Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Security] Bump react-dom from 16.2.0 to 16.12.0#17

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Conversation

dependabot-preview[bot]
Copy link

Bumpsreact-dom from 16.2.0 to 16.12.0.This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

Low severity vulnerability that affects react-dom
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This vulnerability can only affect some server-rendered React apps. Purely client-rendered apps are not affected.

This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.

Affected versions: = 16.2.0

Release notes

Sourced fromreact-dom's releases.

16.12.0 (November 14, 2019)

React DOM

  • Fix passive effects (useEffect) not being fired in a multi-root app. (@​acdlite in#17347)

React Is

  • Fixlazy andmemo types considered elements instead of components (@​bvaughn in#17278)

Artifacts

• react:https://unpkg.com/react@16.12.0/umd/
• react-art:https://unpkg.com/react-art@16.12.0/umd/
• react-dom:https://unpkg.com/react-dom@16.12.0/umd/
• react-is:https://unpkg.com/react-is@16.12.0/umd/
• react-test-renderer:https://unpkg.com/react-test-renderer@16.12.0/umd/
• scheduler:https://unpkg.com/scheduler@0.18.0/umd/

16.11.0 (October 22, 2019)

React DOM

  • Fixmouseenter handlers from firing twice inside nested React containers.@​yuanoook in#16928
  • Removeunstable_createRoot andunstable_createSyncRoot experimental APIs. (These are available in the Experimental channel ascreateRoot andcreateSyncRoot.) (@​acdlite in#17088)

Artifacts

• react:https://unpkg.com/react@16.11.0/umd/
• react-art:https://unpkg.com/react-art@16.11.0/umd/
• react-dom:https://unpkg.com/react-dom@16.11.0/umd/
• react-is:https://unpkg.com/react-is@16.11.0/umd/
• react-test-renderer:https://unpkg.com/react-test-renderer@16.11.0/umd/
• scheduler:https://unpkg.com/scheduler@0.17.0/umd/

16.10.2 (October 3, 2019)

React DOM

  • Fix regression in react-native-web by restoring order of arguments in event plugin extractors (@​necolas in#16978)

Artifacts

• react:https://unpkg.com/react@16.10.2/umd/
• react-art:https://unpkg.com/react-art@16.10.2/umd/
• react-dom:https://unpkg.com/react-dom@16.10.2/umd/
• react-is:https://unpkg.com/react-is@16.10.2/umd/
• react-test-renderer:https://unpkg.com/react-test-renderer@16.10.2/umd/
• scheduler:https://unpkg.com/scheduler@0.16.2/umd/

16.10.1 (September 28, 2019)

React DOM

... (truncated)
Changelog

Sourced fromreact-dom's changelog.

16.12.0 (November 14, 2019)

React DOM

  • Fix passive effects (useEffect) not being fired in a multi-root app. (@​acdlite in#17347)

React Is

  • Fixlazy andmemo types considered elements instead of components (@​bvaughn in#17278)

16.11.0 (October 22, 2019)

React DOM

  • Fixmouseenter handlers from firing twice inside nested React containers.@​yuanoook in#16928
  • Removeunstable_createRoot andunstable_createSyncRoot experimental APIs. (These are available in the Experimental channel ascreateRoot andcreateSyncRoot.) (@​acdlite in#17088)

16.10.2 (October 3, 2019)

React DOM

  • Fix regression in react-native-web by restoring order of arguments in event plugin extractors (@​necolas in#16978)

16.10.1 (September 28, 2019)

React DOM

  • Fix regression in Next.js apps by allowing Suspense mismatch during hydration to silently proceed (@​sebmarkbage in#16943)

16.10.0 (September 27, 2019)

React DOM

Scheduler (Experimental)

  • Improve queue performance by switching its internal data structure to a min binary heap. (@​acdlite in#16245)
  • UsepostMessage loop with short intervals instead of attempting to align to frame boundaries withrequestAnimationFrame. (@​acdlite in#16214)

useSubscription

  • Avoid tearing issue when a mutation happens and the previous update is still in progress. (@​bvaughn in#16623)
... (truncated)
Commits
  • b53ea6c [Bugfix] Passive effects triggered by synchronous renders in a multi-root app...
  • 01bce8c Change legacy-events plugin nativeEventTarget to allow null (#17344)
  • b8f8258 Split ReactDOM entry point (#17331)
  • a7b4d51 Warn when doing createRoot twice on the same node (another approach) (#17329)
  • be3bfa6 [Flight] Basic Integration Test (#17307)
  • e701632 [react-interactions] Change unmount blur logic to a dedicated event (#17291)
  • dee0304 [Flight] Basic Streaming Suspense Support (#17285)
  • cb09dbe [react-interactions] Add handleSimulateChildBlur upon DOM node removal (#17225)
  • f4148b2 [Flight] Move around the Server side a bit (#17251)
  • fadc971 [Flight] Add Client Infrastructure (#17234)
  • Additional commits viewable incompare view
Maintainer changes

This version was pushed to npm bylunaruan, a new releaser for react-dom since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabotdashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) from 16.2.0 to 16.12.0. **This update includes a security fix.**- [Release notes](https://github.com/facebook/react/releases)- [Changelog](https://github.com/facebook/react/blob/master/CHANGELOG.md)- [Commits](https://github.com/facebook/react/commits/v16.12.0/packages/react-dom)Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-previewdependabot-previewbot added dependenciesPull requests that update a dependency file securityPull requests that address a security vulnerability labelsDec 5, 2019
@coveralls
Copy link

Pull Request Test Coverage Report forBuild 120

  • 0 of0 changed or added relevant lines in0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at53.202%

TotalsCoverage Status
Change from baseBuild 98:0.0%
Covered Lines:95
Relevant Lines:158

💛 -Coveralls

@dependabot-preview
Copy link
Author

Superseded by#28.

@dependabot-previewdependabot-previewbot deleted the dependabot/npm_and_yarn/react-dom-16.12.0 branchFebruary 26, 2020 21:20
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers
No reviews
Assignees
No one assigned
Labels
dependenciesPull requests that update a dependency filesecurityPull requests that address a security vulnerability
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

1 participant
@coveralls

[8]ページ先頭

©2009-2025 Movatter.jp