codesandbox-client
codesandbox-client copied to clipboard
[Snyk] Security upgrade gatsby-plugin-sharp from 2.14.4 to 4.23.0
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- packages/homepage/package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-NTHCHECK-1586032 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: gatsby-plugin-sharp
The new version differs by 250 commits.- 92543af chore(release): Publish
- e79623c fix(create-gatsby): Missing "plugins" in cmses.json (#36566)
- a373d80 chore(docs): Remove `content` from sourcing guide (#36562)
- 8b59183 fix(gatsby): Remove default support for non ESM browsers (#36522)
- fab2db2 chore: setup v5 release channel (#36540)
- bac1e7a chore(gatsby): Update `react-refresh` to `^0.14.0` (#36553)
- 5f6ad91 chore(deps): update dependency autoprefixer to ^10.4.8 for gatsby-plugin-sass (#36273)
- cc3ef79 fix(deps): update dependency eslint-plugin-react-hooks to ^4.6.0 (#36040)
- 856b695 chore(deps): update [dev] minor and patch dependencies for gatsby-legacy-polyfills (#35547)
- 0b6e823 chore(deps): update dependency @ types/semver to ^7.3.12 (#36510)
- 0e56ad6 chore(deps): update dependency microbundle to ^0.15.1 for gatsby-link (#36512)
- 80f6616 chore(deps): update dependency microbundle to ^0.15.1 for gatsby-script (#36513)
- 34c8e51 fix(deps): update dependency eslint-plugin-jsx-a11y to ^6.6.1 (#36039)
- afba8ca chore(deps): update [dev] minor and patch dependencies for gatsby-source-shopify (#34363)
- b55e1d5 chore(docs): monorepos support (#36504)
- 8aeae21 fix(gatsby): pass custom graphql context provided by createResolverContext to materialization executor (#36552)
- 9c5eacf fix(gatsby): Handle renderToPipeableStream errors (#36555)
- 42e241c feat(gatsby): split up head & page component loading (#36545)
- dc9aa9a chore(gatsby): perfect `GatsbyConfig.proxy` type (#36548)
- 1125e58 fix: ci pipeline (#36544)
- 7fe8e51 fix(deps): update dependency react-docgen to ^5.4.3 for gatsby-transformer-react-docgen (#36277)
- bc04e8f chore(docs): migrate cloud docs to dotcom(1) (#36452)
- 59c1f4f fix(deps): update starters and examples - gatsby (#36503)
- 0d4dfe9 chore(docs): update url of `deleteNode` (#36502)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:

Open in CodeSandbox Web Editor | VS Code | VS Code Insiders
Build for latest commit https://github.com/codesandbox/codesandbox-client/pull/6889/commits/68d4bd3145d2d6b7084ae938f2440d8e907a8b86 failed.