Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(root): upgrade vuepress from 1.5.3 to 1.5.4 #91

Merged
merged 1 commit into from
Oct 17, 2020

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade vuepress from 1.5.3 to 1.5.4.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released 22 days ago, on 2020-08-23.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Arbitrary Code Injection
SNYK-JS-SERIALIZEJAVASCRIPT-570062
492/1000
Why? Proof of Concept exploit, CVSS 7.7
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: vuepress
  • 1.5.4 - 2020-08-23

    Bug Fixes

    • $core: decode regularPath when generate router config (fix #1946) (#1947) (dd26c7c)
    • $shared-utils: fix date parse logic for permalinks (#2181) (d4d0380)
    • $shared-utils: replace diacritics with regex (#1855) (a03e93d)
    • $theme-default: overlap navbar dropdown menus (fix #2227) (#2365) (ceb0fa9)
    • $theme-default: remove invalidate aria-labelledby on homepage title(#2277) (94a7de4)
  • 1.5.3 - 2020-08-05

    Bug Fixes

    • $theme-default: fix editLink for repos hosted on gitlab.com (#2523) (1c3967c)
    • add toml dependencyt to shared-utils (b858a6e)
    • regular files should not be executable (#2535) (ffb8527)
    • $theme-default: improve last-updated text color contrast (#2282) (7ca9fbc)
    • allows no rel attribute on external links in the nav (#2338) (b343cd3)
    • $core: style loss under build for package that specifies sideEffects: false (fix #2350) (#2471) (7e29900)
    • $markdown: line highlighting not working correctly when importing code snippets (#2441) (d0f2e42)

    Features

    • $theme-default: add initial open group index option (#2408) (465ae40)
from vuepress GitHub release notes
Commit messages
Package name: vuepress
  • 98086ad build: release version 1.5.4
  • ceb0fa9 fix($theme-default): overlap navbar dropdown menus (fix #2227) (#2365)
  • d4d0380 fix($shared-utils): fix date parse logic for permalinks (#2181)
  • dd26c7c fix($core): decode regularPath when generate router config (fix #1946) (#1947)
  • 94a7de4 fix($theme-default): remove invalidate aria-labelledby on homepage title(#2277)
  • 02816cf docs: warn of styling config restriction (#2161)
  • c68a4e7 test($core): add missing tests for Page (#2218)
  • 318068f docs: add generator path to readme
  • 0e78453 docs: update getting started experience (#2576)
  • 6b25140 docs: update cloudbase deploy doc (#2582)
  • a03e93d fix($shared-utils): replace diacritics with regex (#1855)
  • dfe43f6 docs: update cloudbase deploy doc (#2579)
  • a8f8e61 docs: reduce priority of 0.x docs (#2577)
  • ce81aa4 docs($zh): fix typos (#2542)
  • c7ba616 docs: remove workflow update
  • f04d14d docs: remove deps updates
  • 5706fb0 chore: version 1.5.3 changelog

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@auto-assign auto-assign bot requested a review from diegoazh September 14, 2020 04:46
@diegoazh diegoazh changed the title [Snyk] Upgrade vuepress from 1.5.3 to 1.5.4 chore(root): upgrade vuepress from 1.5.3 to 1.5.4 Oct 17, 2020
@diegoazh diegoazh merged commit 0125598 into master Oct 17, 2020
@diegoazh diegoazh deleted the snyk-upgrade-3701e51998ca336bba7bcb66bb1c8afc branch October 17, 2020 19:07
@github-actions
Copy link

🎉 This PR is included in version 2.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants