMATCH-15353389
SNYK-JS-NODEFORGE-15789767
SNYK-JS-NODEFORGE-15789769
SNYK-JS-NODEFORGE-15789771
SNYK-JS-NODEFORGE-15789773
SNYK-JS-QS-14724253
SNYK-JS-SHELLQUOTE-16799355
SNYK-JS-SHELLQUOTE-17457810
SNYK-JS-TMP-16881240
SNYK-JS-TMP-17315641
SNYK-JS-SERIALIZEJAVASCRIPT-570062
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Prototype Pollution
🦉 Uncontrolled Recursion
🦉 Allocation of Resources Without Limits or Throttling
🦉 More lessons are available in Snyk Learn