Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade react-hot-loader from 3.0.0-beta.7 to 3.0.0 #7

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-610226
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-hot-loader The new version differs by 86 commits.
  • 5973747 Merge pull request #658 from gaearon/react-16
  • 80136ac v3.0.0
  • 7a968b6 refactor: revert HotContainer for now
  • 6d0346f feat: expose AppContainer with warning
  • 7d0e0da docs: remove coverage badge
  • 429cc4a docs: improve README
  • 3338ce2 feat: React 16 compatibility
  • 47ccb0a Merge pull request #655 from theKashey/master
  • b964851 document HOC Troubleshooting
  • 00404dd docs: keep AppContainer in doc
  • 60503a7 Merge pull request #639 from gaearon/hot-container
  • 7d1d294 Rename AppContainer into HotContainer
  • 2679e73 Merge pull request #494 from gaearon/no-redbox
  • 31fba04 Remove RedBox as default error catcher
  • ac52cd9 Merge pull request #608 from theKashey/master
  • f53860c Merge branch 'master' of https://github.com/gaearon/react-hot-loader
  • 37e105a Merge pull request #638 from gaearon/upgrade-project
  • ee4093f refactor: support node >=6
  • 31a79d2 tests: remove filename from snapshots
  • fb9f233 chore: target node 6 & 8 on travis
  • 3c2cb72 chore: upgrade source-map
  • e1c86bb chore: eslint + prettier
  • 5776cbb chore(test): switch to Jest
  • 0269524 Merge pull request #637 from gaearon/next

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant