taquito icon indicating copy to clipboard operation
taquito copied to clipboard

[Snyk] Security upgrade @docusaurus/preset-classic from 2.4.3 to 3.5.0

Open michaelkernaghan opened this issue 1 year ago • 3 comments

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • website/package.json
    • website/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 601/1000
Why? Recently disclosed, Has a fix available, CVSS 6.3
Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @docusaurus/preset-classic The new version differs by 250 commits.
  • cb5829f v3.5.0
  • a19d54f Merge remote-tracking branch 'origin/slorber/docusaurus-v3.5' into slorber/docusaurus-v3.5
  • ea49177 3.5 docs
  • 55a58ee changelog
  • 8f8f7f2 Merge branch 'main' into slorber/docusaurus-v3.5
  • a096bbc feat(blog): add `onUntruncatedBlogPosts` blog options (#10375)
  • 2611aa1 refactor: apply lint autofix
  • f9e5adb v3.5 blog post
  • c3af215 v3.5 blog post
  • af24976 v3.5 blog post
  • 2028ca4 v3.5 blog post
  • f43be85 fix(translations): fix wrong Estonian (et) translations and typos (#10344)
  • a2e30be fix(search): fix algolia search ignore ctrl + F in search input (#10342)
  • 44ddada fix(docs): the _category_.json description attribute should display on generated index pages (#10324)
  • 95ab9f8 feat(theme): show unlisted/draft banners in dev mode (#10376)
  • c58fcbd feat(ci): continuous releases for main and PRs with pkg.pr.new (#10369)
  • 087a329 fix(cli): Fix bad docusaurus CLI behavior on for --version, -V, --help, -h (#10368)
  • 7be1fea feat(blog): add feed xlst options to render beautiful RSS and Atom feeds (#9252)
  • 08a893a chore: add prettier-xml plugin (#10364)
  • f356e29 feat(blog): authors page (#10216)
  • 50f9fce docs: rename @ getcanary/docusaurus-pagefind in docs (#10361)
  • 347070b fix(translations): Fix and Improve Spanish translations (#10360)
  • 95990c6 docs: Add @ getcanary/docusaurus-pagefind in docs (#10345)
  • 40676cd chore(deps): update infima npm dependency to version 0.2.0-alpha.44 (#10343)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

michaelkernaghan avatar Oct 09 '24 20:10 michaelkernaghan

Deploying taquito with  Cloudflare Pages  Cloudflare Pages

Latest commit: 5f50086
Status: ✅  Deploy successful!
Preview URL: https://054c8ac2.taquito.pages.dev
Branch Preview URL: https://snyk-fix-b6d6e0d7c34b485e1e7.taquito.pages.dev

View logs

A new deploy preview is available on Cloudflare Pages at https://307f577b.taquito-test-dapp.pages.dev

github-actions[bot] avatar Oct 09 '24 20:10 github-actions[bot]

New packages have been deployed to the preview repository at https://npm.preview.tezostaquito.io/.

Published packages:

npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/
npm i @taquito/[email protected] --registry https://npm.preview.tezostaquito.io/

github-actions[bot] avatar Oct 09 '24 21:10 github-actions[bot]

duplicate with pr #3082 therefore closing this one

hui-an-yang avatar Nov 08 '24 17:11 hui-an-yang