Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade jsoneditor from 5.34.0 to 9.5.6 #7

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • dashboard/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
low severity 471/1000
Why? Recently disclosed, Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
SNYK-JS-JSONEDITOR-1726760
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: jsoneditor The new version differs by 250 commits.
  • d289517 Publish v9.5.6, update devDependencies
  • 6e64f93 Add a SECURITY.md file
  • 092e386 Fix inefficient regex to replace return characters
  • c33544b publish v9.5.5
  • f5b3046 Fix `setMode` not throwing an exception anymore in case of a parse error
  • f97e875 Publish v9.5.4
  • b3b31f2 Fix opening the Transform or Sort modal in code mode with invalid JSON contents not triggering the `onError` callback (see #1364)
  • cbb95ae Change the default behavior of error handling to open a basic alert instead of logging the error in the console (see #1364).
  • 883a0c9 Update history
  • 5dbdfe4 Fix #1363: parsing error contains html caharacters
  • f87fb79 Update history
  • ed09d87 Use noreferrer for window.open (#1365)
  • a0f69af Publish v9.5.3
  • e041985 Update history
  • 74e40d3 Fixed enum on referenced schemas (#1355)
  • eab98fe Fix #1356: background of tree mode is transparent instead of white
  • 4b54776 Publish `v9.5.2`
  • 6112cab Fixed relative URLs from becoming absolute during build (#1354)
  • 698102c Change lockfileVersion to 2 (npm@7)
  • 19ed1fc Set up CI testing using Github Actions
  • eb84c4e Publish v9.5.1
  • c9fceae Upgrade to [email protected], update devDependencies
  • 2355135 Publish v9.5.0
  • 5a3a5b3 Update devDependencies

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant