Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade bootstrap-vue from 2.2.2 to 2.22.0 #36

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade bootstrap-vue from 2.2.2 to 2.22.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 32 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2022-04-17.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Denial of Service
SNYK-JS-NODEFETCH-674311
306/1000
Why? CVSS 5.9
No Known Exploit
Information Exposure
SNYK-JS-NODEFETCH-2342118
306/1000
Why? CVSS 5.9
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: bootstrap-vue
  • 2.22.0 - 2022-04-17

    🚀 Features

    • b-link
      • #6811 Support exact-path and exact-path-active-class props for router link
    • b-form-tags
      • #6395 Adds focusin & focusout to wrapper and prevents firing multiple focus/blur events
      • #6347 Add feedback-aria-live prop
    • general
      • #6375 Add headerTag and footerTag props to all componets with header and footer
    • b-dropdown
      • #6339 Add toggle-attrs prop

    🐛 Bug Fixes

    • general
      • #6834 Replace sass division with multiplication
    • b-table
      • #6645 Selected table header text no longer prevents table row selection
      • #6606 Fix range selection of b-table
      • #6603 Set aria-sort when using sortKey and no-local-sorting
      • #6383 Default role to grid when selectable and table otherwise
      • #6382 Prefer user-provided role attribute
      • #6372 Add missing role="grid" when selectable
      • #6371 Header cell overflow for .sr-only sort label
      • #6355 Add missing sortKey field type and correct a typo
    • b-skeleton
      • #6858 Accepts custom attributes
    • nav-item-dropdown
      • 97bb97b Update dropdown to set correct aria-controls
    • b-dropdown
      • #6865 Set correct aria-haspopup attribute for the toggle button
      • #6367 Decrease delay when hiding inside a navbar on no-touch devices
    • utils/dom
    • docs
      • #6545 Use https:// urls in docs
    • b-form-group
      • #6346 Remove role="alert" from valid/invalid feedback
    • b-input-tags
      • #6389 Respect custom $input-color
    • b-link
      • #6374 Remove default values from vue-router pass-down props
    • b-img-lazy
      • #6349 Fix blank placeholder for Firefox
      • #6302 Fix blank-src not working
    • b-form-input/b-form-textarea
      • #6345 Legacy browser support

    🏡 Chore

    • tests
      • 8ce291b Refactor tests not to use $children
      • b16514b Remove useless localVue usage
      • ac8ebfe Replace find with findComponents
      • d113cc7 Remove createContainer helper
    • b-form-tags
      • #6752 Correct typo b-from-tags to b-form-tags
    • icons
      • #6611 Update Bootstrap Icons to v1.5.0
    • docs
      • #6466 Add new "Vuexy - Admin Dashboard" theme
      • #6368 Make sure the clicked anchor target is reflected in URL
    • ci
      • #6592 Update workflows to new Node.js versions
    • refactor
      • #6381 Move away from lifecycle hook listeners
      • #6356 Unify event variable names

    💖 Thanks to

    • Andrei Gheorghiu
    • Connor Forbes
    • Illya Klymov
    • JD
    • James Pickard
    • Jingsong Gao
    • John Franey
    • Jonathan Guberman
    • Joshua Wu
    • Konstantin
    • Lei Wang
    • Olena Horal
    • Pete Hegman
    • Rare Kang
    • Samuel Denis-D'Ortun
    • William
    • William Teixeira
    • magical-l
    • ochowei
    • xenolithviktor
  • 2.21.2 - 2021-01-01
    Read more
  • 2.21.1 - 2020-12-16

    🐛 Bug Fixes

    • b-tabs
      • #6208 Restore correct active tab detection logic
    • b-badge
      • #6217 Attribute inheritance
    • b-pagination
      • #6200 Don't set initial page count twice
    • b-dropdown

    🏡 Chore

    • docs
      • #6206 Fix <b-form-timepicker> "Button only mode" example markup
  • 2.21.0 - 2020-12-14
    Read more
  • 2.20.1 - 2020-12-01

    🐛 Bug Fixes

    • general
      • #6113 User supplied prop function detection
    • table
      • c375ce9 Use original value for fallback when number parsing fails in defaultSortCompare
  • 2.20.0 - 2020-11-30
    Read more
  • 2.19.0 - 2020-11-08
    Read more
  • 2.18.1 - 2020-10-21

    🐛 Bug Fixes

    • b-icon
      • #5939 Local component lookup
    • b-link
      • #5934 href handling with live router
    • b-form-group
      • #5933 Content element ID handling

    🏡 Chore

    • docs
      • #5935 Add example on how to alias Vue with Vue CLI
  • 2.18.0 - 2020-10-19
    Read more
  • 2.17.3 - 2020-09-18
    Read more
  • 2.17.2 - 2020-09-18
  • 2.17.1 - 2020-09-16
  • 2.17.0 - 2020-09-13
  • 2.16.0 - 2020-07-28
  • 2.15.0 - 2020-05-22
  • 2.14.0 - 2020-05-12
  • 2.13.1 - 2020-05-06
  • 2.13.0 - 2020-04-27
  • 2.12.0 - 2020-04-20
  • 2.11.0 - 2020-04-08
  • 2.10.1 - 2020-04-02
  • 2.10.0 - 2020-04-01
  • 2.9.0 - 2020-03-26
  • 2.8.0 - 2020-03-22
  • 2.7.0 - 2020-03-14
  • 2.6.1 - 2020-03-06
  • 2.6.0 - 2020-03-05
  • 2.5.0 - 2020-02-18
  • 2.4.2 - 2020-02-15
  • 2.4.1 - 2020-02-13
  • 2.4.0 - 2020-02-01
  • 2.3.0 - 2020-01-24
  • 2.2.2 - 2020-01-15
from bootstrap-vue GitHub release notes
Commit messages
Package name: bootstrap-vue
  • 93a7590 chore: simplify bootstrap version range in package.json
  • 94c810a build: update release scripts
  • 6c34b14 chore(deps): bump actions/checkout from 2 to 3 (#6928)
  • 048e847 chore(deps): bump prismjs from 1.25.0 to 1.27.0 (#6922)
  • 8501a32 chore(deps): bump minimist from 1.2.5 to 1.2.6 (#6949)
  • 6b3bd36 chore(deps): bump codecov/codecov-action from 2.1.0 to 3.0.0 (#6955)
  • 14ae1c7 chore(deps): bump actions/setup-node from 2.5.0 to 3.1.1 (#6953)
  • 2eb08fe chore(deps): bump actions/cache from 2.1.7 to 3.0.2 (#6954)
  • c645a33 chore(deps): bump node-fetch from 2.6.1 to 2.6.7 (#6903)
  • c9d244a chore(deps): bump shelljs from 0.8.4 to 0.8.5 (#6896)
  • 4222833 chore(deps): bump bootstrap from 4.5.3 to 4.6.0 (#6337)
  • 524652a chore(compat): fetch fresh template element when checking visibility
  • 48ec2e0 chore(deps-dev): bump terser from 5.7.0 to 5.10.0 (#6885)
  • dfbc56d chore(deps-dev): bump @ babel/standalone from 7.14.1 to 7.16.6 (#6884)
  • fefc76b chore(deps-dev): bump autoprefixer from 10.2.5 to 10.4.0 (#6883)
  • 7ea67d2 chore(deps-dev): bump improved-yarn-audit from 2.3.2 to 3.0.0 (#6881)
  • d2133b8 chore(deps-dev): bump eslint-plugin-prettier from 3.4.0 to 3.4.1 (#6880)
  • 9f70574 Update README.md (#6794)
  • 8ce291b chore(compat): refactor tests not to use $children
  • 6683001 chore(compat): fix table-sorting test
  • 92d588f chore(compat): refactor skeleton-wrapper test
  • 6353c31 chore(compat): deal with timing differences in Vue 2 and Vue 3
  • ccf62a4 chore(compat): replace toHaveBeenCalledLastWith with relaxed check
  • b1f6538 chore(compat): refactor icon search in component tree

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@stale
Copy link

stale bot commented Sep 21, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the wontfix This will not be worked on label Sep 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
wontfix This will not be worked on
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant