[Snyk] Upgrade: , react, react-dom, , , , formik, next, use-remote-data #131
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@emotion/styled
from 11.6.0 to 11.13.0 | 12 versions ahead of your current version | 2 months ago
on 2024-07-20
react
from 17.0.0 to 17.0.2 | 2 versions ahead of your current version | 3 years ago
on 2021-03-22
react-dom
from 17.0.0 to 17.0.2 | 2 versions ahead of your current version | 3 years ago
on 2021-03-22
@chakra-ui/icons
from 1.1.1 to 1.1.7 | 6 versions ahead of your current version | 3 years ago
on 2022-02-20
@chakra-ui/react
from 1.7.2 to 1.8.9 | 13 versions ahead of your current version | 2 years ago
on 2022-09-16
@emotion/react
from 11.7.0 to 11.13.3 | 18 versions ahead of your current version | 23 days ago
on 2024-08-21
formik
from 2.2.9 to 2.4.6 | 11 versions ahead of your current version | 5 months ago
on 2024-04-24
next
from 12.0.7 to 12.3.4 | 275 versions ahead of your current version | 2 years ago
on 2022-11-21
use-remote-data
from 0.4.0 to 0.5.1 | 2 versions ahead of your current version | 2 years ago
on 2022-10-14
Issues fixed by the recommended upgrade:
SNYK-JS-BRACES-6838727
SNYK-JS-BROWSERIFYSIGN-6037026
SNYK-JS-SEMVER-3247795
SNYK-JS-NANOID-2332193
SNYK-JS-NEXT-2388583
SNYK-JS-NEXT-2405694
SNYK-JS-ELLIPTIC-7577916
SNYK-JS-NODEFETCH-2342118
SNYK-JS-ELLIPTIC-7577917
SNYK-JS-ELLIPTIC-7577918
SNYK-JS-LOADERUTILS-3043105
SNYK-JS-JSON5-3182856
SNYK-JS-LOADERUTILS-3042992
SNYK-JS-LOADERUTILS-3105943
SNYK-JS-MINIMIST-2429795
Release notes
Package name: @emotion/styled
Minor Changes
#3198
d8ff8a5
Thanks @ Andarist! - Migrated away from relying onprocess.env.NODE_ENV
checks to differentiate between production and development builds.Development builds (and other environment-specific builds) can be used by using proper conditions (see here). Most modern bundlers/frameworks already preconfigure those for the user so no action has to be taken.
Default files should continue to work in all environments.
#3215
a9f6912
Thanks @ Andarist! - Addededge-light
andworkerd
conditions topackage.json
manifest to better serve users using Vercel Edge and Cloudflare Workers.Patch Changes
d8ff8a5
,a9f6912
]:Package name: react
React DOM
SharedArrayBuffer
cross-origin isolation warning. (@ koba04 and @ bvaughn in #20831, #20832, and #20840)Artifacts
React DOM
Today, we are releasing React 17!
Learn more about React 17 and how to update to it on the official React blog.
React
react/jsx-runtime
andreact/jsx-dev-runtime
for the new JSX transform. (@ lunaruan in #18299)displayName
on context for improved stacks. (@ eps1lon in #18224)'use strict'
from leaking in the UMD bundles. (@ koba04 in #19614)fb.me
for redirects. (@ cylim in #19598)React DOM
document
. (@ trueadm in #18195 and others)useEffect
cleanup functions asynchronously. (@ bvaughn in #17925)focusin
andfocusout
foronFocus
andonBlur
. (@ trueadm in #19186)Capture
events use the browser capture phase. (@ trueadm in #19221)onScroll
event. (@ gaearon in #19464)forwardRef
ormemo
component returnsundefined
. (@ gaearon in #19550)console
in the second render pass of DEV mode double render. (@ sebmarkbage in #18547)ReactTestUtils.SimulateNative
API. (@ gaearon in #13407)ReactDOM.flushSync
during lifecycle methods (but warn). (@ sebmarkbage in #18759)code
property to the keyboard event objects. (@ bl00mber in #18287)disableRemotePlayback
property forvideo
elements. (@ tombrowndev in #18619)enterKeyHint
property forinput
elements. (@ eps1lon in #18634)value
is provided to<Context.Provider>
. (@ charlie1404 in #19054)memo
orforwardRef
components returnundefined
. (@ bvaughn in #19550)onTouchStart
,onTouchMove
, andonWheel
passive. (@ gaearon in #19654)setState
hanging in development inside a closed iframe. (@ gaearon in #19220)defaultProps
. (@ jddxf in #18539)dangerouslySetInnerHTML
isundefined
. (@ eps1lon in #18676)require
implementation. (@ just-boris in #18632)onBeforeInput
reporting an incorrectevent.type
. (@ eps1lon in #19561)event.relatedTarget
reported asundefined
in Firefox. (@ claytercek in #19607)movementX/Y
polyfill with capture events. (@ gaearon in #19672)onSubmit
andonReset
events. (@ gaearon in #19333)React DOM Server
useCallback
behavior consistent withuseMemo
for the server renderer. (@ alexmckenley in #18783)React Test Renderer
findByType
error message. (@ henryqdineen in #17439)Concurrent Mode (Experimental)
unstable_
prefix before the experimental APIs. (@ acdlite in #18825)unstable_discreteUpdates
andunstable_flushDiscreteUpdates
. (@ trueadm in #18825)timeoutMs
argument. (@ acdlite in #19703)<div hidden />
prerendering in favor of a different future API. (@ acdlite in #18917)unstable_expectedLoadTime
to Suspense for CPU-bound trees. (@ acdlite in #19936)unstable_useOpaqueIdentifier
Hook. (@ lunaruan in #17322)unstable_startTransition
API. (@ rickhanlonii in #19696)act
in the test renderer no longer flushes Suspense fallbacks. (@ acdlite in #18596)useMutableSource
that may happen whengetSnapshot
changes. (@ bvaughn in #18297)useMutableSource
. (@ bvaughn in #18912)Artifacts
Package name: react-dom
React DOM
SharedArrayBuffer
cross-origin isolation warning. (@ koba04 and @ bvaughn in #20831, #20832, and #20840)Artifacts
React DOM
Today, we are releasing React 17!
Learn more about React 17 and how to update to it on the official React blog.
React
react/jsx-runtime
andreact/jsx-dev-runtime
for the new JSX transform. (@ lunaruan in #18299)displayName
on context for improved stacks. (@ eps1lon in #18224)'use strict'
from leaking in the UMD bundles. (@ koba04 in #19614)fb.me
for redirects. (@ cylim in #19598)React DOM
document
. (@ trueadm in #18195 and others)useEffect
cleanup functions asynchronously. (@ bvaughn in #17925)focusin
andfocusout
foronFocus
andonBlur
. (@ trueadm in #19186)Capture
events use the browser capture phase. (@ trueadm in #19221)onScroll
event. (@ gaearon in #19464)forwardRef
ormemo
component returnsundefined
. (@ gaearon in #19550)console
in the second render pass of DEV mode double render. (@ sebmarkbage in #18547)ReactTestUtils.SimulateNative
API. (@ gaearon in #13407)ReactDOM.flushSync
during lifecycle methods (but warn). (@ sebmarkbage in #18759)code
property to the keyboard event objects. (@ bl00mber in #18287)disableRemotePlayback
property forvideo
elements. (@ tombrowndev in #18619)enterKeyHint
property forinput
elements. (@ eps1lon in #18634)value
is provided to<Context.Provider>
. (@ charlie1404 in #19054)memo
orforwardRef
components returnundefined
. (@ bvaughn in #19550)onTouchStart
,onTouchMove
, andonWheel
passive. (@ gaearon in #19654)setState
hanging in development inside a closed iframe. (@ gaearon in #19220)defaultProps
. (@ jddxf in #18539)dangerouslySetInnerHTML
isundefined
. (@ eps1lon in #18676)require
implementation. (@ just-boris in #18632)onBeforeInput
reporting an incorrectevent.type
. (@ eps1lon in #19561)event.relatedTarget
reported asundefined
in Firefox. (@ claytercek in #19607)movementX/Y
polyfill with capture events. (@ gaearon in #19672)onSubmit
andonReset
events. (@ gaearon in #19333)React DOM Server
useCallback
behavior consistent withuseMemo
for the server renderer. (@ alexmckenley in #18783)React Test Renderer
findByType
error message. (@ henryqdineen in #17439)Concurrent Mode (Experimental)
unstable_
prefix before the experimental APIs. (@ acdlite in #18825)unstable_discreteUpdates
andunstable_flushDiscreteUpdates
. (@ trueadm in #18825)timeoutMs
argument. (@ acdlite in #19703)<div hidden />
prerendering in favor of a different future API. (@ acdlite in #18917)unstable_expectedLoadTime
to Suspense for CPU-bound trees. (@ acdlite in #19936)unstable_useOpaqueIdentifier
Hook. (@ lunaruan in #17322)unstable_startTransition
API. (@ rickhanlonii in #19696)act
in the test renderer no longer flushes Suspense fallbacks. (@ acdlite in #18596)useMutableSource
that may happen whengetSnapshot
changes. (@ bvaughn in #18297)useMutableSource
. (@ bvaughn in #18912)Artifacts
Package name: @chakra-ui/icons
Package name: @chakra-ui/react
Package name: @emotion/react
Patch Changes
#3232
0ce3ed0
Thanks @ ENvironmentSet! - Distributecss
prop attachment over props that are union typesUpdated dependencies []:
Minor Changes
#3198
d8ff8a5
Thanks @ Andarist! - Migrated away from relying onprocess.env.NODE_ENV
checks to differentiate between production and development builds.Development builds (and other environment-specific builds) can be used by using proper conditions (see here). Most modern bundlers/frameworks already preconfigure those for the user so no action has to be taken.
Default files should continue to work in all environments.
#3215
a9f6912
Thanks @ Andarist! - Addededge-light
andworkerd
conditions topackage.json
manifest to better serve users using Vercel Edge and Cloudflare Workers.Patch Changes
d8ff8a5
,a9f6912
]:Package name: formik
Patch Changes
f57ca9b
#3949 Thanks @ DeveloperRaj! - Changing the state inside formik was changing reference of initialValues provided via props, deep cloning the initialvalues will fix it.Patch Changes
d7db9cd
#3860 Thanks @ patik! - Add missing dependency@ types/hoist-non-react-statics
, closes #3837fe4ed7e
#3501 Thanks @ markspolakovs! - Markformik
as side-effect free inpackage.json
Patch Changes
41720c2
#3862 Thanks @ yazaldefilimonepinto! - ForwardclassName
for custom components used withField
...