[Snyk] Upgrade react-markdown from 8.0.0 to 8.0.7 #327
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade react-markdown from 8.0.0 to 8.0.7.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-ANSIREGEX-1583908
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AXIOS-6032459
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AXIOS-6144788
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-BROWSERIFYSIGN-6037026
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-6141137
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-INFLIGHT-6095116
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SIDEWAYFORMULA-3317169
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-XML2JS-5414874
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AXIOS-6124857
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-BABELTRAVERSE-5962462
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-JPEGJS-2859218
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-GOT-2932019
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-GOT-2932019
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-HTTPCACHESEMANTICS-3248783
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: react-markdown
Perf
by @ wooorm in #738
Docs
by @ dlqqq in #736
Full Changelog: 8.0.6...8.0.7
33ab015
Update to TS 5by @ Methuselah96 in #734
Full Changelog: 8.0.5...8.0.6
Misc
node16
module resolution intsconfig.json
by @ ChristianMurphy in #723
plugins
deprecation messageby @ marc2332 in #719
defaultProps
by @ Lepozepo in #718
New Contributors
Full Changelog: 8.0.4...8.0.5
td
,th
propsby @ lucasassisrosa in #714
alt
onimg
in docsby @ cballenar in #692
Full Changelog: 8.0.3...8.0.4
by @ starpit in #683
Full Changelog: 8.0.2...8.0.3
react-is
by @ Methuselah96 in #676
Full Changelog: 8.0.1...8.0.2
by @ Methuselah96 in #675
Full Changelog: 8.0.0...8.0.1
What's Changed
cd845c9
Remove deprecatedplugins
option(migrate by renaming it to
remarkPlugins
)36e4916
Updateremark-rehype
, add support for passing it optionsby @ peolic in #669
(migrate by removing
remark-footnotes
and updatingremark-gfm
if you were using them, otherwise you shouldn’t notice this)Full Changelog: 7.1.2...8.0.0
Commit messages
Package name: react-markdown
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs