react-mapycz
react-mapycz copied to clipboard
build(deps-dev): Bump react-syntax-highlighter and @types/react-syntax-highlighter
Bumps react-syntax-highlighter and @types/react-syntax-highlighter. These dependencies needed to be updated together.
Updates react-syntax-highlighter
from 15.4.4 to 15.5.0
Release notes
Sourced from react-syntax-highlighter's releases.
15.5.0
- react-syntax-highlighter/react-syntax-highlighter#466: updated prismjs to 1.27.0, fixing the XSS vuln mentioned in react-syntax-highlighter/react-syntax-highlighter#461
As noted in the PR, updating
prism
usually brings along a few surprises; this one gave us a new programming language namedfalse
, which as you can imagine is fun to import and parse within Javascript.Thanks to everyone for your patience. We'll be getting back in the groove of regular releases here.
Commits
- See full diff in compare view
Updates @types/react-syntax-highlighter
from 13.5.2 to 15.5.5
Commits
- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)