Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: enzyme, enzyme-adapter-react-16, react, react-dom, babel-preset-airbnb, chai, mocha-multi, nock, node-fetch, react-bootstrap, react-redux, react-router, redux, redux-mock-store, redux-thunk, sinon, uuid #26

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

tiff-es
Copy link
Owner

@tiff-es tiff-es commented Sep 18, 2024

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

enzyme
from 3.3.0 to 3.11.0 | 13 versions ahead of your current version | 5 years ago
on 2019-12-20
enzyme-adapter-react-16
from 1.1.1 to 1.15.8 | 30 versions ahead of your current version | 7 months ago
on 2024-02-10
react
from 16.4.1 to 16.14.0 | 36 versions ahead of your current version | 4 years ago
on 2020-10-14
react-dom
from 16.4.1 to 16.14.0 | 35 versions ahead of your current version | 4 years ago
on 2020-10-14
babel-preset-airbnb
from 2.5.2 to 2.6.0 | 2 versions ahead of your current version | 6 years ago
on 2018-08-29
chai
from 4.1.2 to 4.5.0 | 15 versions ahead of your current version | 2 months ago
on 2024-07-25
mocha-multi
from 1.0.1 to 1.1.7 | 8 versions ahead of your current version | 2 years ago
on 2022-11-15
nock
from 9.4.3 to 9.6.1 | 4 versions ahead of your current version | 6 years ago
on 2018-08-13
node-fetch
from 2.6.0 to 2.7.0 | 14 versions ahead of your current version | a year ago
on 2023-08-23
react-bootstrap
from 0.32.1 to 0.33.1 | 5 versions ahead of your current version | 5 years ago
on 2019-11-27
react-redux
from 5.0.7 to 5.1.2 | 4 versions ahead of your current version | 5 years ago
on 2019-10-08
react-router
from 3.2.1 to 3.2.6 | 5 versions ahead of your current version | 5 years ago
on 2020-03-04
redux
from 4.0.0 to 4.2.1 | 12 versions ahead of your current version | 2 years ago
on 2023-01-28
redux-mock-store
from 1.5.3 to 1.5.4 | 1 version ahead of your current version | 5 years ago
on 2019-12-11
redux-thunk
from 2.3.0 to 2.4.2 | 3 versions ahead of your current version | 2 years ago
on 2022-11-04
sinon
from 6.1.4 to 6.3.5 | 9 versions ahead of your current version | 6 years ago
on 2018-10-03
uuid
from 3.3.2 to 3.4.0 | 2 versions ahead of your current version | 5 years ago
on 2020-01-16

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-LODASH-567746
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-608086
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-6139239
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-73638
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASHES-2434283
731 Proof of Concept
high severity Code Injection
SNYK-JS-LODASHES-2434284
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASHES-2434285
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASHES-2434287
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASHES-2434290
731 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
731 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-GETFUNCNAME-5923417
731 Proof of Concept
high severity Code Injection
SNYK-JS-LODASH-1040724
731 Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-450202
731 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
731 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASHES-2434286
731 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-PATHVAL-596926
731 Proof of Concept
medium severity Cross-site Scripting (XSS)
npm:react-dom:20180802
731 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASHES-2434289
731 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CSSWHAT-3035488
731 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
731 Proof of Concept
low severity Denial of Service (DoS)
SNYK-JS-JUSTEXTEND-72674
731 No Known Exploit
Release notes
Package name: enzyme
  • 3.11.0 - 2019-12-20
  • 3.10.0 - 2019-06-04
  • 3.9.0 - 2019-02-17
  • 3.8.0 - 2018-12-10
  • 3.7.0 - 2018-10-05
  • 3.6.0 - 2018-09-05
  • 3.5.1 - 2018-09-03
  • 3.5.0 - 2018-08-25
  • 3.4.4 - 2018-08-17
  • 3.4.3 - 2018-08-17
  • 3.4.2 - 2018-08-16
  • 3.4.1 - 2018-08-08
  • 3.4.0 - 2018-08-08
  • 3.3.0 - 2017-12-28
from enzyme GitHub release notes
Package name: enzyme-adapter-react-16
  • 1.15.8 - 2024-02-10
    • [refactor] use hasown instead of has
    • [deps] update in-range deps
    • [meta] run build/files steps in prepack, not prepublish
  • 1.15.7 - 2022-11-05
    • [fix] isEmptyRender: properly detect memoized SFCs returning null
    • [fix] avoid a crash with lazy components
    • [fix] fix simulateError() on Memo component (#2525)
    • [babel] add babel-plugin-add-module-exports and fully use ESM syntax
    • [deps] update enzyme-shallow-equal, enzyme-adapter-utils, object.assign, object.values, prop-types
    • [meta] use npmignore to autogenerate
    • [eslint] switch to @ babel/eslint-parser, fix lintingan npmignore file
    • [dev deps] update @ babel/cli, @ babel/core, eslint, eslint-config-airbnb, eslint-config-airbnb-base, eslint-plugin-import, eslint-plugin-jsx-a11y, eslint-plugin-markdown, eslint-plugin-react, eslint-plugin-react-hooks
    • [dev deps] update safe-publish-latest; use prepublishOnly
  • 1.15.6 - 2021-01-20
  • 1.15.5 - 2020-09-24
  • 1.15.4 - 2020-08-31
  • 1.15.3 - 2020-08-08
  • 1.15.2 - 2019-12-19
  • 1.15.1 - 2019-10-11
  • 1.15.0 - 2019-10-09
  • 1.14.0 - 2019-06-03
  • 1.13.2 - 2019-05-26
  • 1.13.1 - 2019-05-19
  • 1.13.0 - 2019-05-11
  • 1.12.1 - 2019-04-06
  • 1.12.0 - 2019-04-06
  • 1.11.2 - 2019-03-14
  • 1.11.1 - 2019-03-14
  • 1.11.0 - 2019-03-13
  • 1.10.0 - 2019-02-26
  • 1.9.1 - 2019-02-05
  • 1.9.0 - 2019-02-05
  • 1.8.0 - 2019-01-24
  • 1.7.1 - 2018-12-10
  • 1.7.0 - 2018-11-08
  • 1.6.0 - 2018-10-05
  • 1.5.0 - 2018-09-05
  • 1.4.0 - 2018-09-04
  • 1.3.1 - 2018-08-31
  • 1.3.0 - 2018-08-25
  • 1.2.0 - 2018-08-08
  • 1.1.1 - 2017-12-18
from enzyme-adapter-react-16 GitHub release notes
Package name: react from react GitHub release notes
Package name: react-dom from react-dom GitHub release notes
Package name: babel-preset-airbnb from babel-preset-airbnb GitHub release notes
Package name: chai from chai GitHub release notes
Package name: mocha-multi from mocha-multi GitHub release notes
Package name: nock from nock GitHub release notes
Package name: node-fetch from node-fetch GitHub release notes
Package name: react-bootstrap
  • 0.33.1 - 2019-11-27

    v0.33.1

  • 0.33.0 - 2019-10-30

    v0.33.0

  • 0.32.4 - 2018-09-06
  • 0.32.3 - 2018-08-20
  • 0.32.2 - 2018-08-17
  • 0.32.1 - 2018-01-25
from react-bootstrap GitHub release notes
Package name: react-redux
  • 5.1.2 - 2019-10-08

    Changes

  • 5.1.1 - 2018-11-10
  • 5.1.0 - 2018-10-25
  • 5.1.0-test.1 - 2018-06-21
  • 5.0.7 - 2018-02-16
from react-redux GitHub release notes
Package name: react-router from react-router GitHub release notes
Package name: redux
  • 4.2.1 - 2023-01-28

    This bugfix release removes the isMinified internal check to fix a compat issue with Expo. That check has added

Snyk has created this PR to upgrade:
  - enzyme from 3.3.0 to 3.11.0.
    See this package in npm: https://www.npmjs.com/package/enzyme
  - enzyme-adapter-react-16 from 1.1.1 to 1.15.8.
    See this package in npm: https://www.npmjs.com/package/enzyme-adapter-react-16
  - react from 16.4.1 to 16.14.0.
    See this package in npm: https://www.npmjs.com/package/react
  - react-dom from 16.4.1 to 16.14.0.
    See this package in npm: https://www.npmjs.com/package/react-dom
  - babel-preset-airbnb from 2.5.2 to 2.6.0.
    See this package in npm: https://www.npmjs.com/package/babel-preset-airbnb
  - chai from 4.1.2 to 4.5.0.
    See this package in npm: https://www.npmjs.com/package/chai
  - mocha-multi from 1.0.1 to 1.1.7.
    See this package in npm: https://www.npmjs.com/package/mocha-multi
  - nock from 9.4.3 to 9.6.1.
    See this package in npm: https://www.npmjs.com/package/nock
  - node-fetch from 2.6.0 to 2.7.0.
    See this package in npm: https://www.npmjs.com/package/node-fetch
  - react-bootstrap from 0.32.1 to 0.33.1.
    See this package in npm: https://www.npmjs.com/package/react-bootstrap
  - react-redux from 5.0.7 to 5.1.2.
    See this package in npm: https://www.npmjs.com/package/react-redux
  - react-router from 3.2.1 to 3.2.6.
    See this package in npm: https://www.npmjs.com/package/react-router
  - redux from 4.0.0 to 4.2.1.
    See this package in npm: https://www.npmjs.com/package/redux
  - redux-mock-store from 1.5.3 to 1.5.4.
    See this package in npm: https://www.npmjs.com/package/redux-mock-store
  - redux-thunk from 2.3.0 to 2.4.2.
    See this package in npm: https://www.npmjs.com/package/redux-thunk
  - sinon from 6.1.4 to 6.3.5.
    See this package in npm: https://www.npmjs.com/package/sinon
  - uuid from 3.3.2 to 3.4.0.
    See this package in npm: https://www.npmjs.com/package/uuid

See this project in Snyk:
https://app.snyk.io/org/boostinwrx/project/a6b7063d-36df-4416-a4b9-58609f775d8e?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants