This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|
 | 713/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.4 | Prototype Pollution SNYK-JS-JSON5-3182856 | Yes | Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name:css-loader
The new version differs by 250 commits.
- 7857d8f chore(release): 4.0.0
- 5604205 feat: support `file:` protocol
- 5303db2 chore(deps): update (#1131)
- 9aa0549 chore(deps): update
- a54c955 test: imports
- 5b45d87 test: support in `@ import` at-rule
- 83515fa refactor: code
- 1c20b1e fix: parsing
- 7f49a0a feat: `@ value` supports importing `url()` (#1126)
- 791fff3 refactor: named export (#1125)
- 01e8c76 refactor: change function arguments of the `import` option (#1124)
- c153fe6 refactor: improve schema options (#1123)
- 58b4b98 test: unresolved (#1122)
- d2f6bd2 refactor: getLocalIdent function (#1121)
- 069dbb0 refactor: the `modules.localsConvention` option was renamed to the `modules.exportLocalsConvention` option (#1120)
- fc04401 refactor: the `modules.context` option was renamed to the `modules.localIdentContext` option (#1119)
- 3a96a3d refactor: the `hashPrefix` option was renamed to the `localIdentHashPrefix` option (#1118)
- 0080f88 refactor: default values `modules` and `module.auto` are true (#1117)
- e1c55e4 refactor: rename the `onlyLocals` option (#1116)
- ac5f413 refactor: code
- a5c1b5f test: code coverange (#1114)
- 908ecee refactor: `esModule` option is `true` by default (#1111)
- 7cca035 test: coverange (#1112)
- bc19ddd feat: improve `url()` resolving algorithm
See the full diff
Package name:file-loader
The new version differs by 68 commits.
See the full diff
Package name:html-webpack-plugin
The new version differs by 250 commits.
- 74fae99 chore(release): 5.0.0
- 94a20df chore: update to webpack 5.20.0
- c5c8212 feat: add meta attribute for html tags
- d0ab774 feat: provide public path to the alterAssetTagGroups hook
- 5200ae6 feat: provide public path to the alterAssetTags hook
- ccbe93a chore: update examples to latest webpack version
- 33cbd59 fix: generate html files even if no webpack entry exists
- 826739f feat: allow to use the latest loader-utils and tapable version
- 81d7b2c feat: add typings for options and version
- 8d34b81 fix: use correct casing for webpack type import
- 36f9aca chore: upgrade dev dependencies
- 1755962 chore: fix css-loader for unit testing
- a79ab17 chore: drop support for appcache-webpack-plugin as it is not compatible to webpack 5
- 7c3146d feat: allow to set publicPath to empty string ’’
- b109213 docs: update installation instructions for webpack 4
- 833b46b fix: inject javascripts in the <head> tag for inject:true and scriptLoading:'defer'
- 13af0fb feat: add full support for public paths inside templates
- fd5fe58 refactor: move the publicPath generation into a seperate function
- 60a6ef8 test: add test for experiments: { outputModule: true }
- a43ab72 feat: overrule module output
- 10a0c5e fix: adjust tests as webpack 5 will no longer emit files for builds with errors
- 2975a6a feat: process html during the processAssets stage PROCESS_ASSETS_STAGE_OPTIMIZE_INLINE
- 0f9c239 fix: add support for publicPath: 'auto' in combination with type: 'asset/resource'
- ab8b195 fix: support loaders like raw-loader
See the full diff
Package name:postcss-loader
The new version differs by 93 commits.
See the full diff
Package name:source-map-loader
The new version differs by 15 commits.
See the full diff
Package name:style-loader
The new version differs by 112 commits.
See the full diff
Package name:ts-loader
The new version differs by 250 commits.
- 268bc69 chore(deps): upgrade most production deps (#1237)
- e160564 Add a cache to file path mapping (#1228)
- 14fa3f8 Add documentation about performance profiling (#1230)
- 3cc78b8 Fix typo in README.md (#1229)
- 8f2a509 Add documentation for the useCaseSensitiveFileNames option (#1227)
- 566e6ce Instead of checking date, check time thats more accurate to see if something has changed (#1217)
- 172ebeb Feature/typescript 4 1 (#1213)
- 0816fe9 Add peer dependencies for Yarn PnP (#1209)
- 4909d99 Fixed missing errors in watch mode in webpack5 (#1208)
- 3f73e98 Fix failed builds when using thread-loader (#1207)
- e90f8ad Fix memory leak when using multiple webpack instances (#1205)
- 95050eb Speeds up project reference build and doesnt store the result in memory (#1202)
- f99c7c4 doc: escape pipe in table (#1201)
- 0b4a86d Replace afterCompile to stop webpack 5 warning (#1200)
- 6d8d601 Fixed deprecation warnings on webpack@5. (#1195)
- cafc933 Fix installation link on README.md (#1192)
- f5e901e Bump http-proxy in /examples/react-babel-karma-gulp (#1182)
- 0767bce add github action status badge (#1190)
- db5ea55 Feature/upgrade testpack to ts4 (#1189)
- 95b6fe8 Uses existing instance if config file is same as already built solution (#1177)
- b38678a Update minimum compiler version to 3.6.3 (#1188)
- f8eba53 Add documentation and example code for projectReferences (#1184)
- 46d9761 Update docs to show transpileOnly does not affect project references (#1175)
- 0e64ceb Fix getOptionsHash when two options has different props but same values. (#1170)
See the full diff
Package name:url-loader
The new version differs by 57 commits.
See the full diff
Package name:webpack
The new version differs by 250 commits.
- 610f368 5.0.0
- 5ce65c1 update examples
- bbe1230 Merge pull request #11628 from webpack/bugfix/real-content-hash
- 75ecff2 5.0.0-rc.6
- bfc35d6 Merge pull request #11603 from MayaWolf/master
- 76e8cbd Merge pull request #11622 from webpack/dependabot/npm_and_yarn/types/node-13.13.25
- 9fd1be2 chore(deps-dev): bump @ types/node from 13.13.23 to 13.13.25
- 36bcfaa Merge pull request #11621 from webpack/bugfix/11619
- 9130d10 fix called variables with ProvidePlugin
- 3e42105 Merge pull request #11620 from webpack/bugfix/11617
- 4709719 skip connections copied to concatenated module
- 57b493f 5.0.0-rc.5
- 1658e2f Merge pull request #11618 from webpack/bugfix/11615
- a8fb45d fixes crash in SideEffectsFlagPlugin
- 84b196d emit error instead of crashing when unexpected problem occurs
- 5573fed Merge pull request #11601 from Hornwitser/improve-suggested-polyfill-config
- 9b5cce9 Merge pull request #11609 from snitin315/export-types
- 37c495c export type RuleSetUseItem
- 39faf34 export type RuleSetUse
- e5fd246 export type RuleSetConditionAbsolute
- 660baad export RuleSetCondition types
- 13e3ca5 Merge pull request #11602 from webpack/bugfix/shared-runtime-chunk
- 9c0587e Merge pull request #11606 from webpack/dependabot/npm_and_yarn/simple-git-2.21.0
- 502d166 Merge pull request #11607 from webpack/dependabot/npm_and_yarn/acorn-8.0.4
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project.
Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐View latest project report
🛠Adjust project settings
📚Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉Prototype Pollution
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.4
SNYK-JS-JSON5-3182856
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name:css-loader
The new version differs by 250 commits.See the full diff
Package name:file-loader
The new version differs by 68 commits.See the full diff
Package name:html-webpack-plugin
The new version differs by 250 commits.See the full diff
Package name:postcss-loader
The new version differs by 93 commits.See the full diff
Package name:source-map-loader
The new version differs by 15 commits.See the full diff
Package name:style-loader
The new version differs by 112 commits.devtoolsetting tosource-mapwmonk/create-react-app-typescript#442)jsorjsxfiles in live dev mode. wmonk/create-react-app-typescript#440)See the full diff
Package name:ts-loader
The new version differs by 250 commits.See the full diff
Package name:url-loader
The new version differs by 57 commits.npm ls react-scripts-tsis empty wmonk/create-react-app-typescript#176 (SwitchNODE_PATHtoREACT_APP_NODE_PATHwmonk/create-react-app-typescript#177)See the full diff
Package name:webpack
The new version differs by 250 commits.See the full diff
Check the changes in this PR to ensure they won't cause issues with your project.
Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐View latest project report
🛠Adjust project settings
📚Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉Prototype Pollution