Skip to content

[Snyk] Fix for 2 vulnerabilities#196

Open
grootjans wants to merge 1 commit into
masterfrom
snyk-fix-d6eb6fb78699fa10993e4022897b5706
Open

[Snyk] Fix for 2 vulnerabilities#196
grootjans wants to merge 1 commit into
masterfrom
snyk-fix-d6eb6fb78699fa10993e4022897b5706

Conversation

@grootjans

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the pnpm dependencies of this project.

Snyk changed the following file(s):

  • packages/pluggable-widgets-tools/package.json
⚠️ Warning
Failed to update the pnpm-lock.yaml, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Inefficient Algorithmic Complexity
SNYK-JS-JSYAML-18313070
  828  
high severity Directory Traversal
SNYK-JS-POSTCSS-18313038
  721  

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal

@grootjans

Copy link
Copy Markdown
Author

Merge Risk: High

This upgrade to eslint@10.0.0 is a major version with significant breaking changes requiring mandatory configuration updates. The upgrade for postcss is a minor patch with low risk.

eslint 9.39.4 → 10.0.0 (High Risk)

This major release finalizes the transition to the "flat config" system and drops support for legacy configurations.

Key Breaking Changes:

  • eslintrc Configuration Removed: Support for .eslintrc.* files has been completely removed. You must migrate to a flat config file (eslint.config.js).
  • Node.js Version Requirement: Support for Node.js versions older than v20.19.0 has been dropped.
  • New Config File Lookup: ESLint now locates the configuration file starting from the directory of each linted file, which primarily affects monorepo setups.
  • API and CLI Changes: Deprecated Linter methods, SourceCode methods, and eslintrc-specific CLI flags (e.g., --env, --rulesdir) have been removed.
  • JSX Reference Tracking: JSX elements are now tracked for scope analysis, which may lead to new no-unused-vars errors if components are not used correctly.

Recommendation:
It is mandatory to migrate your configuration from .eslintrc to eslint.config.js. Use the official migration guide and codemods to automate this process before upgrading.

postcss 8.5.14 → 8.5.18 (Low Risk)

This is a patch release containing bug fixes and a minor security enhancement. Version 8.5.18 restricts source map file loading paths for security reasons, which is unlikely to impact standard builds.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants