Skip to content

[Snyk] Security upgrade @reduxjs/toolkit from 1.5.1 to 1.6.0#102

Open
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-a8ce10c7a2fdcae33e04c224dbc6e75e
Open

[Snyk] Security upgrade @reduxjs/toolkit from 1.5.1 to 1.6.0#102
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-a8ce10c7a2fdcae33e04c224dbc6e75e

Conversation

@snyk-bot
Copy link
Contributor

@snyk-bot snyk-bot commented Sep 1, 2021

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 673/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-IMMER-1540542
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @reduxjs/toolkit The new version differs by 250 commits.
  • 8910a61 1.6.0
  • b718e01 Merge pull request #1016 from reduxjs/feature/v1.6-integration
  • 034bdec Merge branch 'master' into feature/v1.6-integration
  • 17d4629 Merge pull request #1140 from reduxjs/docs/rtkq-exports
  • dac5b00 Remove legacy RTKQ incubator files
  • 4a1d92f Add API docs for miniSerializeError and copyWithStructuralSharing
  • bdc4e3f Merge pull request #1115 from Shrugsy/docs/dynamic-base-url-example-snippet
  • 0075ca9 Merge pull request #1138 from reduxjs/docs/final-rtkq-cleanup
  • f9f85c7 add TS 4.3 to test matrix, disable `strictOptionalProperties` for TS4.4 (#1137)
  • 9e76b6b Add NgRx interop links
  • 64eeee8 Merge branch 'feature/v1.6-integration' into docs/final-rtkq-cleanup
  • b3eee1c Merge pull request #1136 from reduxjs/example-chores
  • 64ffe4b Lots more docs cleanup!
  • c50cf53 fixup examples
  • b1dc9e1 chores: move examples to current RC
  • 13d57c6 Show sandboxes as run-on-click
  • 0c04f42 Expand Query/Mutation descriptions and clarify TS usage
  • 72f9332 Clean up grammar
  • a31e3c5 Add RTQK navbar / footer links
  • c2c4f51 Add additional RTKQ comparison and intro material
  • 4cfdf8a Merge pull request #1135 from Shrugsy/docs/clarify-query-loading-states
  • f94e9d3 📝 Clarify query loading states
  • 037e772 Merge pull request #1133 from Shrugsy/docs/extend-onQueryStarted-documentation
  • ead8694 * change get/update singular post example

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-IMMER-1540542
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant