Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to upgrade nuxt from 2.13.0 to 2.16.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 29 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2023-03-17.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Arbitrary Code Injection
SNYK-JS-EJS-1049328
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-3244450
512/1000
Why? Proof of Concept exploit, CVSS 8.1
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: nuxt
  • 2.16.3 - 2023-03-17

    2.16.3 is a patch release with bug fixes.

    👉 Changelog

    compare changes

    🩹 Fixes

    • types: Add return type for error() (#19044)
    • types: Bring types from less into namespace (#19738)
    • types: Sync vue type augmentations with Vue 2.7 (#19526)
    • config: Move preset to inner postcssOptions (#19518)
    • webpack: Add node-fetch-native to externals list (#19755)

    🏡 Chore

    • Release all packages with latest tag except nuxt (4e9dcddcb)
    • examples: Use 2.x version of nuxt instead of latest (#19737)
    • Lint package files (6ca842e36)

    ❤️ Contributors

  • 2.16.2 - 2023-03-01

    2.16.2 is a patch release with bug fixes.

    ✨ Highlights

    The main change in this patch release is that we now patch the crypto node built-in during build to allow Nuxt 2 to be used on Node versions greater than Node 16, which should ease the pressure users feel after Node 16 reaches its own EOL this year.

    Warning
    This should not be taken for an endorsement of continuing to run with Webpack 4, which is out of date and has a number of dependencies with issues. I expect that number to continue to grow, and we will not be able to resolve all of them. I would strongly urge migrating to Nuxt 3 if possible and the team will do our best to make this possible over the course of the year ❤️

    👉 Changelog

    compare changes

    🚀 Enhancements

    • types: Add basic types for Nuxt interface (#9772)

    🩹 Fixes

    • vue-renderer: Insert charset before title (#18998)
    • types: Remove non-existent properties from context (#19021)
    • Add minimum node 14.18 version constraint (#19112)
    • config: Upgrade md4 -> md5 on node > 16 (#19108)
    • vue-app: Handle promise rejection from asyncData (#18585)

    🏡 Chore

    ❤️ Contributors

  • 2.16.1 - 2023-02-13

    Nuxt 2.16.1 is a patch release with a couple of small bugfixes to last week's 2.16.0 release.

    v2.16.0...v2.16.1

    🩹 Fixes

    • deps: Downgrade @ types packages depending on webpack 5 (#18827)
    • config: Let webpack merge postcss plugins (#18839)
    • types: Import Location from vue-router (#18908)

    🏡 Chore

    • Tag 2.x releases appropriately (aba93e9)
    • Revert node types to v16 (3d034a3)
    • Remove stub type definitions (daed62a)

    ❤️ Contributors

  • 2.16.0 - 2023-02-03
  • 2.15.8 - 2021-08-11
  • 2.15.7 - 2021-06-14
  • 2.15.6 - 2021-05-12
  • 2.15.5 - 2021-05-09
  • 2.15.4 - 2021-04-01
  • 2.15.3 - 2021-03-10
  • 2.15.2 - 2021-02-23
  • 2.15.1 - 2021-02-19
  • 2.15.0 - 2021-02-15
  • 2.14.12 - 2020-12-16
  • 2.14.11 - 2020-12-09
  • 2.14.10 - 2020-12-07
  • 2.14.9 - 2020-12-02
  • 2.14.8 - 2020-12-01
  • 2.14.7 - 2020-10-15
  • 2.14.6 - 2020-09-21
  • 2.14.5 - 2020-09-10
  • 2.14.4 - 2020-08-27
  • 2.14.3 - 2020-08-16
  • 2.14.2 - 2020-08-16
  • 2.14.1 - 2020-08-04
  • 2.14.0 - 2020-07-27
  • 2.13.3 - 2020-07-02
  • 2.13.2 - 2020-06-26
  • 2.13.1 - 2020-06-24
  • 2.13.0 - 2020-06-18
from nuxt GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants