asset-system
asset-system copied to clipboard
[Snyk] Security upgrade svgo from 1.3.2 to 2.3.1
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- packages/bundle/package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-CSSWHAT-1298035 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: svgo
The new version differs by 199 commits.- daf2f88 2.3.1
- 25d0f87 Upgrade css-select from `^3.1.2` to `^4.1.3` (#1485)
- 59876d8 Remove unused artifacts
- 68798eb Mark convertStyleToAttrs as `disabled` in README (#1472)
- 3d79f57 Convert convertPathData to visitor
- 06110b4 Convert mergePaths to visitor
- 368a67b Convert removeHiddenElems to visitor
- 17aaf36 Cleanup collapseGroups tests
- e381ccc 2.3.0
- 09aec37 Implement exclude pattern cli option (#1409)
- e3f37ec Add mergeStyles to readme
- 27bef1a Add "visitor" plugins support (#1454)
- 19c77d2 Add mergeStyles plugin (#1381)
- d89d36e Split regression extracter and runner (#1451)
- eb934b4 Serve svg for regressions and cache w3c test suite
- 7389bcd Override default floatPrecision with global
- d08815c Implement simple node clone (#1450)
- 3d4adb6 Simplify number rendering and fix -0 in path
- 316a002 Remove hasAttr and hasAttrLocal usages (#1447)
- 447f82c Convert addAttributesToSVGElement to item plugin (#1448)
- 13a0ad0 Specify --ignore-path for ESLint (#1443)
- e8d563c Fix invalid radix in cli (#1446)
- bc5c4ea Add a test for removeXMLNS plugin (#1444)
- 3390df1 removeOffCanvasPaths: Add one more test (#1445)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report