Skip to content

[Snyk] Security upgrade react-syntax-highlighter from 5.8.0 to 15.4.2#692

Closed
wkylin wants to merge 1 commit into
mainfrom
snyk-fix-f0b9aba5cf745764a7ebcb49db3a9f01
Closed

[Snyk] Security upgrade react-syntax-highlighter from 5.8.0 to 15.4.2#692
wkylin wants to merge 1 commit into
mainfrom
snyk-fix-f0b9aba5cf745764a7ebcb49db3a9f01

Conversation

@wkylin
Copy link
Copy Markdown
Owner

@wkylin wkylin commented May 24, 2025

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue
medium severity Prototype Pollution
SNYK-JS-HIGHLIGHTJS-1045326
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HIGHLIGHTJS-1048676

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution
🦉 Regular Expression Denial of Service (ReDoS)

@vercel
Copy link
Copy Markdown

vercel Bot commented May 24, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
pro-react-admin ✅ Ready (Inspect) Visit Preview 💬 Add feedback May 24, 2025 7:00am

@what-the-diff
Copy link
Copy Markdown

what-the-diff Bot commented May 24, 2025

PR总结

  • 更改1:更新了react-syntax-highlighter的版本
    我们在package.jsonpackage-lock.json两个文件中,把react-syntax-highlighter的版本从^5.8.0更新到了^15.4.2

  • 更改2:添加了新的模块hast-util-parse-selector
    我们在package-lock.json中添加了版本为2.2.5hast-util-parse-selector模块以及其相关元数据。

  • 更改3: 添加了新的模块hastscript
    package-lock.json中添加了版本为6.0.0的新模块hastscript,以及它的依赖关系。

  • 更改4:更新了lowlight版本
    package-lock.json中,lowlight的依赖版本从1.9.2升级到了1.20.0,也对它的依赖进行了更新。

  • 更改5:更新了highlight.js版本
    lowlight模块中,highlight.js的依赖版本由9.12.0更新到了10.7.3

  • 更改6:添加了新的模块refractor
    我们在package-lock.json中添加了版本3.6.0refractor模块及其依赖关系。

  • 更改7:为refractor模块添加了各种新依赖
    package-lock.json中,我们为refractor模块添加了各种特定版本的新依赖。

  • 更改8:标记了开发依赖项
    package-lock.json中,包括babel-runtime在内的多个项目被标记为dev: true,表示这些都是开发依赖项。

@sonarqubecloud
Copy link
Copy Markdown

@wkylin wkylin closed this May 24, 2025
@wkylin wkylin deleted the snyk-fix-f0b9aba5cf745764a7ebcb49db3a9f01 branch May 31, 2025 07:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants