surveyjs_react_quickstart
surveyjs_react_quickstart copied to clipboard
Bump jspdf from 1.5.3 to 3.0.1
Bumps jspdf from 1.5.3 to 3.0.1.
Release notes
Sourced from jspdf's releases.
v3.0.1
This release fixes two security vulnerabilities:
- Upgrade optional dependency canvg to 3.0.11
- Fix a ReDoS vulnerability in the
addImagemethod and the methodshtmlandaddSvgAsImage, which depend onaddImagev3.0.0
This major release officially drops support for Internet Explorer and fixes a security vulnerability in the
htmlfunction by updating the optional dependencydompurifyto v3.2.4. There are no other breaking changes.New Contributors
@nlqivisionmade their first contribution in parallax/jsPDF#3812@dependabotmade their first contribution in parallax/jsPDF#3826@hainenbermade their first contribution in parallax/jsPDF#3827Full Changelog: https://github.com/parallax/jsPDF/compare/v2.5.2...v3.0.0
v2.5.2
This release upgrades the Dompurify dependency to 2.5.4 with fixes a vulnerability with high severity: https://github.com/advisories/GHSA-mmhx-hmjr-r674.
It also upgrades fflate, core-js, and
@babel/runtimeto more recent versions.What's Changed
- Implement justifying for unicode fonts by
@owenl131in parallax/jsPDF#3285- chore: update dompurify version 2.5.4 by
@MarcioMeierin parallax/jsPDF#3768- [Snyk] Upgrade fflate from 0.4.8 to 0.8.1 by
@MrRioin parallax/jsPDF#3666- [Snyk] Upgrade core-js from 3.6.5 to 3.33.0 by
@MrRioin parallax/jsPDF#3664- [Snyk] Upgrade
@babel/runtimefrom 7.14.6 to 7.23.2 by@MrRioin parallax/jsPDF#3665v2.5.1
This release fixes two security related issues.
- #3348: Check integrity when loading the pdfobject lib from CDN in calls to
output('pdfobjectnewwindow')- #3368: Fix inefficient regular expression in
setDisplayMode(CWE-1333)v2.5.0
This release adds some minor new features and fixes some bugs, e.g. related to multiline text. Thanks to all contributors!
New Features
Bugfixes
- #3271: fix
htmlfunction only rendering on the first invocation per document- #3304, #3295: fix
context2D.closePath(now properly closes the path)- #3274: fix Acroform text fields with multiline text
- #3281: fix
textWithLinkfor multiline text- #3283: fix
lineHeightFactorintextoptions having no effect- #3302: fixes to
htmltypings- #3272: fix return type of
savefunction in typings (promise overload)
... (truncated)
Commits
57cbe943.0.17cf6ddffix: upgrade@babel/runtimefrom 7.26.0 to 7.26.7 (#3832)b167c43improve performance of data url parsing in addimage (#3843)c4b7421don't use saucelabs in CI to be able to correctly run CI for PRs6136d4bUpgrade canvg from 3.0.6 to 3.0.11 (#3836)d0c605f3.0.07aa332efix(sec): remove MSIE support to allow upgrading to vuln-freedompurifyv3 ...e2c1818Bump rollup from 2.21.0 to 2.79.2 (#3826)5aad456fix: upgrade@babel/runtimefrom 7.25.6 to 7.26.0 (#3822)637b5d3Upgrade dompurify to 2.5.6 to 2.5.8 (#3812)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.