Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade esbuild from 0.14.54 to 0.20.2 #1

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

jetboard
Copy link
Owner

@jetboard jetboard commented Apr 9, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade esbuild from 0.14.54 to 0.20.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 94 versions ahead of your current version.
  • The recommended version was released a month ago, on 2024-03-14.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: esbuild
  • 0.20.2 - 2024-03-14
    • Support TypeScript experimental decorators on abstract class fields (#3684)

      With this release, you can now use TypeScript experimental decorators on abstract class fields. This was silently compiled incorrectly in esbuild 0.19.7 and below, and was an error from esbuild 0.19.8 to esbuild 0.20.1. Code such as the following should now work correctly:

      // Original code
      const log = (x: any, y: string) => console.log(y)
      abstract class Foo { @log abstract foo: string }
      new class extends Foo { foo = '' }

      // Old output (with --loader=ts --tsconfig-raw={"compilerOptions":{"experimentalDecorators":true}})
      const log = (x, y) => console.log(y);
      class Foo {
      }
      new class extends Foo {
      foo = "";
      }();

      // New output (with --loader=ts --tsconfig-raw={"compilerOptions":{"experimentalDecorators":true}})
      const log = (x, y) => console.log(y);
      class Foo {
      }
      __decorateClass([
      log
      ], Foo.prototype, "foo", 2);
      new class extends Foo {
      foo = "";
      }();

    • JSON loader now preserves __proto__ properties (#3700)

      Copying JSON source code into a JavaScript file will change its meaning if a JSON object contains the __proto__ key. A literal __proto__ property in a JavaScript object literal sets the prototype of the object instead of adding a property named __proto__, while a literal __proto__ property in a JSON object literal just adds a property named __proto__. With this release, esbuild will now work around this problem by converting JSON to JavaScript with a computed property key in this case:

      // Original code
      import data from 'data:application/json,{"proto":{"fail":true}}'
      if (Object.getPrototypeOf(data)?.fail) throw 'fail'

      // Old output (with --bundle)
      (() => {
      // <data:application/json,{"proto":{"fail":true}}>
      var json_proto_fail_true_default = { proto: { fail: true } };

      // entry.js
      if (Object.getPrototypeOf(json_proto_fail_true_default)?.fail)
      throw "fail";
      })();

      // New output (with --bundle)
      (() => {
      // <data:application/json,{"proto":{"fail":true}}>
      var json_proto_fail_true_default = { ["proto"]: { fail: true } };

      // example.mjs
      if (Object.getPrototypeOf(json_proto_fail_true_default)?.fail)
      throw "fail";
      })();

    • Improve dead code removal of switch statements (#3659)

      With this release, esbuild will now remove switch statements in branches when minifying if they are known to never be evaluated:

      // Original code
      if (true) foo(); else switch (bar) { case 1: baz(); break }

      // Old output (with --minify)
      if(1)foo();else switch(bar){case 1:}

      // New output (with --minify)
      foo();

    • Empty enums should behave like an object literal (#3657)

      TypeScript allows you to create an empty enum and add properties to it at run time. While people usually use an empty object literal for this instead of a TypeScript enum, esbuild's enum transform didn't anticipate this use case and generated undefined instead of {} for an empty enum. With this release, you can now use an empty enum to generate an empty object literal.

      // Original code
      enum Foo {}

      // Old output (with --loader=ts)
      var Foo = /* @ PURE */ ((Foo2) => {
      })(Foo || {});

      // New output (with --loader=ts)
      var Foo = /* @ PURE */ ((Foo2) => {
      return Foo2;
      })(Foo || {});

    • Handle Yarn Plug'n'Play edge case with tsconfig.json (#3698)

      Previously a tsconfig.json file that extends another file in a package with an exports map failed to work when Yarn's Plug'n'Play resolution was active. This edge case should work now starting with this release.

    • Work around issues with Deno 1.31+ (#3682)

      Version 0.20.0 of esbuild changed how the esbuild child process is run in esbuild's API for Deno. Previously it used Deno.run but that API is being removed in favor of Deno.Command. As part of this change, esbuild is now calling the new unref function on esbuild's long-lived child process, which is supposed to allow Deno to exit when your code has finished running even though the child process is still around (previously you had to explicitly call esbuild's stop() function to terminate the child process for Deno to be able to exit).

      However, this introduced a problem for Deno's testing API which now fails some tests that use esbuild with error: Promise resolution is still pending but the event loop has already resolved. It's unclear to me why this is happening. The call to unref was recommended by someone on the Deno core team, and calling Node's equivalent unref API has been working fine for esbuild in Node for a long time. It could be that I'm using it incorrectly, or that there's some reference counting and/or garbage collection bug in Deno's internals, or that Deno's unref just works differently than Node's unref. In any case, it's not good for Deno tests that use esbuild to be failing.

      In this release, I am removing the call to unref to fix this issue. This means that you will now have to call esbuild's stop() function to allow Deno to exit, just like you did before esbuild version 0.20.0 when this regression was introduced.

      Note: This regression wasn't caught earlier because Deno doesn't seem to fail tests that have outstanding setTimeout calls, which esbuild's test harness was using to enforce a maximum test runtime. Adding a setTimeout was allowing esbuild's Deno tests to succeed. So this regression doesn't necessarily apply to all people using tests in Deno.

  • 0.20.1 - 2024-02-19
    Read more
  • 0.20.0 - 2024-01-27

    This release deliberately contains backwards-incompatible changes. To avoid automatically picking up releases like this, you should either be pinning the exact version of esbuild in your package.json file (recommended) or be using a version range syntax that only accepts patch upgrades such as ^0.19.0 or ~0.19.0. See npm's documentation about semver for more information.

    This time there is only one breaking change, and it only matters for people using Deno. Deno tests that use esbuild will now fail unless you make the change described below.

    • Work around API deprecations in Deno 1.40.x (#3609, #3611)

      Deno 1.40.0 was just released and introduced run-time warnings about certain APIs that esbuild uses. With this release, esbuild will work around these run-time warnings by using newer APIs if they are present and falling back to the original APIs otherwise. This should avoid the warnings without breaking compatibility with older versions of Deno.

      Unfortunately, doing this introduces a breaking change. The newer child process APIs lack a way to synchronously terminate esbuild's child process, so calling esbuild.stop() from within a Deno test is no longer sufficient to prevent Deno from failing a test that uses esbuild's API (Deno fails tests that create a child process without killing it before the test ends). To work around this, esbuild's stop() function has been changed to return a promise, and you now have to change esbuild.stop() to await esbuild.stop() in all of your Deno tests.

    • Reorder implicit file extensions within node_modules (#3341, #3608)

      In version 0.18.0, esbuild changed the behavior of implicit file extensions within node_modules directories (i.e. in published packages) to prefer .js over .ts even when the --resolve-extensions= order prefers .ts over .js (which it does by default). However, doing that also accidentally made esbuild prefer .css over .ts, which caused problems for people that published packages containing both TypeScript and CSS in files with the same name.

      With this release, esbuild will reorder TypeScript file extensions immediately after the last JavaScript file extensions in the implicit file extension order instead of putting them at the end of the order. Specifically the default implicit file extension order is .tsx,.ts,.jsx,.js,.css,.json which used to become .jsx,.js,.css,.json,.tsx,.ts in node_modules directories. With this release it will now become .jsx,.js,.tsx,.ts,.css,.json instead.

      Why even rewrite the implicit file extension order at all? One reason is because the .js file is more likely to behave correctly than the .ts file. The behavior of the .ts file may depend on tsconfig.json and the tsconfig.json file may not even be published, or may use extends to refer to a base tsconfig.json file that wasn't published. People can get into this situation when they forget to add all .ts files to their .npmignore file before publishing to npm. Picking .js over .ts helps make it more likely that resulting bundle will behave correctly.

  • 0.19.12 - 2024-01-23
    Read more
  • 0.19.11 - 2023-12-29
    Read more
  • 0.19.10 - 2023-12-19
    Read more
  • 0.19.9 - 2023-12-10
    Read more
  • 0.19.8 - 2023-11-26
    Read more
  • 0.19.7 - 2023-11-21
    Read more
  • 0.19.6 - 2023-11-19
    Read more
  • 0.19.5 - 2023-10-17
  • 0.19.4 - 2023-09-28
  • 0.19.3 - 2023-09-14
  • 0.19.2 - 2023-08-14
  • 0.19.1 - 2023-08-11
  • 0.19.0 - 2023-08-08
  • 0.18.20 - 2023-08-08
  • 0.18.19 - 2023-08-07
  • 0.18.18 - 2023-08-05
  • 0.18.17 - 2023-07-26
  • 0.18.16 - 2023-07-23
  • 0.18.15 - 2023-07-20
  • 0.18.14 - 2023-07-18
  • 0.18.13 - 2023-07-15
  • 0.18.12 - 2023-07-13
  • 0.18.11 - 2023-07-01
  • 0.18.10 - 2023-06-26
  • 0.18.9 - 2023-06-26
  • 0.18.8 - 2023-06-25
  • 0.18.7 - 2023-06-24
  • 0.18.6 - 2023-06-20
  • 0.18.5 - 2023-06-20
  • 0.18.4 - 2023-06-16
  • 0.18.3 - 2023-06-15
  • 0.18.2 - 2023-06-13
  • 0.18.1 - 2023-06-12
  • 0.18.0 - 2023-06-09
  • 0.17.19 - 2023-05-13
  • 0.17.18 - 2023-04-22
  • 0.17.17 - 2023-04-16
  • 0.17.16 - 2023-04-10
  • 0.17.15 - 2023-04-01
  • 0.17.14 - 2023-03-26
  • 0.17.13 - 2023-03-24
  • 0.17.12 - 2023-03-17
  • 0.17.11 - 2023-03-03
  • 0.17.10 - 2023-02-20
  • 0.17.9 - 2023-02-19
  • 0.17.8 - 2023-02-13
  • 0.17.7 - 2023-02-09
  • 0.17.6 - 2023-02-06
  • 0.17.5 - 2023-01-27
  • 0.17.4 - 2023-01-22
  • 0.17.3 - 2023-01-18
  • 0.17.2 - 2023-01-17
  • 0.17.1 - 2023-01-16
  • 0.17.0 - 2023-01-14
  • 0.16.17 - 2023-01-11
  • 0.16.16 - 2023-01-08
  • 0.16.15 - 2023-01-07
  • 0.16.14 - 2023-01-04
  • 0.16.13 - 2023-01-02
  • 0.16.12 - 2022-12-28
  • 0.16.11 - 2022-12-27
  • 0.16.10 - 2022-12-19
  • 0.16.9 - 2022-12-18
  • 0.16.8 - 2022-12-16
  • 0.16.7 - 2022-12-14
  • 0.16.6 - 2022-12-14
  • 0.16.5 - 2022-12-13
  • 0.16.4 - 2022-12-10
  • 0.16.3 - 2022-12-08
  • 0.16.2 - 2022-12-08
  • 0.16.1 - 2022-12-07
  • 0.16.0 - 2022-12-07
  • 0.15.18 - 2022-12-05
  • 0.15.17 - 2022-12-04
  • 0.15.16 - 2022-11-27
  • 0.15.15 - 2022-11-21
  • 0.15.14 - 2022-11-15
  • 0.15.13 - 2022-11-03
  • 0.15.12 - 2022-10-19
  • 0.15.11 - 2022-10-14
  • 0.15.10 - 2022-09-29
  • 0.15.9 - 2022-09-22
  • 0.15.8 - 2022-09-18
  • 0.15.7 - 2022-09-04
  • 0.15.6 - 2022-08-30
  • 0.15.5 - 2022-08-17
  • 0.15.4 - 2022-08-16
  • 0.15.3 - 2022-08-14
  • 0.15.2 - 2022-08-12
  • 0.15.1 - 2022-08-10
  • 0.15.0 - 2022-08-10
  • 0.14.54 - 2022-08-08
from esbuild GitHub release notes
Commit messages
Package name: esbuild
  • 617edda publish 0.20.2 to npm
  • 4780075 fix #3700: json loader preserves `__proto__` keys
  • 30bed2d better errors for invalid js decorator syntax
  • 300eeb7 ts: allow non-null assertions in js decorators
  • 4d997d9 fix #3698: yarn pnp edge case with `tsconfig.json`
  • cf42954 resolver: improve some debug logging
  • b0765ae fix some lints
  • dfa6206 fix some comments (closes #3683)
  • ae5cc17 fix #3684: `abstract` experimental decorators
  • c809af0 fix #2388: allow consuming types without dom types (#3679)
  • 116f63e Work around issues with Deno 1.31+ (#3685)
  • cc74e60 fix #3659: trim code in dead `switch` statements
  • a064abc fix bug with no-identifier `var` in dead branches
  • 40711af fix #3657: empty enum returns `{}` not `undefined`
  • 9f9e4f8 publish 0.20.1 to npm
  • ac36537 fix #3651: handle `__proto__` edge cases better
  • 555db48 fix #3645: constant folding for `< > <= >=`
  • 5650831 fix #3650: add a wrapper for float64 math
  • d086889 fix some lints
  • ad3d8c6 fix #3648: copy selectors before checking children
  • a08f30d fix #3634: crash if resolving with bad source dir
  • 2af5ccf publish 0.20.0 to npm
  • 0bccf08 fix https://github.com/alpine deno using musl-c compatibility esbuild/deno-esbuild#5
  • 931f87d work around api deprecations in deno 1.40.x (#3609) (#3611)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants