spark-design-system
spark-design-system copied to clipboard
[Snyk] Security upgrade gatsby-plugin-mdx from 1.2.15 to 2.14.1
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
691/1000 Why? Recently disclosed, Has a fix available, CVSS 8.1 |
Deserialization of Untrusted Data SNYK-JS-GATSBYPLUGINMDX-2405699 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: gatsby-plugin-mdx
The new version differs by 250 commits.- 4997d63 chore(release): Publish
- ff94ed5 fix(gatsby-plugin-mdx): don't allow JS frontmatter by default (#35830) (#35834)
- 36f21b0 chore: Removate validate-renovate from v3-latest branch (#34460)
- 1acb1bc chore(release): Publish
- 1589bd8 fix(gatsby): ensure that writing node manifests to disk does not break on Windows (#33853) (#34020)
- 9694010 fix(gatsby-source-drupal): Ensure all new nodes are created before creating relationships (#33864) (#34019)
- 76deb39 fix(gatsby-source-drupal): searcParams missing from urls (#33861) (#34018)
- f74cc8f feat(gatsby-source-drupal): Add node manifest support for previews (#33683) (#34017)
- 476a591 chore(release): Publish
- 35b48f8 fix(gatsby-plugin-image): GatsbyImage not displaying image in IE11 (#33416) (#33806)
- 880022e fix(gatsby-plugin-image): flickering when state changes (#33732) (#33807)
- c0d07e7 feat(gatsby-source-wordpress): Update supported-remote-plugin-versions.ts (#33801) (#33804)
- 3d9a702 chore(release): Publish
- 84053a2 fix(gatsby-plugin-sharp): pass input buffer instead of readStream when processing image jobs (#33685) (#33703)
- 4722a0d fix(gatsby-source-drupal): Add timeout in case of stalled API requests (#33668) (#33705)
- 857a628 fix(gatsby): single page node manifest accuracy (#33642) (#33698)
- 6bfd0f1 Properly set the pathPrefix and assetPrefix in the pluginData (#33667) (#33702)
- 26c51c0 fix(gatsby-source-drupal): cache backlink records (#33444) (#33701)
- b80c53a fix(gatsby-source-drupal): Correctly update nodes with changed back references so queries are re-run (#33328) (#33699)
- e29a194 chore: use gatsby-dev-cli@latest-v3 in tests
- f90c61c chore(lerna): use latest-v3 npm dist tag (#33638)
- fdf616c chore(release): Publish
- d4cf891 fix(gatsby): use lmdb.removeSync so getNode can't return deleted nodes (#33554) (#33633)
- c692e1f chore(release): Publish
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons: