cal.com icon indicating copy to clipboard operation
cal.com copied to clipboard

[Snyk] Security upgrade @calcom/embed-react from 0.0.0-use.local to 1.0.0

Open pumfleet opened this issue 8 months ago • 3 comments
trafficstars

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • apps/web/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory. If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELHELPERS-9397697

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

pumfleet avatar Mar 13 '25 19:03 pumfleet

The latest updates on your projects. Learn more about Vercel for Git ↗︎

2 Skipped Deployments
Name Status Preview Comments Updated (UTC)
cal ⬜️ Ignored (Inspect) Visit Preview Mar 13, 2025 7:17pm
calcom-web-canary ⬜️ Ignored (Inspect) Visit Preview Mar 13, 2025 7:17pm

vercel[bot] avatar Mar 13 '25 19:03 vercel[bot]

Hey there and thank you for opening this pull request! 👋🏼

We require pull request titles to follow the Conventional Commits specification and it looks like your proposed title needs to be adjusted.

Details:

No release type found in pull request title "[Snyk] Security upgrade @calcom/embed-react from 0.0.0-use.local to 1.0.0". Add a prefix to indicate what kind of release this pull request corresponds to. For reference, see https://www.conventionalcommits.org/

Available types:
 - feat: A new feature
 - fix: A bug fix
 - docs: Documentation only changes
 - style: Changes that do not affect the meaning of the code (white-space, formatting, missing semi-colons, etc)
 - refactor: A code change that neither fixes a bug nor adds a feature
 - perf: A code change that improves performance
 - test: Adding missing tests or correcting existing tests
 - build: Changes that affect the build system or external dependencies (example scopes: gulp, broccoli, npm)
 - ci: Changes to our CI configuration files and scripts (example scopes: Travis, Circle, BrowserStack, SauceLabs)
 - chore: Other changes that don't modify src or test files
 - revert: Reverts a previous commit

github-actions[bot] avatar Mar 13 '25 19:03 github-actions[bot]

Graphite Automations

"Add consumer team as reviewer" took an action on this PR • (03/13/25)

1 reviewer was added to this PR based on Keith Williams's automation.

graphite-app[bot] avatar Mar 13 '25 19:03 graphite-app[bot]

This PR is being marked as stale due to inactivity.

github-actions[bot] avatar Mar 28 '25 00:03 github-actions[bot]

This needs an exclusion. Will add.

keithwillcode avatar Mar 28 '25 14:03 keithwillcode