Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @docusaurus/plugin-pwa from 2.0.0-alpha.63 to 3.1.0 #304

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dalexhd
Copy link
Owner

@dalexhd dalexhd commented Apr 24, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • docs/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 626/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.1
Cross-site Scripting (XSS)
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @docusaurus/plugin-pwa The new version differs by 250 commits.
  • a5e6758 v3.1.0
  • a97a74f update lockfile
  • 0da5936 remove problematic @ ts-expect-error
  • 9088efb docs: broken link in release 3.0 page (#9573)
  • 643c33c update lockfile
  • 921fa24 refactor: apply lint autofix
  • a9cef92 fix(theme): allow empty code blocks and live playgrounds (#9704)
  • a779857 fix(create-docusaurus): fix init template code blocks, and little improvements (#9696)
  • 760a5ae feat(core): make broken link checker detect broken anchors - add `onBrokenAnchors` config (#9528)
  • 6d1897d fix(pwa-plugin): upgrade workbox (#9668)
  • 31bd1b1 feat(mdx-loader): add support for siteConfig.markdown.remarkRehypeOptions (#9674)
  • 539fd73 feat(theme-common): code block MagicComments support for (Visual) Basic/Batch/Fortran/COBOL/ML (#9671)
  • 803ccee chore: attempt fo fix Lint Autofix workflow (#9632)
  • 6c06a70 chore: add lint autofix CI job (#9604)
  • 839ccbd fix(cli): output help when no conventional config + no subcommand (#9648)
  • 1a91145 feat: siteConfig.markdown.parseFrontMatter hook (#9624)
  • 85e32fd fix(live-codeblock): stabilize react-live transformCode callback, fix editor/preview desync (#9631)
  • 3c051ee feat(core): enable port configuration via environment variable (#9610)
  • 17a2751 fix(utils): Markdown link replacement with <> but no spaces (#9617)
  • ab6147a fix(type-aliases): add `title` prop for imported inline SVG React components (#9612)
  • ed758fc fix(content-blog): add baseUrl for author.image_url (#9581)
  • 68cc281 refactor(theme-common): allow optional desktopBreakpoint param in useWindowSize (#9335)
  • 97278be fix(i18n): complete translations for theme-common.json Brazilian Portuguese (pt-BR) (#9477)
  • a2e05d2 chore: release Docusaurus 3.0.1 (#9596)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

Copy link

Great PR! Please pay attention to the following items before merging:

Files matching docs/**:

  • Do you linted the code?
  • Have you added the new version on metadata.js?

This is an automatically generated QA checklist based on modified files.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants