storybook-state icon indicating copy to clipboard operation
storybook-state copied to clipboard

[Snyk] Security upgrade @storybook/react from 5.3.14 to 6.4.0

Open Sambego opened this issue 3 years ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @storybook/react The new version differs by 250 commits.
  • 7d4d6ab v6.4.0
  • 86e2d61 Update root, peer deps, version.ts/json to 6.4.0 [ci skip]
  • ec6fd3b 6.4.0 changelog
  • b88d2d9 6.4.0-rc.11 next.json version file
  • 2d78019 Update git head to 6.4.0-rc.11, update yarn.lock
  • 77eb43c v6.4.0-rc.11
  • ca91e77 Update root, peer deps, version.ts/json to 6.4.0-rc.11 [ci skip]
  • 52ed4b0 6.4.0-rc.11 changelog
  • 4f23295 Merge pull request #16795 from SebastienGllmt/patch-1
  • d443c73 Fix breaking changing process/browser
  • 16678e0 6.4.0-rc.10 next.json version file
  • 0e8f1c2 Update git head to 6.4.0-rc.10, update yarn.lock
  • 5ae60fc v6.4.0-rc.10
  • 135ca93 Update root, peer deps, version.ts/json to 6.4.0-rc.10 [ci skip]
  • a89d8e9 6.4.0-rc.10 changelog
  • 68c4086 Merge pull request #16791 from storybookjs/16756-argTypes-storiesOf
  • 0a03181 Merge pull request #16788 from storybookjs/16767-sort-stories-index
  • 8b4b8fc Merge pull request #16783 from storybookjs/remove-missing-console-error
  • 465a4be Merge branch 'next' into 16756-argTypes-storiesOf
  • 1799997 Merge pull request #16792 from storybookjs/16745-fix-docs-story-rendered
  • 38aadfc Merge pull request #16790 from storybookjs/16743-argTypeTargets-no-args
  • 068ee39 Fix typo
  • 809b59e Remove console log
  • 1636334 Wait for the story component to render before emitting

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

Sambego avatar May 13 '22 19:05 Sambego