Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade react-flow-renderer from 10.0.0-next.30 to 10.0.0 #350

Closed
wants to merge 1 commit into from

Conversation

snyk-bot
Copy link
Contributor

@snyk-bot snyk-bot commented Apr 1, 2022

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-D3COLOR-1076592
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-flow-renderer The new version differs by 176 commits.
  • 3548891 Merge pull request #1555 from wbkd/v10
  • bfe06a5 chore(bezier-edge): less curvy by default
  • 64f8d10 Merge pull request #1969 from joeyballentine/v10-bezier-fix
  • 9128967 Fix merge conflict
  • 2018f93 Merge remote-tracking branch 'wbkd/v10' into v10-bezier-fix
  • 6f51af2 Improve UE-style Bezier Edge calculation
  • 9fff0e5 refactor(bezier-edge): only do calculations when necessary
  • 3b87563 refactor(cypress): cleanup
  • 2d714dc chore(deps): update
  • bf2f9e5 Merge pull request #1968 from wbkd/v10-ue-edge
  • bc5d1df refactor(edges): add BaseEdge
  • b362c11 refactor(edges): use new edge as default, add simplebezier
  • dfc91d7 chore(readme): wording
  • 72f77c6 Update README.md
  • cdc6f49 Update README.md
  • 843f209 Update README.md
  • 02cd3cb Update README.md
  • 3c96b07 Rename to "unreal" edge, fix for both horizontal and vertical handles
  • 726bc2e Add Unreal Engine style bezier edge
  • 64a3c2d chore(attribution): update options
  • 466a0af chore(version): bump
  • 1424cf8 chore(version): bump
  • 5cc3502 Merge pull request #1947 from Himself65/v10-fix
  • a48276e fix: type error

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-D3COLOR-1076592
Copy link
Contributor

@anrusina anrusina left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

THIS PR is BLOCKED, as it has breaking changes for Graph support

@anrusina
Copy link
Contributor

This Vulerability has been fixed by updating "react-flow-renderer" to "10.1.1" in the #418

@anrusina anrusina closed this Apr 21, 2022
@anrusina anrusina deleted the snyk-fix-10496d921aef1f86e748810dbdcbe22a branch April 21, 2022 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants