gatsby-project-kb
gatsby-project-kb copied to clipboard
[Snyk] Security upgrade gatsby from 4.25.8 to 5.13.2
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- demo/package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
631/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 6.2 |
Missing Release of Resource after Effective Lifetime SNYK-JS-INFLIGHT-6095116 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: gatsby
The new version differs by 250 commits.- b24134d chore(release): Publish
- c74745c fix(gatsby): support builtin modules prefixed with `node:` on `build-html` (#38516) (#38818)
- c9f8c24 chore: swap babel-plugin-lodash with updated version that doesn't use deprecated APIs (#38797) (#38803)
- fc0eea1 fix(gatsby): fix webpack compilation when pnpm is used (#38757) (#38804)
- f6ed443 fix(gatsby): try to automatically recover when parcel segfaults (#38773) (#38799)
- 68b0821 fix(gatsby): more robust adapter zero-conf handling (#38778) (#38800)
- 366b54c chore(release): Publish
- 4b892c5 chore(gatsby-cli,gatsby-source-wordpress): bump clipboardy (#38775) (#38776)
- 2c0622c chore(release): Publish
- 5d6bb65 fix(docs): update remote url docs (#38768) (#38770)
- 18ffcfa chore(release): Publish
- 1953e5c fix(gatsby): allow gatsby-adapter-netlify@">=1.0.0 <=1.0.3" for gatsby@<5.12.10 (#38758)
- 4a780fb feat: image and file cdn url generator adapter implementation (#38685)
- f8c207b chore: move gatsby-plugin-netlify-cms to deprecated-packages (#38755)
- 6d1d97e chore(gatsby-plugin-netlify-cms): add deprecation notice (#38753)
- 7a7fa5f chore(deps): update dependency @ types/jscodeshift to ^0.11.11 for gatsby-codemods (#38595)
- 8919982 fix(deps): update dependency gatsby-plugin-webpack-bundle-analyser-v2 to ^1.1.32 (#38722)
- d148295 chore(deps): update [dev] minor and patch dependencies for gatsby-cli (#38592)
- 37f2288 chore(deps): update dependency rimraf to ^5.0.5 (#38596)
- 0faf0fe chore(deps): update dependency rimraf to ^5.0.5 for gatsby-telemetry (#38597)
- 31272e9 chore(deps): update dependency rimraf to ^5.0.5 for gatsby-worker (#38598)
- edcb035 chore(deps): update dependency start-server-and-test to ^2.0.3 (#38599)
- 956e30c chore(deps): update dependency wait-on to ^7.2.0 (#38724)
- c1138ad chore(deps): update dependency fs-extra to ^11.2.0 (#38723)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.