Skip to content

[Snyk] Upgrade react-dropzone from 12.0.5 to 12.1.0#9

Closed
ekaterinamishina wants to merge 1 commit into
mainfrom
snyk-upgrade-a736ed69f0f7a12fb8fd0bc084fca786
Closed

[Snyk] Upgrade react-dropzone from 12.0.5 to 12.1.0#9
ekaterinamishina wants to merge 1 commit into
mainfrom
snyk-upgrade-a736ed69f0f7a12fb8fd0bc084fca786

Conversation

@ekaterinamishina
Copy link
Copy Markdown
Contributor

Snyk has created this PR to upgrade react-dropzone from 12.0.5 to 12.1.0.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

✨ Snyk has automatically assigned this pull request, set who gets assigned.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released 2 years ago, on 2022-04-26.
Release notes
Package name: react-dropzone from react-dropzone GitHub release notes
Commit messages
Package name: react-dropzone
  • 2a71cc9 feat(deps): bump file-selector from 0.4.0 to 0.5.0
  • 5bc4273 fix: remove autocomplete for file input type
  • 888fb6f docs: fix the image preview example

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

👩‍💻 Set who automatically gets assigned

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@rbuergi rbuergi closed this Oct 7, 2024
@rbuergi rbuergi deleted the snyk-upgrade-a736ed69f0f7a12fb8fd0bc084fca786 branch October 7, 2024 16:59
rbuergi added a commit that referenced this pull request May 5, 2026
…leasePath is set

Tasks #6, #7, #8, #9, #10, #11, #12, #13, #14 from the failing-tests list
share one root cause: NodeTypeContractHandler.Handle was short-circuiting
on node.AssemblyLocation alone. For freshly-created dynamic NodeTypes
(NodeType=NodeType, Content=NodeTypeDefinition), NodeTypeService
.EnrichWithNodeType propagates the STATIC "NodeType" type's framework DLL
(MeshWeaver.Graph.dll) onto the new node's AssemblyLocation through its
fast-path ApplyEntry. The handler then opened MeshWeaver.Graph.dll,
found no MeshNodeProvider for the new hub's path, and silently returned
Success=true with empty NodeTypeConfigurations — so:

- CompileFailsWhenSourceCodeIsInvalid sees Success=true (compile never
  actually ran).
- CompileWithMultipleSourceLocationsPullsInExternalCode misses the
  external Profile type for the same reason.
- CompileActivityLogTest.* never produces an activity log because the
  Roslyn compile never ran.
- LinkedIn* tests can't render their NodeType-bound layout areas.
- MeshPluginTest broken-NodeType tests don't see the compile error
  because no compile happened.

Fix: only take the short-circuit path when def.LatestReleasePath is
non-empty. A populated LatestReleasePath means StartCompile (or a
release publish) has actually emitted an assembly for THIS NodeType;
only then is AssemblyLocation a real release DLL. Otherwise fall through
to compilationService.CompileAndGetConfigurations, which runs Roslyn,
returns the real Success/Failed shape, and lets the cluster behave.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
rbuergi added a commit that referenced this pull request May 10, 2026
…fix DI lifetimes, redact PII, drop dynamic

- ThreadExecution: collapse triple-stacked <summary> blocks on
  WatchForExecution and NotifyParentCompletion. Tooling kept the last
  one anyway; the dead scaffolding was just noise.
- SocialExtensions: register LinkedInPublisher / XPublisher as TRUE
  singletons (factory-resolved with named HttpClient). The previous
  AddHttpClient<T>+AddSingleton<IPlatformPublisher> mix made the
  concrete type transient while the interface alias was singleton —
  direct vs via-interface resolution returned different instances.
  Also gate hosted-service registration on at least one platform
  being configured (the "all-or-nothing" comment was wrong; with
  zero platforms the four hosted services started anyway and faulted
  on first tick).
- LinkedInPublisher: replace `(dynamic)media.shareMediaCategory`
  peek with two concrete payload shapes — typo turns into a compile
  error instead of a RuntimeBinderException.
- LinkedIn / X publishers: cap error-body logs at 200 chars to
  bound PII exposure (the body can echo the user's post text on
  validation rejection). Full body still goes to PublishResult.Error
  for the caller.

Addresses PR #95 review items #9, #20, #21, #22, #23.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants