nextjs-fcm
nextjs-fcm copied to clipboard
[Snyk] Upgrade: react, react-dom
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together. :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.| Name | Versions | Released on |
|---|---|---|
| reactfrom 16.13.1 to 16.14.0 | 1 version ahead of your current version | 3 years agoon 2020-10-14 |
| react-domfrom 16.13.1 to 16.14.0 | 1 version ahead of your current version | 3 years agoon 2020-10-14 |
The recommended version fixes:
| Severity | Issue | PriorityScore (*) | Exploit Maturity |
|---|---|---|---|
| Command Injection SNYK-JS-LODASH-1040724 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Denial of Service (DoS) SNYK-JS-DECODEURICOMPONENT-3149970 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-OBJECTPATH-1017036 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-OBJECTPATH-1585658 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-LOADERUTILS-3043105 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-LOADERUTILS-3043105 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-LOADERUTILS-3043105 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Remote Code Execution (RCE) SNYK-JS-SHELLQUOTE-1766506 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-SSRI-1246392 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-SSRI-1246392 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Arbitrary File Overwrite SNYK-JS-TAR-1536528 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Arbitrary File Overwrite SNYK-JS-TAR-1536531 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Arbitrary File Write SNYK-JS-TAR-1579147 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Arbitrary File Write SNYK-JS-TAR-1579152 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Arbitrary File Write SNYK-JS-TAR-1579155 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-UNSETVALUE-2400660 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-BROWSERSLIST-1090194 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Cryptographic Issues SNYK-JS-ELLIPTIC-1064899 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-GLOBPARENT-1016905 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-GLOBPARENT-1016905 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-JSON5-3182856 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-JSON5-3182856 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-OBJECTPATH-1569453 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-PATHPARSE-1077067 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-POSTCSS-1090595 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-POSTCSS-1255640 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-POSTCSS-1090595 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-POSTCSS-1255640 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-LOADERUTILS-3042992 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-LOADERUTILS-3105943 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-LOADERUTILS-3042992 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-LOADERUTILS-3105943 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-LOADERUTILS-3042992 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-LOADERUTILS-3105943 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-LODASH-1018905 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-MINIMATCH-3050818 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Open Redirect SNYK-JS-NEXT-1540422 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Denial of Service SNYK-JS-NODEFETCH-674311 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-TERSER-2806366 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-MINIMIST-2429795 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-TAR-1536758 |
467/1000 Why? Proof of Concept exploit, CVSS 7.2 |
No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: react
-
16.14.0 - 2020-10-14
React
- Add support for the new JSX transform. (@ lunaruan in #18299)
-
16.13.1 - 2020-03-19
React DOM
- Fix bug in legacy mode Suspense where effect clean-up functions are not fired. This only affects users who use Suspense for data fetching in legacy mode, which is not technically supported. (@ acdlite in #18238)
- Revert warning for cross-component updates that happen inside class render lifecycles (
componentWillReceiveProps,shouldComponentUpdate, and so on). (@ gaearon in #18330)
Artifacts
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
Package name: react-dom
-
16.14.0 - 2020-10-14
React
- Add support for the new JSX transform. (@ lunaruan in #18299)
-
16.13.1 - 2020-03-19
React DOM
- Fix bug in legacy mode Suspense where effect clean-up functions are not fired. This only affects users who use Suspense for data fetching in legacy mode, which is not technically supported. (@ acdlite in #18238)
- Revert warning for cross-component updates that happen inside class render lifecycles (
componentWillReceiveProps,shouldComponentUpdate, and so on). (@ gaearon in #18330)
Artifacts
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🔕 Ignore this dependency or unsubscribe from future upgrade PRs