Skip to content

Conversation

AdamMurray
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
No No Known Exploit
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: nwb The new version differs by 250 commits.
  • ae86f9e Release v0.24.0
  • ae2b06a Don't ask a question about React compatibility when creating a Preact app, as preact/compat is now always available
  • f500d24 Doc tweaks
  • 88a3e52 Fix Inferno Babel config and re-enable the new app test
  • c13e27e Remove some missed mentions of *-test.js from the docs
  • d556bad Update Node version in CONTRIBUTING templates
  • 81122b4 Update Preact config for Preact X
  • 908267f Update CHANGES
  • 08b3de4 Add document language option (#520)
  • a296ab9 Merge pull request #515 from rrapiteanu/remove-scope-from-pkg-name
  • 8c83fe8 Merge branch 'master' into remove-scope-from-pkg-name
  • bf531d0 Merge pull request #527 from adamweeks/patch-1
  • 4453022 Update to Babel 7
  • ee6063d Update dependencies
  • 92a04c8 docs(FAQ): fix links
  • 3dbc36c Don't ignore devServer.host config when building the dev server URL
  • 71befb3 Update dependencies & drop support for Node.js 6
  • a9dd6f3 single quotes
  • f49e775 added tests
  • 7f04c6a added formatPackageName to remove scope from pkg.name for umd builds
  • ac2bf0b Update dependencies
  • d66162f Replace use of UglifyJsPlugin with TerserWebpackPlugin
  • 91ef6a0 Update dependencies
  • ed9680e Update dependencies

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled resource consumption

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants