[Snyk] Upgrade css-loader from 5.0.2 to 6.7.1 #40
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade css-loader from 5.0.2 to 6.7.1.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
Warning: This is a major version upgrade, and may be a breaking change.
The recommended version fixes:
npm:underscore.string:20170908
Why? CVSS 7.5
SNYK-JS-URLPARSE-2407770
Why? CVSS 7.5
SNYK-JS-TAR-1579155
Why? CVSS 7.5
SNYK-JS-TAR-1579152
Why? CVSS 7.5
SNYK-JS-TAR-1579147
Why? CVSS 7.5
SNYK-JS-TAR-1536531
Why? CVSS 7.5
SNYK-JS-TAR-1536528
Why? CVSS 7.5
SNYK-JS-PACRESOLVER-1564857
Why? CVSS 7.5
SNYK-JS-NTHCHECK-1586032
Why? CVSS 7.5
SNYK-JS-NETMASK-1089716
Why? CVSS 7.5
SNYK-JS-MOMENT-2944238
Why? CVSS 7.5
SNYK-JS-MOMENT-2440688
Why? CVSS 7.5
SNYK-JS-LODASH-1040724
Why? CVSS 7.5
SNYK-JS-JSRSASIGN-2869122
Why? CVSS 7.5
SNYK-JS-JSONSCHEMA-1920922
Why? CVSS 7.5
SNYK-JS-GETOBJECT-1054932
Why? CVSS 7.5
SNYK-JS-EJS-2803307
Why? CVSS 7.5
SNYK-JS-DNSPACKET-1293563
Why? CVSS 7.5
SNYK-JS-AXIOS-1579269
Why? CVSS 7.5
SNYK-JS-ASYNC-2441827
Why? CVSS 7.5
SNYK-JS-ASYNC-2441827
Why? CVSS 7.5
SNYK-JS-ANSIHTML-1296849
Why? CVSS 7.5
SNYK-JS-URLPARSE-2412697
Why? CVSS 7.5
SNYK-JS-URLPARSE-2407759
Why? CVSS 7.5
SNYK-JS-URLPARSE-2401205
Why? CVSS 7.5
SNYK-JS-URLPARSE-1533425
Why? CVSS 7.5
SNYK-JS-URLPARSE-1078283
Why? CVSS 7.5
SNYK-JS-UNDERSCORE-1080984
Why? CVSS 7.5
SNYK-JS-UGLIFYJS-1727251
Why? CVSS 7.5
SNYK-JS-TERSER-2806366
Why? CVSS 7.5
SNYK-JS-TERSER-2806366
Why? CVSS 7.5
SNYK-JS-POSTCSS-1090595
Why? CVSS 7.5
SNYK-JS-PATHPARSE-1077067
Why? CVSS 7.5
SNYK-JS-NODEFETCH-2342118
Why? CVSS 7.5
SNYK-JS-NANOID-2332193
Why? CVSS 7.5
SNYK-JS-MARKDOWNIT-2331914
Why? CVSS 7.5
SNYK-JS-LODASH-1018905
Why? CVSS 7.5
SNYK-JS-JSRSASIGN-1244072
Why? CVSS 7.5
SNYK-JS-I-1726768
Why? CVSS 7.5
SNYK-JS-HOSTEDGITINFO-1088355
Why? CVSS 7.5
SNYK-JS-GRUNT-2813632
Why? CVSS 7.5
SNYK-JS-GRUNT-2635969
Why? CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-2332181
Why? CVSS 7.5
SNYK-JS-EVENTSOURCE-2823375
Why? CVSS 7.5
SNYK-JS-ELLIPTIC-1064899
Why? CVSS 7.5
SNYK-JS-EJS-1049328
Why? CVSS 7.5
SNYK-JS-BROWSERSLIST-1090194
Why? CVSS 7.5
npm:utile:20180614
Why? CVSS 7.5
SNYK-JS-TAR-1536758
Why? CVSS 7.5
SNYK-JS-MINIMIST-2429795
Why? CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-2396346
Why? CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: css-loader
6.7.1 (2022-03-08)
Bug Fixes
6.7.0 (2022-03-04)
Features
6.6.0 (2022-02-02)
Features
hashStrategy
option (ca4abce)6.5.1 (2021-11-03)
Bug Fixes
6.5.0 (2021-10-26)
Features
url()
whenexperiments.buildHttp
enabled (#1389) (8946be4)Bug Fixes
nosources
in thedevtool
option (c60eff2)6.4.0 (2021-10-09)
Features
Bug Fixes
6.3.0 (2021-09-18)
Features
[folder]
placeholder (a0dee4f)exportType
option with'array'
,'string'
and'css-style-sheet'
values (c6d2066)'array'
- the default export isArray
with API forstyle-loader
and other'string'
- the default export isString
you don't needto-string-loader
loader anymore'css-style-sheet'
- the default export is aconstructable stylesheet
, you can useimport sheet from './styles.css' assert { type: 'css' };
like in a browser, more information you can find heresupports()
andlayer()
functions in@ import
at-rules (#1377) (bce2c17)@ media
at-rules (#1377) (bce2c17)Bug Fixes
6.2.0 (2021-07-19)
Features
exportLocalsConvention
option can be a function useful for named export (#1351) (3c4b357)6.1.0 (2021-07-17)
Features
link
in schema (#1345) (7d4e493)Bug Fixes
localIdentRegExp
option (#1349) (42f150b)6.0.0 (2021-07-14)
Notes
~
is deprecated when theesModules
option is enabled (enabled by default) and can be removed from your code (we recommend it) (url(~package/image.png)
->url(package/image.png)
,@ import url(~package/style.css)
->@ import url(package/style.css)
,composes: import from '~package/one.css';
->composes: import from 'package/one.css';
), but we still support it for historical reasons. Why can you remove it? The loader will first try to resolve@ import
/url()
/etc as relative, if it cannot be resolved, the loader will try to resolve@ import
/url()
/etc insidenode_modules
or modules directories.file-loader
andurl-loader
are deprecated, please migrate onasset modules
, since v6css-loader
is generatingnew URL(...)
syntax, it enables by default built-inassets modules
, i.e.type: 'asset'
for allurl()
⚠ BREAKING CHANGES
Node.js
version is12.13.0
webpack
version is5
, we recommend to update to the latest version for better performanceurl
andimport
optionsFunction
type was removed in favorObject
type with thefilter
property, i.e. before{ url: () => true }
, now{ url: { filter: () => true } }
and before{ import: () => true }
, now{ import: { filter: () => true } }
modules.compileType
option was removed in favor themodules.mode
option withicss
value, also themodules
option can haveicss
string valuenew URL()
syntax used forurl()
, only when theesModules
option is enabled (enabled by default), it means you can bundle CSS for librariesurl()
, it means you can register loaders for them, examplefalse
value forurl()
now generate empty data URI (i.e.data:0,
), only when theesModules
option is enabled (enabled by default)[ext]
placeholder don't need.
(dot) before for thelocalIdentName
option, i.e. please change.[ext]
on[ext]
(no dot before)[folder]
placeholder was removed without replacement for thelocalIdentName
option, please use a custom function if you need complex logic[emoji]
placeholder was removed without replacement for thelocalIdentName
option, please use a custom function if you need complex logiclocalIdentHashPrefix
was removed in favor thelocalIdentHashSalt
optionFeatures
resolve.byDependency.css
resolve options for@ import
resolve.byDependency.icss
resolve CSS modules and ICSS imports (i.e.composes
/etc)modules.localIdentHashFunction
,modules.localIdentHashDigest
,modules.localIdentHashDigestLength
options for better class hashing controllingBug Fixes
@ import
Commit messages
Package name: css-loader
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs