Skip to content

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Feb 28, 2023

Bumps @primer/react from 34.7.1 to 35.20.0.

Release notes

Sourced from @​primer/react's releases.

v35.20.0

Minor Changes

  • 5967b0a9 Thanks @​broccolinisoup! - Issue a deprecation notice for UnderlineNav v1

  • #2815 74df59c4 Thanks @​mperrotti! - Addresses feedback from the accessibility team about our SegmentedControl component. These changes include an update to ActionMenu that allows u to specify the ID of the DOM node that labels the menu.

  • #2768 5055b91b Thanks @​green6erry! - Confine Heading as prop to header element types

  • #2903 13651ba1 Thanks @​colebemis! - TreeView promoted to beta status. You can now import it from the main bundle instead of /drafts:

    - import {TreeView} from '@primer/react/drafts'
    + import {TreeView} from '@primer/react'

Patch Changes

v35.19.0

... (truncated)

Changelog

Sourced from @​primer/react's changelog.

35.20.0

Minor Changes

  • 5967b0a9 Thanks @​broccolinisoup! - Issue a deprecation notice for UnderlineNav v1

  • #2815 74df59c4 Thanks @​mperrotti! - Addresses feedback from the accessibility team about our SegmentedControl component. These changes include an update to ActionMenu that allows u to specify the ID of the DOM node that labels the menu.

  • #2768 5055b91b Thanks @​green6erry! - Confine Heading as prop to header element types

  • #2903 13651ba1 Thanks @​colebemis! - TreeView promoted to beta status. You can now import it from the main bundle instead of /drafts:

    - import {TreeView} from '@primer/react/drafts'
    + import {TreeView} from '@primer/react'

Patch Changes

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@primer/react](https://github.com/primer/react) from 34.7.1 to 35.20.0.
- [Release notes](https://github.com/primer/react/releases)
- [Changelog](https://github.com/primer/react/blob/main/CHANGELOG.md)
- [Commits](primer/react@v34.7.1...v35.20.0)

---
updated-dependencies:
- dependency-name: "@primer/react"
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 28, 2023
@guardrails
Copy link

guardrails bot commented Feb 28, 2023

⚠️ We detected 41 security issues in this pull request:

Vulnerable Libraries (41)
Severity Details
Medium pkg:npm/[email protected]@3.6.1 (t) - no patch available
High pkg:npm/[email protected]@11.1.4 (t) - no patch available
Medium pkg:npm/[email protected]@9.22.1 (t) upgrade to: 10.0.0
High pkg:npm/[email protected]@0.3.1 (t) - no patch available
Medium pkg:npm/[email protected]@2.1.3 (t) upgrade to: 2.1.4
Critical pkg:npm/[email protected]@1.2.3 (t) upgrade to: 2.0.3
Critical pkg:npm/[email protected]@2.0.15 (t) - no patch available
High pkg:npm/[email protected]@0.4.2 (t) - no patch available
Medium pkg:npm/@actions/[email protected]@1.6.0 (t) upgrade to: 1.9.1
Medium pkg:npm/[email protected]@1.11.0 (t) - no patch available
N/A pkg:npm/[email protected]@2.6.9 (t) upgrade to: 3.1.0
Critical pkg:npm/[email protected]@1.4.0 (t) upgrade to: 2.0.3
High pkg:npm/[email protected]@2.0.1 (t) - no patch available
High pkg:npm/[email protected]@6.1.0 (t) upgrade to: 10.2.7
High pkg:npm/[email protected]@1.0.1 (t) upgrade to: 2.2.2
Medium pkg:npm/[email protected]@2.6.12 (t) - no patch available
Medium pkg:npm/[email protected]@2.2.4 (t) - no patch available
Medium pkg:npm/[email protected]@10.7.0 (t) - no patch available
Low pkg:npm/[email protected]@2.6.7 (t) - no patch available
Critical pkg:npm/[email protected]@1.7.2 (t) upgrade to: 1.7.3
Medium pkg:npm/[email protected]@12.0.3 (t) upgrade to: 12.1.0,11.8.5
High pkg:npm/[email protected]@2.2.0 (t) upgrade to: 2.2.2
Critical pkg:npm/[email protected]@6.9.6 (t) - no patch available
Medium pkg:npm/[email protected]@17.0.2 (t) - no patch available
High pkg:npm/[email protected]@9.0.0 (t) - no patch available
High pkg:npm/[email protected]@0.8.5 (t) - no patch available
High pkg:npm/[email protected]@4.1.0 (t) upgrade to: 4.1.1,4.1.1
Critical pkg:npm/[email protected]@6.9.3 (t) - no patch available
High pkg:npm/[email protected]@7.0.2 (t) upgrade to: 10.2.7
Medium pkg:npm/@sideway/[email protected]@3.0.0 (t) upgrade to: 3.0.1
Medium pkg:npm/[email protected]@11.8.2 (t) - no patch available
High pkg:npm/[email protected]@1.5.0 (t) - no patch available
Medium pkg:npm/[email protected]@5.0.0 (t) - no patch available
High pkg:npm/[email protected]@3.0.4 (t) upgrade to: 3.0.5
Medium pkg:npm/[email protected]@6.2.2 (t) - no patch available
Medium pkg:npm/[email protected]@2.2.0 (t) - no patch available
High pkg:npm/[email protected]@1.27.0 (t) - no patch available
Medium pkg:npm/[email protected]@4.17.2 (t) - no patch available
High pkg:npm/[email protected]@5.0.2 (t) - no patch available
Medium pkg:npm/[email protected]@3.2.8 (t) - no patch available
Medium pkg:npm/[email protected]@9.6.0 (t) - no patch available

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants