Skip to content

Conversation

div1127
Copy link

@div1127 div1127 commented Oct 20, 2024

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • frontend/package.json
    • frontend/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 498/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 2.1
Regular Expression Denial of Service (ReDoS)
SNYK-JS-VUE-8219889
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: bootstrap-vue The new version differs by 250 commits.
  • 78ff0c5 chore: importdoc mising closing single quotes
  • 3d269e7 chore: add sr-only text for home link in nav
  • 76d32f0 enable font-smoothing for docs
  • 63c2b90 sexy logo flip
  • d338ffe fix imports
  • f23706b update nav
  • 2a57647 update dependencies
  • 5c4bc2a update docs
  • 945288d chore: update changelog
  • 7e4dd97 docs(link): Document b-link component (#1294)
  • 991ac8c docs: typo in list-group docs (#1290)
  • c928ff5 chore: Update changelog
  • c6d3642 feat(tabs): New props for adding classes to nav tab (#1289)
  • c9a8144 docs(modal): document the `busy`, `ok-disabled` and `cancel-disabled` props
  • 53cfa08 chore: Update image test fixture
  • e51fc96 Update pagination.html
  • 036681d docs: Update astarter templtes
  • 2f99189 docs: Update importdoc.vue component
  • 8a5df82 chore: Update changelog
  • 1f1064f fix(progress): Bootstrap V4.beta.2 missing progress bar transition
  • 4b73c25 chore: update changelog
  • bd4c3c3 perf(input-group): convert to functional component (#1288)
  • a84c14b test(input-group): create basic tests for input-group (#1287)
  • c65798a chore: Update changelog

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

…nerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-VUE-8219889
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants