lattice
lattice copied to clipboard
[Snyk] Fix for 2 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- packages/froala-editor/package.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
626/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 6.1 |
Cross-site Scripting (XSS) SNYK-JS-FROALAEDITOR-5902996 |
Yes | Proof of Concept |
![]() |
626/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 6.1 |
Cross-site Scripting (XSS) SNYK-JS-FROALAEDITOR-6009154 |
Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: react-froala-wysiwyg
The new version differs by 45 commits.- ce10ec4 Update to v4.1.4
- a54711e Update to v4.1.3
- 1ebdc99 Update to v4.1.2
- 3a0f305 Update to v4.1.1
- 400d5a3 Update to v4.1.0 (#373)
- 87d0038 Update to v4.0.19
- 199aeb7 CI/CD changes (#363)
- e94dd03 Added dist folder in the ignore list
- 4b112e3 Update to v4.0.18
- 18d13cb Cicd changes (#348)
- de18d36 Update to v4.0.17
- 447847a Update to v4.0.16
- 6a53776 Update to v4.0.15
- bf9491d Update to v4.0.14
- 2b41933 Merge pull request #336 from CelestialSystem/cel-4409
- fae2c41 Fixed:4409
- 5c91076 Merge pull request #334 from CelestialSystem/cel-4409
- a12864a Fixed:4409
- d19a207 Fixed:4409
- bf3a7ba Merge pull request #327 from h3rmanj/master
- e0fb95e Update to v4.0.13
- b1483ec Update to v4.0.12
- 1ba1984 Update to v4.0.11
- dbeb388 Support React 18
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: