asset-system icon indicating copy to clipboard operation
asset-system copied to clipboard

[Snyk] Security upgrade svgo from 1.3.2 to 2.3.1

Open snyk-bot opened this issue 4 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/bundle/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CSSWHAT-1298035
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: svgo The new version differs by 199 commits.
  • daf2f88 2.3.1
  • 25d0f87 Upgrade css-select from `^3.1.2` to `^4.1.3` (#1485)
  • 59876d8 Remove unused artifacts
  • 68798eb Mark convertStyleToAttrs as `disabled` in README (#1472)
  • 3d79f57 Convert convertPathData to visitor
  • 06110b4 Convert mergePaths to visitor
  • 368a67b Convert removeHiddenElems to visitor
  • 17aaf36 Cleanup collapseGroups tests
  • e381ccc 2.3.0
  • 09aec37 Implement exclude pattern cli option (#1409)
  • e3f37ec Add mergeStyles to readme
  • 27bef1a Add "visitor" plugins support (#1454)
  • 19c77d2 Add mergeStyles plugin (#1381)
  • d89d36e Split regression extracter and runner (#1451)
  • eb934b4 Serve svg for regressions and cache w3c test suite
  • 7389bcd Override default floatPrecision with global
  • d08815c Implement simple node clone (#1450)
  • 3d4adb6 Simplify number rendering and fix -0 in path
  • 316a002 Remove hasAttr and hasAttrLocal usages (#1447)
  • 447f82c Convert addAttributesToSVGElement to item plugin (#1448)
  • 13a0ad0 Specify --ignore-path for ESLint (#1443)
  • e8d563c Fix invalid radix in cli (#1446)
  • bc5c4ea Add a test for removeXMLNS plugin (#1444)
  • 3390df1 removeOffCanvasPaths: Add one more test (#1445)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

snyk-bot avatar Jun 27 '21 02:06 snyk-bot