Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , , babel-jest, jest, vue, vue-template-compiler, , , , , eslint-plugin-vue, , , , , , , , , , , autoprefixer, core-js, eslint, eslint-config-prettier, eslint-plugin-nuxt, eslint-plugin-promise, lint-staged, msw, nuxt, pinia, postcss-html, prettier, stylelint, stylelint-config-recommended-vue, stylelint-config-standard, tailwindcss, ts-jest, vue-jest, vue-server-renderer, webpack #386

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

WontonSam
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

Name Versions Released on

@commitlint/cli
from 15.0.0 to 19.4.0 | 57 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-07
@commitlint/config-conventional
from 15.0.0 to 19.2.2 | 37 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 5 months ago
on 2024-04-14
babel-jest
from 27.5.1 to 29.7.0 | 48 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-09-12
jest
from 27.5.1 to 29.7.0 | 49 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-09-12
vue
from 2.7.14 to 3.4.38 | 219 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-15
vue-template-compiler
from 2.7.14 to 2.7.16 | 4 versions ahead of your current version | 9 months ago
on 2023-12-24
@babel/eslint-parser
from 7.19.1 to 7.25.1 | 26 versions ahead of your current version | 2 months ago
on 2024-07-28
@nuxt/types
from 2.15.8 to 2.18.1 | 11 versions ahead of your current version | 3 months ago
on 2024-06-28
@nuxt/typescript-build
from 3.0.1 to 3.0.2 | 1 version ahead of your current version | 10 months ago
on 2023-11-16
@nuxtjs/composition-api
from 0.33.1 to 0.34.0 | 1 version ahead of your current version | 5 months ago
on 2024-04-12
eslint-plugin-vue
from 8.7.1 to 9.27.0 | 41 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
on 2024-07-02
@nuxtjs/eslint-config-typescript
from 8.0.0 to 12.1.0 | 5 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-08-29
@nuxtjs/eslint-module
from 3.1.0 to 4.1.0 | 4 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
on 2023-05-18
@nuxtjs/storybook
from 4.3.2 to 8.2.0 | 17 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-17
@nuxtjs/stylelint-module
from 4.1.0 to 5.2.0 | 7 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 7 months ago
on 2024-02-06
@pinia/nuxt
from 0.2.1 to 0.5.4 | 20 versions ahead of your current version | a month ago
on 2024-08-21
@pinia/testing
from 0.0.12 to 0.1.5 | 11 versions ahead of your current version | a month ago
on 2024-08-06
@testing-library/jest-dom
from 5.16.5 to 6.5.0 | 23 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 24 days ago
on 2024-08-23
@testing-library/vue
from 5.9.0 to 8.1.0 | 21 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 4 months ago
on 2024-05-18
@types/jest
from 27.5.2 to 29.5.12 | 41 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 8 months ago
on 2024-02-01
@vue/test-utils
from 1.3.0 to 2.4.6 | 80 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 4 months ago
on 2024-05-07
autoprefixer
from 10.4.13 to 10.4.20 | 7 versions ahead of your current version | a month ago
on 2024-08-02
core-js
from 3.19.3 to 3.38.1 | 58 versions ahead of your current version | a month ago
on 2024-08-20
eslint
from 8.34.0 to 9.9.1 | 43 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 24 days ago
on 2024-08-23
eslint-config-prettier
from 8.6.0 to 9.1.0 | 6 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 9 months ago
on 2023-12-02
eslint-plugin-nuxt
from 3.2.0 to 4.0.0 | 1 version ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 years ago
on 2022-08-31
eslint-plugin-promise
from 6.1.1 to 7.1.0 | 8 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-06
lint-staged
from 12.5.0 to 15.2.9 | 30 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-13
msw
from 0.49.3 to 2.3.5 | 66 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-02
nuxt
from 2.15.8 to 3.13.0 | 77 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 25 days ago
on 2024-08-22
pinia
from 2.0.19 to 2.2.2 | 29 versions ahead of your current version | a month ago
on 2024-08-15
postcss-html
from 1.5.0 to 1.7.0 | 2 versions ahead of your current version | 4 months ago
on 2024-05-08
prettier
from 2.8.4 to 3.3.3 | 33 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 2 months ago
on 2024-07-13
stylelint
from 14.16.1 to 16.8.2 | 38 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-15
stylelint-config-recommended-vue
from 1.4.0 to 1.5.0 | 1 version ahead of your current version | a year ago
on 2023-07-10
stylelint-config-standard
from 24.0.0 to 36.0.1 | 14 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
on 2024-06-21
tailwindcss
from 3.2.6 to 3.4.10 | 20 versions ahead of your current version | a month ago
on 2024-08-13
ts-jest
from 27.1.1 to 29.2.5 | 37 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 24 days ago
on 2024-08-23
vue-jest
from 3.0.4 to 4.0.1 | 14 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | 4 years ago
on 2021-03-06
vue-server-renderer
from 2.7.14 to 2.7.16 | 4 versions ahead of your current version | 9 months ago
on 2023-12-24
webpack
from 4.46.0 to 5.94.0 | 242 versions ahead of your current version
⚠️ This is a major version upgrade, and may be a breaking change | a month ago
on 2024-08-22

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
124 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
124 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TRIM-1017038
124 Proof of Concept
high severity Denial of Service (DoS)
SNYK-JS-TRIMNEWLINES-1298042
124 No Known Exploit
high severity Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
124 No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
124 Proof of Concept
high severity Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
124 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
124 Proof of Concept
high severity Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
124 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-NUXT-7640972
124 Proof of Concept
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962463
124 Proof of Concept
high severity Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
124 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
124 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTMLMINIFIER-3091181
124 Proof of Concept
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
124 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-WEBPACK-7840298
124 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-WEBPACK-7840298
124 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
124 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
124 Proof of Concept
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
124 Proof of Concept
Release notes
Package name: @commitlint/cli from @commitlint/cli GitHub release notes
Package name: @commitlint/config-conventional
  • 19.2.2 - 2024-04-14

    19.2.2 (2024-04-14)

    Bug Fixes

    Chore

    New Contributors

    Full Changelog: v19.2.1...v19.2.2

  • 19.1.0 - 2024-03-12

    19.1.0 (2024-03-12)

    Bug Fixes

    Features

    Chore

    New Contributors

    Full Changelog: v19.0.3...v19.1.0

  • 19.0.3 - 2024-02-28

    19.0.3 (2024-02-28)

    Bug Fixes

    • fix: mark @ types/conventional-commits-parser as dep for @ commitlint/types by @ JounQin in #3944

    Full Changelog: v19.0.2...v19.0.3

  • 19.0.0 - 2024-02-27
  • 18.6.3 - 2024-03-11

    18.6.3 (2024-03-11)

    Bug Fixes

    Full Changelog: v18.6.2...v18.6.3

  • 18.6.2 - 2024-02-14
  • 18.6.1 - 2024-02-13
  • 18.6.0 - 2024-01-25
  • 18.5.0 - 2024-01-22
  • 18.4.4 - 2024-01-04
  • 18.4.3 - 2023-11-21
  • 18.4.2 - 2023-11-16
  • 18.4.0 - 2023-11-10
  • 18.1.0 - 2023-10-25
  • 18.0.0 - 2023-10-20
  • 17.8.1 - 2023-10-20
  • 17.8.0 - 2023-10-14
  • 17.7.0 - 2023-08-09
  • 17.6.7 - 2023-07-19
  • 17.6.6 - 2023-06-24
  • 17.6.5 - 2023-05-30
  • 17.6.3 - 2023-05-04
  • 17.6.1 - 2023-04-14
  • 17.6.0 - 2023-04-13
  • 17.4.4 - 2023-02-17
  • 17.4.3 - 2023-02-13
  • 17.4.2 - 2023-01-12
  • 17.4.0 - 2023-01-04
  • 17.3.0 - 2022-11-21
  • 17.2.0 - 2022-10-31
  • 17.1.0 - 2022-08-27
  • 17.0.3 - 2022-06-25
  • 17.0.2 - 2022-06-01
  • 17.0.0 - 2022-05-16
  • 16.2.4 - 2022-04-28
  • 16.2.1 - 2022-02-13
  • 16.0.0 - 2021-12-26
  • 15.0.0 - 2021-11-17
from @commitlint/config-conventional GitHub release notes
Package name: babel-jest
  • 29.7.0 - 2023-09-12

    Features

    • [create-jest] Add npm init / yarn create initialiser for Jest projects (#14465)
    • [jest-validate] Allow deprecation warnings for unknown options (#14499)

    Fixes

    • [jest-resolver] Replace unmatched capture groups in moduleNameMapper with empty string instead of undefined (#14507)
    • [jest-snapshot] Allow for strings as well as template literals in inline snapshots (#14465)
    • [@ jest/test-sequencer] Calculate test runtime if perStats.duration is missing (#14473)

    Performance

    • [@ jest/create-cache-key-function] Cache access of NODE_ENV and BABEL_ENV (#14455)

    Chore & Maintenance

    • [jest-cli] Move internal config initialisation logic to the create-jest package (#14465)

    New Contributors

Snyk has created this PR to upgrade:
  - @commitlint/cli from 15.0.0 to 19.4.0.
    See this package in npm: https://www.npmjs.com/package/@commitlint/cli
  - @commitlint/config-conventional from 15.0.0 to 19.2.2.
    See this package in npm: https://www.npmjs.com/package/@commitlint/config-conventional
  - babel-jest from 27.5.1 to 29.7.0.
    See this package in npm: https://www.npmjs.com/package/babel-jest
  - jest from 27.5.1 to 29.7.0.
    See this package in npm: https://www.npmjs.com/package/jest
  - vue from 2.7.14 to 3.4.38.
    See this package in npm: https://www.npmjs.com/package/vue
  - vue-template-compiler from 2.7.14 to 2.7.16.
    See this package in npm: https://www.npmjs.com/package/vue-template-compiler
  - @babel/eslint-parser from 7.19.1 to 7.25.1.
    See this package in npm: https://www.npmjs.com/package/@babel/eslint-parser
  - @nuxt/types from 2.15.8 to 2.18.1.
    See this package in npm: https://www.npmjs.com/package/@nuxt/types
  - @nuxt/typescript-build from 3.0.1 to 3.0.2.
    See this package in npm: https://www.npmjs.com/package/@nuxt/typescript-build
  - @nuxtjs/composition-api from 0.33.1 to 0.34.0.
    See this package in npm: https://www.npmjs.com/package/@nuxtjs/composition-api
  - eslint-plugin-vue from 8.7.1 to 9.27.0.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-vue
  - @nuxtjs/eslint-config-typescript from 8.0.0 to 12.1.0.
    See this package in npm: https://www.npmjs.com/package/@nuxtjs/eslint-config-typescript
  - @nuxtjs/eslint-module from 3.1.0 to 4.1.0.
    See this package in npm: https://www.npmjs.com/package/@nuxtjs/eslint-module
  - @nuxtjs/storybook from 4.3.2 to 8.2.0.
    See this package in npm: https://www.npmjs.com/package/@nuxtjs/storybook
  - @nuxtjs/stylelint-module from 4.1.0 to 5.2.0.
    See this package in npm: https://www.npmjs.com/package/@nuxtjs/stylelint-module
  - @pinia/nuxt from 0.2.1 to 0.5.4.
    See this package in npm: https://www.npmjs.com/package/@pinia/nuxt
  - @pinia/testing from 0.0.12 to 0.1.5.
    See this package in npm: https://www.npmjs.com/package/@pinia/testing
  - @testing-library/jest-dom from 5.16.5 to 6.5.0.
    See this package in npm: https://www.npmjs.com/package/@testing-library/jest-dom
  - @testing-library/vue from 5.9.0 to 8.1.0.
    See this package in npm: https://www.npmjs.com/package/@testing-library/vue
  - @types/jest from 27.5.2 to 29.5.12.
    See this package in npm: https://www.npmjs.com/package/@types/jest
  - @vue/test-utils from 1.3.0 to 2.4.6.
    See this package in npm: https://www.npmjs.com/package/@vue/test-utils
  - autoprefixer from 10.4.13 to 10.4.20.
    See this package in npm: https://www.npmjs.com/package/autoprefixer
  - core-js from 3.19.3 to 3.38.1.
    See this package in npm: https://www.npmjs.com/package/core-js
  - eslint from 8.34.0 to 9.9.1.
    See this package in npm: https://www.npmjs.com/package/eslint
  - eslint-config-prettier from 8.6.0 to 9.1.0.
    See this package in npm: https://www.npmjs.com/package/eslint-config-prettier
  - eslint-plugin-nuxt from 3.2.0 to 4.0.0.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-nuxt
  - eslint-plugin-promise from 6.1.1 to 7.1.0.
    See this package in npm: https://www.npmjs.com/package/eslint-plugin-promise
  - lint-staged from 12.5.0 to 15.2.9.
    See this package in npm: https://www.npmjs.com/package/lint-staged
  - msw from 0.49.3 to 2.3.5.
    See this package in npm: https://www.npmjs.com/package/msw
  - nuxt from 2.15.8 to 3.13.0.
    See this package in npm: https://www.npmjs.com/package/nuxt
  - pinia from 2.0.19 to 2.2.2.
    See this package in npm: https://www.npmjs.com/package/pinia
  - postcss-html from 1.5.0 to 1.7.0.
    See this package in npm: https://www.npmjs.com/package/postcss-html
  - prettier from 2.8.4 to 3.3.3.
    See this package in npm: https://www.npmjs.com/package/prettier
  - stylelint from 14.16.1 to 16.8.2.
    See this package in npm: https://www.npmjs.com/package/stylelint
  - stylelint-config-recommended-vue from 1.4.0 to 1.5.0.
    See this package in npm: https://www.npmjs.com/package/stylelint-config-recommended-vue
  - stylelint-config-standard from 24.0.0 to 36.0.1.
    See this package in npm: https://www.npmjs.com/package/stylelint-config-standard
  - tailwindcss from 3.2.6 to 3.4.10.
    See this package in npm: https://www.npmjs.com/package/tailwindcss
  - ts-jest from 27.1.1 to 29.2.5.
    See this package in npm: https://www.npmjs.com/package/ts-jest
  - vue-jest from 3.0.4 to 4.0.1.
    See this package in npm: https://www.npmjs.com/package/vue-jest
  - vue-server-renderer from 2.7.14 to 2.7.16.
    See this package in npm: https://www.npmjs.com/package/vue-server-renderer
  - webpack from 4.46.0 to 5.94.0.
    See this package in npm: https://www.npmjs.com/package/webpack

See this project in Snyk:
https://app.snyk.io/org/cachiman/project/38034379-ac15-4af2-8aa7-90d870017ff8?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

google-cla bot commented Sep 17, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants