-
Notifications
You must be signed in to change notification settings - Fork 3.5k
[Snyk] Security upgrade babel-plugin-module-resolver from 4.1.0 to 5.0.0 #14146
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSON5-3182856
|
@sketchydroide Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
Reviewer Checklist
Screenshots/VideosWebMobile Web - ChromeMobile Web - SafariDesktopiOSAndroid |
|
I though we originally did not use this, but we do just not for it seems, but for a log we use to access the library, it's a bit weird, but yeah I think we need to update this. Can't really test as this is only used in prod for logs, so even it fails it's not critical, and I see no reason why it should fail. |
|
@sketchydroide looks like this was merged without a test passing. Please add a note explaining why this was done and remove the |
|
not an emergency snyk just doesn't have a list |
Performance Comparison Report 📊Significant Changes To DurationThere are no entries Meaningless Changes To DurationShow entries
Show details
|
|
🚀 Deployed to staging by @sketchydroide in version: 1.2.52-1 🚀
|
|
🚀 Deployed to production by @Julesssss in version: 1.2.52-4 🚀
|
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Proof of Concept exploit, Recently disclosed, CVSS 6.4
SNYK-JS-JSON5-3182856
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: babel-plugin-module-resolver
The new version differs by 3 commits.See the full diff
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Prototype Pollution