Skip to content
This repository has been archived by the owner on Feb 4, 2023. It is now read-only.

[Snyk] Security upgrade @strapi/strapi from 4.0.2 to 4.2.3 #11

Merged
merged 1 commit into from Nov 27, 2022

Conversation

DzmitrySha
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-LOADERUTILS-3043105
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @strapi/strapi The new version differs by 250 commits.
  • fe296ba v4.2.3
  • e2b48c6 Merge pull request #13637 from meherchandan/fix/knex-migration-transaction-error
  • b2be3d4 Merge pull request #13759 from strapi/chore/ctb-tab-label
  • 849213e Merge pull request #13740 from strapi/chore/jest-28
  • 8b4644b revert errors.test.js
  • 4570dd6 CTB: Improve tab labels
  • 710a39f Merge pull request #13751 from Le-Bit/typo-can-by-used
  • 2e926e6 revert strapi.start to load and listen
  • 5706191 fix unit tests open handles
  • d48d91e fix open handles
  • e9bfdca fix worker-queue.test.js
  • 9d0a01a fix add-missing-keys-to-other-language.test.js
  • 6d265c2 fix permission-domain.test.js
  • f98c00f chore: Update jest to 28.x
  • 0b1faa8 Merge pull request #13748 from strapi/fix/jest-config-github
  • 5d831d4 fix: typo
  • 91c2004 Fix jest running because of .github and jest weird behavior
  • 141ef84 Merge pull request #13746 from strapi/fix/richtext-table
  • ed129b8 Merge pull request #13676 from benderillo/fix-13675-send-components
  • e87ada0 PreviewWysiwyg: Fix and improve styles for tables
  • d0c29fe Merge pull request #13594 from SarkarKurdish/master
  • 4c1fad8 Merge pull request #13495 from poonamdhangar/master
  • 9229d8d Merge pull request #13730 from strapi/dependabot/npm_and_yarn/css-loader-6.7.1
  • 006aeb4 updated iso locales snapshot

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

馃 Prototype Pollution

@DzmitrySha DzmitrySha merged commit 9b5dc1b into main Nov 27, 2022
@DzmitrySha DzmitrySha deleted the snyk-fix-ef8224807a4384ed8f0abfff9b227bce branch January 26, 2023 15:25
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
2 participants