Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , , , ace-builds, apexcharts, bootstrap, chart.js, cropperjs, datatables.net-bs5, feather-icons, fullcalendar, inputmask, jquery-validation, moment, sortablejs, sweetalert2, tinymce #1

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

bmiguelbc16
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@mdi/font
from 7.1.96 to 7.4.47 | 3 versions ahead of your current version | 8 months ago
on 2023-12-27
@popperjs/core
from 2.11.6 to 2.11.8 | 2 versions ahead of your current version | a year ago
on 2023-05-26
@simonwep/pickr
from 1.8.2 to 1.9.1 | 2 versions ahead of your current version | 4 months ago
on 2024-05-10
ace-builds
from 1.14.0 to 1.35.4 | 54 versions ahead of your current version | 2 months ago
on 2024-07-22
apexcharts
from 3.36.3 to 3.52.0 | 27 versions ahead of your current version | a month ago
on 2024-08-05
bootstrap
from 5.2.3 to 5.3.3 | 7 versions ahead of your current version | 7 months ago
on 2024-02-20
chart.js
from 4.1.2 to 4.4.3 | 10 versions ahead of your current version | 4 months ago
on 2024-05-17
cropperjs
from 1.5.13 to 1.6.2 | 3 versions ahead of your current version | 5 months ago
on 2024-04-21
datatables.net-bs5
from 1.13.1 to 1.13.11 | 9 versions ahead of your current version | 6 months ago
on 2024-02-27
feather-icons
from 4.29.0 to 4.29.2 | 2 versions ahead of your current version | 4 months ago
on 2024-05-01
fullcalendar
from 6.0.3 to 6.1.15 | 15 versions ahead of your current version | 2 months ago
on 2024-07-12
inputmask
from 5.0.7 to 5.0.9 | 44 versions ahead of your current version | 3 months ago
on 2024-05-31
jquery-validation
from 1.19.5 to 1.21.0 | 3 versions ahead of your current version | 2 months ago
on 2024-07-17
moment
from 2.29.4 to 2.30.1 | 2 versions ahead of your current version | 8 months ago
on 2023-12-27
sortablejs
from 1.15.0 to 1.15.2 | 2 versions ahead of your current version | 8 months ago
on 2024-01-14
sweetalert2
from 11.7.0 to 11.12.4 | 51 versions ahead of your current version | a month ago
on 2024-08-01
tinymce
from 6.8.2 to 6.8.4 | 2 versions ahead of your current version | 3 months ago
on 2024-06-19

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Cross-site Scripting (XSS)
SNYK-JS-TINYMCE-7278053
479 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-TINYMCE-7278059
479 No Known Exploit
Release notes
Package name: @mdi/font from @mdi/font GitHub release notes
Package name: @popperjs/core
  • 2.11.8 - 2023-05-26
  • 2.11.7 - 2023-03-24
  • 2.11.6 - 2022-08-11
from @popperjs/core GitHub release notes
Package name: @simonwep/pickr
  • 1.9.1 - 2024-05-10

    Bug fixes

    • Include missing scss files in npm package (#331)
    • Add module field (#323)
    • Remove node-sass dependency (#328)
  • 1.9.0 - 2023-09-28

    Features

    • Support percentages for alpha in hsl and hsv.
    • Support new rgba syntax with relative values (#327).
  • 1.8.2 - 2021-09-14

    Fixes

    • Fix broken comparison option due to switch to css variables (#286).
    • Fix broken clear button (#283).

    Improvements

    • Dependency upgrades.
    • Upgrade to webpack 5.
    • Switch to GitHub actions.
    • Cleanups.
from @simonwep/pickr GitHub release notes
Package name: ace-builds
  • 1.35.4 - 2024-07-22

    package 22.07.24

  • 1.35.3 - 2024-07-18

    package 18.07.24

  • 1.35.2 - 2024-07-01

    package 01.07.24

  • 1.35.1 - 2024-06-27

    package 27.06.24

  • 1.35.0 - 2024-06-11

    package 11.06.24

  • 1.34.2 - 2024-05-27

    package 27.05.24

  • 1.34.1 - 2024-05-24

    package 24.05.24

  • 1.34.0 - 2024-05-22

    package 22.05.24

  • 1.33.3 - 2024-05-21

    package 21.05.24

  • 1.33.2 - 2024-05-13

    package 13.05.24

  • 1.33.1 - 2024-04-23
  • 1.33.0 - 2024-04-12
  • 1.32.9 - 2024-03-29
  • 1.32.8 - 2024-03-22
  • 1.32.7 - 2024-03-01
  • 1.32.6 - 2024-02-07
  • 1.32.5 - 2024-01-30
  • 1.32.4 - 2024-01-29
  • 1.32.3 - 2023-12-29
  • 1.32.2 - 2023-12-14
  • 1.32.1 - 2023-12-11
  • 1.32.0 - 2023-11-30
  • 1.31.2 - 2023-11-15
  • 1.31.1 - 2023-10-30
  • 1.31.0 - 2023-10-23
  • 1.30.0 - 2023-10-13
  • 1.29.0 - 2023-10-09
  • 1.28.0 - 2023-09-22
  • 1.27.0 - 2023-09-19
  • 1.26.0 - 2023-09-15
  • 1.25.1 - 2023-09-14
  • 1.25.0 - 2023-09-14
  • 1.24.2 - 2023-09-08
  • 1.24.1 - 2023-08-15
  • 1.24.0 - 2023-08-09
  • 1.23.4 - 2023-07-12
  • 1.23.3 - 2023-07-10
  • 1.23.2 - 2023-07-07
  • 1.23.1 - 2023-06-27
  • 1.23.0 - 2023-06-21
  • 1.22.1 - 2023-06-11
  • 1.22.0 - 2023-05-22
  • 1.21.1 - 2023-05-16
  • 1.21.0 - 2023-05-15
  • 1.20.0 - 2023-05-10
  • 1.19.0 - 2023-05-03
  • 1.18.1 - 2023-05-03
  • 1.18.0 - 2023-04-21
  • 1.17.0 - 2023-04-12
  • 1.16.0 - 2023-03-17
  • 1.15.3 - 2023-03-02
  • 1.15.2 - 2023-02-16
  • 1.15.1 - 2023-02-13
  • 1.15.0 - 2023-01-25
  • 1.14.0 - 2022-12-12
from ace-builds GitHub release notes
Package name: apexcharts
  • 3.52.0 - 2024-08-05

    What's Changed

    • fix #1339; tooltip.enabledOnSeries bugfix in irregular time series
    • fix #4600; show percentage in 100% stacked bar chart
    • fix #4067; incorrect x-axis labels for numeric x-axis for small dataset
    • fixes #4579; heatmap legend color issue
    • feat(ci): added continuous integration tests by @ Sebastian-Webster in #4577
    • Add null checks on gridRect to avoid safari error by @ Nikkitory in #4599

    New Contributors

    Full Changelog: v3.51.0...v3.52.0

  • 3.51.0 - 2024-07-21

    What's Changed

    ✨ More marker shapes

    hswil69ah

    Full Changelog: v3.50.0...v3.51.0

  • 3.50.0 - 2024-07-05

    What's Changed

    • Refactor markers code for generating new markers shapes (plus, cross, line)
    Screenshot 2024-07-05 at 11 27 12 PM

    New Contributors

    Full Changelog: v3.49.2...v3.50.0

  • 3.49.2 - 2024-06-25

    What's Changed

    New Contributors

    Full Changelog: v3.49.1...v3.49.2

  • 3.49.1 - 2024-05-12

    🆕 Enhancements

    basic-slope-chart

    🐞 Bug fixes

    • Fix issue #4216: grid padding calculation to support array of stroke widths, thanks @ veryinsanee
    • Fix heatmap yaxis offset #2033, thanks @ cart-before-horse
    • FIx types (yaxis.seriesName as an Array), thanks @ j2ghz
    • Remove redundant graphics.move() from end of lower rangeArea paths. - thanks @ rosco54
    • Fix #4386; pie chart size issue when given in percentage
    • Fix #3827 - y-axis tooltip value in reversed
    • Fix #4348 - dumbbell chart fix for timescale xaxis
    • Fix #2251 - pie chart dataPointIndex when clicked
    • Fix #4206 - datalabels in timeline chart
    • Revert PR #4240
  • 3.49.0 - 2024-04-21

    🐞 Bug fixes

    • Fix gradient fill glitches for series with nulls - by @ rosco54
    • Fix point annotation still visible when referenced series is collapsed. - by @ rosco54
    • Additional fixes for indexing errors using yaxis-series mappings after - by @ rosco54
    • Fixed Issue #3525. - by @ rosco54
    • added color evaluation function in Bar.js under stroke property - by @ Digvijayrao-KF
    • Radar chart bugfix #4371
    • Update zh-tw.json - by @ iblislin
    • Fixed #4402 by @ rosco54
  • 3.48.0 - 2024-03-19

    🆕 Enhancements

    • Provide a "step before" version of the current "step after" line chart; Fixes #4313
    • Use ShadowRoot getElementById() when in ShadowDOM; Thanks @ cyraid

    🐞 Bug fixes

    • Fixes #4323 (multiple y-axis scale fixes for backward compatibility)
    • Zoomed scale fixes - In zoomed charts, ensure the Y axis scale fits the full min..max range of Y values
    • Fix css nonce attribute
    • Improve grid-rect to prevent bar overflowing on x-axis
    • When chart is type 'bar', ensure reference to zero is maintained
    • Fixes #2757 (annotation overflow)
    • Fixes #3073 (annotation overflow)
    • Fixes #3421 (annotation overflow)
    • Fixes #3553 (annotation overflow)
    • Fixes #4081 (x-axis annotation fix in sparkline)

    Thanks @ rosco54 for multiple y-axis scale fixes

  • 3.47.0 - 2024-03-08

    🆕 Enhancements

    • Map multiple series to the same y-axis scales (in a multi-axes chart) - fixes #4237

    🐞 Bug fixes

    • Area chart gradient drawing glitch; fixes #4271
    • Point annotation fix when y-axis is not present (in case of sparkline or hidden y-axis)
    • When chart is type 'bar', ensure reference to zero is maintained

    Thanks @ rosco54 for y-axis scale improvements

  • 3.46.0 - 2024-02-17

    🆕 Enhancements

    • Improve the y-axis scale tick generation - Thanks @ rosco54
    • Added "+" and "x" markers - Thanks @ MiguelsPizza
    • Add Belarusan cyrilic and latin locale - Thanks @ hrynko

    🐞 Bug fixes

    • Fix #4167 - shadow bug in multi-series chart
    • Fix #4242 - allow labels with Invalid text
  • 3.45.2 - 2024-01-21

    🆕 Enhancements

    • Update pt.json - Thanks @ artur309
    • Add border-radius to treemap; fixes #4170

    🐞 Bug fixes

    • Fix the range-bar drawing bug when the value is 0
    • Discard initialXRatio in normal category bar charts - fixes #4134
    • Bring back original curve: smooth option for stroke as multiple people reported issues with monotoneCubic curve.
  • 3.45.1 - 2023-12-22
  • 3.45.0 - 2023-12-15
  • 3.44.2 - 2023-12-05
  • 3.44.1 - 2023-12-03
  • 3.44.0 - 2023-10-17
  • 3.43.2-0 - 2023-10-12
  • 3.43.0 - 2023-09-30
  • 3.42.0 - 2023-08-25
  • 3.41.1 - 2023-07-31
  • 3.41.0 - 2023-06-07
  • 3.40.0 - 2023-04-30
  • 3.39.0 - 2023-04-16
  • 3.38.0 - 2023-04-14
  • 3.37.3 - 2023-04-02
  • 3.37.2 - 2023-03-21
  • 3.37.1 - 2023-02-22
  • 3.37.0 - 2023-02-04
  • 3.36.3 - 2022-11-05
from apexcharts GitHub release notes
Package name: bootstrap
  • 5.3.3 - 2024-02-20

    Highlights

    • Fixed a breaking change introduced with color modes where it was required to manually import variables-dark.scss when building Bootstrap with Sass. Now, _variables.scss will automatically import _variables-dark.scss. If you were already importing _variables-dark.scss manually, you should keep doing it as it won't break anything and will be the way to go in v6.
    • Fixed a regression in the selector engine that wasn't able to handle multiple IDs anymore.

    Color modes

    • Badges now use the .text-bg-* text utilities to be certain that the text is always readable (especially when the customized colors are different in light and dark modes).
    • Fixed our color-modes.js script to handle the case where the OS is set to light mode and the auto color mode is used on the website. If you copied the script from our docs, you should apply this change to your own script.
    • Fixed color schemes description in the color modes documentation to show that color-scheme() only accept light and dark values as parameters.

    Miscellaneous

    • Allowed <dl>, <dt> and <dd> in the sanitizer.
    • Dropped evenly items distribution for modal and offcanvas headers.
    • Fixed the accordion CSS selectors to avoid inheritance issues when nesting accordions.
    • Fixed the focus box-shadow for the validation stated form controls.
    • Fixed the focus ring on focused checked buttons.
    • Fixed the product example mobile navbar toggler.
    • Changed the RTL processing of carousel control icons.

    🎨 CSS

    • #37508: Use child combinators to avoid inheriting parent accordion's flush styles
    • #38719: Fix focus box-shadow for validation stated form-controls
    • #38884: fix border-radius on radio-switch
    • #39294: Tests: update navbar in visual modal test
    • #39373: refactor css: modal and offcanvas header spacing
    • #39380: Fix Sass compilation breaking change in v5.3
    • #39387: docs: fix typo
    • #39411: Optimize the accordion icon
    • #39497: Fix a typo
    • #39536: Changed RTL processing of carousel control icons

Snyk has created this PR to upgrade:
  - @mdi/font from 7.1.96 to 7.4.47.
    See this package in npm: https://www.npmjs.com/package/@mdi/font
  - @popperjs/core from 2.11.6 to 2.11.8.
    See this package in npm: https://www.npmjs.com/package/@popperjs/core
  - @simonwep/pickr from 1.8.2 to 1.9.1.
    See this package in npm: https://www.npmjs.com/package/@simonwep/pickr
  - ace-builds from 1.14.0 to 1.35.4.
    See this package in npm: https://www.npmjs.com/package/ace-builds
  - apexcharts from 3.36.3 to 3.52.0.
    See this package in npm: https://www.npmjs.com/package/apexcharts
  - bootstrap from 5.2.3 to 5.3.3.
    See this package in npm: https://www.npmjs.com/package/bootstrap
  - chart.js from 4.1.2 to 4.4.3.
    See this package in npm: https://www.npmjs.com/package/chart.js
  - cropperjs from 1.5.13 to 1.6.2.
    See this package in npm: https://www.npmjs.com/package/cropperjs
  - datatables.net-bs5 from 1.13.1 to 1.13.11.
    See this package in npm: https://www.npmjs.com/package/datatables.net-bs5
  - feather-icons from 4.29.0 to 4.29.2.
    See this package in npm: https://www.npmjs.com/package/feather-icons
  - fullcalendar from 6.0.3 to 6.1.15.
    See this package in npm: https://www.npmjs.com/package/fullcalendar
  - inputmask from 5.0.7 to 5.0.9.
    See this package in npm: https://www.npmjs.com/package/inputmask
  - jquery-validation from 1.19.5 to 1.21.0.
    See this package in npm: https://www.npmjs.com/package/jquery-validation
  - moment from 2.29.4 to 2.30.1.
    See this package in npm: https://www.npmjs.com/package/moment
  - sortablejs from 1.15.0 to 1.15.2.
    See this package in npm: https://www.npmjs.com/package/sortablejs
  - sweetalert2 from 11.7.0 to 11.12.4.
    See this package in npm: https://www.npmjs.com/package/sweetalert2
  - tinymce from 6.8.2 to 6.8.4.
    See this package in npm: https://www.npmjs.com/package/tinymce

See this project in Snyk:
https://app.snyk.io/org/bmiguelbc16/project/1e0607f7-9e30-473a-b67e-f878ac02e157?utm_source=github&utm_medium=referral&page=upgrade-pr
@bmiguelbc16 bmiguelbc16 self-assigned this Sep 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment