Skip to content

Conversation

NOUIY
Copy link
Owner

@NOUIY NOUIY commented May 19, 2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade react-dropzone from 11.4.2 to 11.7.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.

  • The recommended version was released 2 years ago, on 2022-02-06.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
572/1000
Why? Proof of Concept exploit, CVSS 9.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: react-dropzone from react-dropzone GitHub release notes
Commit messages
Package name: react-dropzone

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Note: This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our documentation.

Snyk has created this PR to upgrade react-dropzone from 11.4.2 to 11.7.1.

See this package in npm:
react-dropzone

See this project in Snyk:
https://app.snyk.io/org/nexuscompute/project/84f3bfa3-e40b-4b8e-b809-ad535e4ef242?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

guardrails bot commented May 19, 2024

⚠️ We detected 2 security issues in this pull request:

Vulnerable Libraries (2)
Severity Details
High pkg:npm/@testing-library/react@11.2.7 (t) upgrade to: > 11.2.7
High pkg:npm/@testing-library/jest-dom@5.15.1 (t) upgrade to: > 5.15.1

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants