react-loosely-lazy icon indicating copy to clipboard operation
react-loosely-lazy copied to clipboard

[Snyk] Security upgrade @parcel/plugin from 2.0.0-rc.0 to 2.0.0

Open snyk-bot opened this issue 2 years ago • 0 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/plugins/parcel-reporter-manifest/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 566/1000
Why? Recently disclosed, Has a fix available, CVSS 5.6
Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430337
No No Known Exploit
high severity 651/1000
Why? Recently disclosed, Has a fix available, CVSS 7.3
Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430339
No No Known Exploit
medium severity 566/1000
Why? Recently disclosed, Has a fix available, CVSS 5.6
Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430341
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @parcel/plugin The new version differs by 90 commits.
  • 84da50a v2.0.0
  • aa0a369 Small copy change
  • c78601b shouldVisitChild: Check parent and child node previously deferred separately (#7043)
  • 2c83842 Fix scope resolution for TS enums (#7057)
  • dbe1153 Fix order of hoisted variable declarations (#7053)
  • bea9442 Fix named export with different export name for wrapped assets (#7052)
  • 2175e1b Mark '*' as used when the reexport is only decided at runtime (#7049)
  • 4312b91 Update Micromatch (#6958)
  • 5afe766 Fail when unable to build a native package (#6962)
  • 971ed24 Update watcher and source-map library to 2.0.0 (#7044)
  • 810a854 Add missing C flags for SIMD support in build workflow (#7045)
  • d6de61d Fix shaking for functions types with overload signatures (#7036)
  • daf2cd9 Safely position the HMR script (#6961)
  • 89b4e51 Unmark defer for dependency that become used ('does not export') (#7035)
  • b575212 Bump swc (#7033)
  • 415710f Fix CSS tree shaking with 'build --no-scope-hoist' (#5728)
  • ea0f4e4 Allow jsx and tsx as lang for script block in Vue SFCs (#6983)
  • d2d4f1c Never enable JSX in a .ts file (#7031)
  • aafc318 Don't use deprecated querystring package (#6806)
  • a6a6fb2 Fix cache invalidation when shouldOptimize changes (#7030)
  • 7d4d53a Update all references to v2.parceljs.org to just parceljs.org (#7029)
  • 91de5c0 Ensure symbol order is consistent (#7021)
  • 2ebed00 Ensure named exports are prioritized over wildcard re-exports (#7016)
  • 4904f20 Fix autoinstall with Yarn 2+ (#7023)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

snyk-bot avatar Mar 21 '22 01:03 snyk-bot