Skip to content
This repository has been archived by the owner on Mar 13, 2020. It is now read-only.

[Snyk] Upgrade react-scripts from 2.0.4 to 2.1.8 #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented Feb 5, 2020

Snyk has created this PR to upgrade react-scripts from 2.0.4 to 2.1.8.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 13 versions ahead of your current version.
  • The recommended version was released a year ago, on 2019-03-07.

The recommended version fixes:

Severity Issue Exploit Maturity
Information Exposure
SNYK-JS-WEBPACKDEVSERVER-72405
No Known Exploit
Prototype Pollution
SNYK-JS-HANDLEBARS-534988
No Known Exploit
Arbitrary Code Execution
SNYK-JS-HANDLEBARS-534478
No Known Exploit
Denial of Service (DoS)
SNYK-JS-HANDLEBARS-480388
No Known Exploit
Prototype Pollution
SNYK-JS-HANDLEBARS-469063
No Known Exploit
Arbitrary Code Execution
SNYK-JS-ESLINTUTILS-460220
No Known Exploit
Denial of Service (DoS)
npm:mem:20180117
No Known Exploit
Timing Attack
SNYK-JS-ELLIPTIC-511941
No Known Exploit
Information Disclosure
SNYK-JS-KINDOF-537849
Proof of Concept
Release notes
Package name: react-scripts
  • 2.1.8 - 2019-03-07
  • 2.1.7 - 2019-03-07
  • 2.1.6 - 2019-03-06
  • 2.1.5 - 2019-02-11
  • 2.1.4 - 2019-02-10
  • 2.1.3 - 2019-01-04
  • 2.1.3-next.6a95aae9 - 2019-01-04
  • 2.1.2 - 2018-12-23
  • 2.1.1 - 2018-11-01
  • 2.1.0 - 2018-10-30
  • 2.0.6-next.c662dfb0 - 2018-10-25
  • 2.0.6-next.9b4009d7 - 2018-10-24
  • 2.0.5 - 2018-10-14
  • 2.0.4 - 2018-10-03
from react-scripts GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

[//]: # (snyk:metadata:{"dependencies":[{"name":"react-scripts","from":"2.0.4","to":"2.1.8"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/cule219/project/6370b953-1f6d-4837-8751-c274c488a802?utm_source=github&utm_medium=upgrade-pr","projectPublicId":"6370b953-1f6d-4837-8751-c274c488a802","env":"prod","prType":"upgrade","vulns":["SNYK-JS-WEBPACKDEVSERVER-72405","SNYK-JS-HANDLEBARS-534988","SNYK-JS-HANDLEBARS-534478","SNYK-JS-HANDLEBARS-480388","SNYK-JS-HANDLEBARS-469063","SNYK-JS-ESLINTUTILS-460220","npm:mem:20180117","SNYK-JS-ELLIPTIC-511941","SNYK-JS-KINDOF-537849"],"issuesToFix":[{"issueId":"SNYK-JS-WEBPACKDEVSERVER-72405","severity":"high","title":"Information Exposure","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-HANDLEBARS-534988","severity":"high","title":"Prototype Pollution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-HANDLEBARS-534478","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-HANDLEBARS-480388","severity":"high","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-HANDLEBARS-469063","severity":"high","title":"Prototype Pollution","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-ESLINTUTILS-460220","severity":"high","title":"Arbitrary Code Execution","exploitMaturity":"no-known-exploit"},{"issueId":"npm:mem:20180117","severity":"medium","title":"Denial of Service (DoS)","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-ELLIPTIC-511941","severity":"medium","title":"Timing Attack","exploitMaturity":"no-known-exploit"},{"issueId":"SNYK-JS-KINDOF-537849","severity":"low","title":"Information Disclosure","exploitMaturity":"proof-of-concept"}],"upgrade":["SNYK-JS-WEBPACKDEVSERVER-72405","SNYK-JS-HANDLEBARS-534988","SNYK-JS-HANDLEBARS-534478","SNYK-JS-HANDLEBARS-480388","SNYK-JS-HANDLEBARS-469063","SNYK-JS-ESLINTUTILS-460220","npm:mem:20180117","SNYK-JS-ELLIPTIC-511941","SNYK-JS-KINDOF-537849"],"upgradeInfo":{"versionsDiff":13,"publishedDate":"2019-03-07T00:53:37.511Z"},"templateVariants":[],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false})

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
1 participant