Skip to content

Conversation

AdamMurray
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 591/1000
Why? Recently disclosed, Has a fix available, CVSS 6.1
Open Redirect
SNYK-JS-EXPRESS-6474509
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: nwb The new version differs by 250 commits.
  • 4552964 Release v0.17.0
  • cd0a2aa Update promise polyfill
  • 6cf2fd4 Demo building and serving should use same stage preset as npm builds
  • cd00a66 Fix hrme = false Express middleware option to disable use of React Transform
  • 6819c97 Update ora and postcss-loader
  • 85a77a5 Fix hooking render() in the React render shim with preact-compat
  • 19b46c2 Update CHANGES formatting for next version
  • 9cbda5f Tweak .github stuff
  • 8b1535f Enable preact devtools in development mode
  • 78837e9 Update Flow
  • 9c1059c Update dependencies
  • c21739b Add a --no-clear[-console] flag to disable clearing the console
  • 527dab1 Document --copy-files in the React Components guide and add it to the FAQ
  • 106b041 Add VS Code config
  • 430b5d2 Update dependencies
  • 01496c9 Exit with a non-zero code when a Webpack build finishes with errors
  • 1872599 Use stage 1 preset by default for react-component and web-module builds.
  • faccafa Big refactor
  • 4c98016 Remove the release task, as it wasn't being used
  • 731b866 Fix HMR client when using Express middleware
  • 97aa902 Accept a project type option in Express middleware
  • 6718684 Added babel.removePropTypes and babel.reactConstantElements config
  • 86894a7 Add example of configuring CSS Modules for the default rule for a stylesheet preprocessor plugin
  • 9b9e738 Add note about passing a -- argument to npm run for command options

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Open Redirect

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-EXPRESS-6474509
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants