Skip to content

[Snyk] Security upgrade webpack from 5.75.0 to 5.76.0#2246

Merged
thisislawatts merged 1 commit intomasterfrom
snyk-fix-8a135a9e1f2faae30b1b8ef8577a75af
Apr 27, 2023
Merged

[Snyk] Security upgrade webpack from 5.75.0 to 5.76.0#2246
thisislawatts merged 1 commit intomasterfrom
snyk-fix-8a135a9e1f2faae30b1b8ef8577a75af

Conversation

@snyk-bot
Copy link
Copy Markdown
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/components/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 736/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.3
Sandbox Bypass
SNYK-JS-WEBPACK-3358798
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@snyk-bot snyk-bot requested a review from a team as a code owner April 26, 2023 14:00
@thisislawatts thisislawatts force-pushed the snyk-fix-8a135a9e1f2faae30b1b8ef8577a75af branch from 194d4d9 to a56316c Compare April 26, 2023 14:01
@thisislawatts thisislawatts force-pushed the snyk-fix-8a135a9e1f2faae30b1b8ef8577a75af branch 4 times, most recently from 2487e7d to 0bb019c Compare April 26, 2023 15:31
@cypress
Copy link
Copy Markdown

cypress bot commented Apr 26, 2023

1 flaky tests on run #3376 ↗︎

0 82 0 0 Flakiness 1

Details:

fix: packages/components/package.json to reduce vulnerabilities
Project: onearmy-community-platform Commit: f49c4ce051
Status: Passed Duration: 03:52 💡
Started: Apr 27, 2023 1:09 PM Ended: Apr 27, 2023 1:13 PM
Flakiness  src/integration/common.spec.ts • 1 flaky test • ci-chrome

View Output Video

Test Artifacts
[Common] > [User Menu] > [By Authenticated] Output Screenshots

This comment has been generated by cypress-bot as a result of this project's GitHub integration settings.

@thisislawatts thisislawatts force-pushed the snyk-fix-8a135a9e1f2faae30b1b8ef8577a75af branch from 0bb019c to f49c4ce Compare April 27, 2023 13:00
@thisislawatts thisislawatts enabled auto-merge April 27, 2023 13:00
@thisislawatts thisislawatts merged commit 30d2003 into master Apr 27, 2023
@thisislawatts thisislawatts deleted the snyk-fix-8a135a9e1f2faae30b1b8ef8577a75af branch April 27, 2023 13:07
@cypress cypress bot mentioned this pull request Apr 27, 2023
@onearmy-bot
Copy link
Copy Markdown
Collaborator

🎉 This PR is included in version 1.49.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

4 participants