[Snyk] Upgrade: , react, react-dom, , , , formik, next, use-remote-data #131
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@emotion/styled
from 11.6.0 to 11.13.0 | 12 versions ahead of your current version | 2 months ago
on 2024-07-20
react
from 17.0.0 to 17.0.2 | 2 versions ahead of your current version | 3 years ago
on 2021-03-22
react-dom
from 17.0.0 to 17.0.2 | 2 versions ahead of your current version | 3 years ago
on 2021-03-22
@chakra-ui/icons
from 1.1.1 to 1.1.7 | 6 versions ahead of your current version | 3 years ago
on 2022-02-20
@chakra-ui/react
from 1.7.2 to 1.8.9 | 13 versions ahead of your current version | 2 years ago
on 2022-09-16
@emotion/react
from 11.7.0 to 11.13.3 | 18 versions ahead of your current version | 23 days ago
on 2024-08-21
formik
from 2.2.9 to 2.4.6 | 11 versions ahead of your current version | 5 months ago
on 2024-04-24
next
from 12.0.7 to 12.3.4 | 275 versions ahead of your current version | 2 years ago
on 2022-11-21
use-remote-data
from 0.4.0 to 0.5.1 | 2 versions ahead of your current version | 2 years ago
on 2022-10-14
Issues fixed by the recommended upgrade:
SNYK-JS-BRACES-6838727
SNYK-JS-BROWSERIFYSIGN-6037026
SNYK-JS-SEMVER-3247795
SNYK-JS-NANOID-2332193
SNYK-JS-NEXT-2388583
SNYK-JS-NEXT-2405694
SNYK-JS-ELLIPTIC-7577916
SNYK-JS-NODEFETCH-2342118
SNYK-JS-ELLIPTIC-7577917
SNYK-JS-ELLIPTIC-7577918
SNYK-JS-LOADERUTILS-3043105
SNYK-JS-JSON5-3182856
SNYK-JS-LOADERUTILS-3042992
SNYK-JS-LOADERUTILS-3105943
SNYK-JS-MINIMIST-2429795
Release notes
Package name: @emotion/styled
-
11.13.0 - 2024-07-20
-
-
- Updated dependencies [
- @ emotion/[email protected]
- @ emotion/[email protected]
- @ emotion/[email protected]
-
11.12.0 - 2024-07-19
-
11.11.5 - 2024-03-29
-
11.11.0 - 2023-05-06
-
11.10.8 - 2023-04-28
-
11.10.6 - 2023-02-16
-
11.10.5 - 2022-10-27
-
11.10.4 - 2022-08-30
-
11.10.0 - 2022-07-31
-
11.9.3 - 2022-06-12
-
11.8.1 - 2022-02-19
-
11.8.0 - 2022-02-19
-
11.6.0 - 2021-11-14
from @emotion/styled GitHub release notesMinor Changes
#3198
d8ff8a5Thanks @ Andarist! - Migrated away from relying onprocess.env.NODE_ENVchecks to differentiate between production and development builds.Development builds (and other environment-specific builds) can be used by using proper conditions (see here). Most modern bundlers/frameworks already preconfigure those for the user so no action has to be taken.
Default files should continue to work in all environments.
#3215
a9f6912Thanks @ Andarist! - Addededge-lightandworkerdconditions topackage.jsonmanifest to better serve users using Vercel Edge and Cloudflare Workers.Patch Changes
d8ff8a5,a9f6912]:Package name: react
-
17.0.2 - 2021-03-22
- Remove an unused dependency to address the
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
-
17.0.1 - 2020-10-22
- Fix a crash in IE11. (@ gaearon in #20071)
-
17.0.0 - 2020-10-20
- Add
- Build component stacks from native error frames. (@ sebmarkbage in #18561)
- Allow to specify
- Prevent
- Stop using
- Delegate events to roots instead of
- Clean up all effects before running any next effects. (@ bvaughn in #17947)
- Run
- Use browser
- Make all
- Don't emulate bubbling of the
- Throw if
- Remove event pooling. (@ trueadm in #18969)
- Stop exposing internals that won’t be needed by React Native Web. (@ necolas in #18483)
- Attach all known event listeners when the root mounts. (@ gaearon in #19659)
- Disable
- Deprecate the undocumented and misleading
- Rename private field names used in the internals. (@ gaearon in #18377)
- Don't call User Timing API in development. (@ gaearon in #18417)
- Disable console during the repeated render in Strict Mode. (@ sebmarkbage in #18547)
- In Strict Mode, double-render components without Hooks too. (@ eps1lon in #18430)
- Allow calling
- Add the
- Add the
- Add the
- Warn when no
- Warn when
- Improve the error message for invalid updates. (@ JoviDeCroock in #18316)
- Exclude forwardRef and memo from stack frames. (@ sebmarkbage in #18559)
- Improve the error message when switching between controlled and uncontrolled inputs. (@ vcarl in #17070)
- Keep
- Fix
- Fix rendering bailout for lazy components with
- Fix a false positive warning when
- Fix Test Utils with non-standard
- Fix
- Fix
- Fix "unspecified error" in IE11. (@ hemakshis in #19664)
- Fix rendering into a shadow root. (@ Jack-Works in #15894)
- Fix
- Use delegation for
- Improve memory usage. (@ trueadm in #18970)
- Make
- Fix state leaking when a function component throws. (@ pmaccart in #19212)
- Improve
- Revamp the priority batching heuristics. (@ acdlite in #18796)
- Add the
- Remove
- Remove the
- Disable
- Add
- Add an experimental
- Add an experimental
- Using
- Use global render timeout for CPU Suspense. (@ sebmarkbage in #19643)
- Clear the existing root content before mounting. (@ bvaughn in #18730)
- Fix a bug with error boundaries. (@ acdlite in #18265)
- Fix a bug causing dropped updates in a suspended tree. (@ acdlite in #18384 and #18457)
- Fix a bug causing dropped render phase updates. (@ acdlite in #18537)
- Fix a bug in SuspenseList. (@ sebmarkbage in #18412)
- Fix a bug causing Suspense fallback to show too early. (@ acdlite in #18411)
- Fix a bug with class components inside SuspenseList. (@ sebmarkbage in #18448)
- Fix a bug with inputs that may cause updates to be dropped. (@ jddxf in #18515 and @ acdlite in #18535)
- Fix a bug causing Suspense fallback to get stuck. (@ acdlite in #18663)
- Don't cut off the tail of a SuspenseList if hydrating. (@ sebmarkbage in #18854)
- Fix a bug in
- Fix a tearing bug in
- Warn if calling setState outside of render but before commit. (@ sebmarkbage in #18838)
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
from react GitHub release notesReact DOM
SharedArrayBuffercross-origin isolation warning. (@ koba04 and @ bvaughn in #20831, #20832, and #20840)Artifacts
React DOM
Today, we are releasing React 17!
Learn more about React 17 and how to update to it on the official React blog.
React
react/jsx-runtimeandreact/jsx-dev-runtimefor the new JSX transform. (@ lunaruan in #18299)displayNameon context for improved stacks. (@ eps1lon in #18224)'use strict'from leaking in the UMD bundles. (@ koba04 in #19614)fb.mefor redirects. (@ cylim in #19598)React DOM
document. (@ trueadm in #18195 and others)useEffectcleanup functions asynchronously. (@ bvaughn in #17925)focusinandfocusoutforonFocusandonBlur. (@ trueadm in #19186)Captureevents use the browser capture phase. (@ trueadm in #19221)onScrollevent. (@ gaearon in #19464)forwardReformemocomponent returnsundefined. (@ gaearon in #19550)consolein the second render pass of DEV mode double render. (@ sebmarkbage in #18547)ReactTestUtils.SimulateNativeAPI. (@ gaearon in #13407)ReactDOM.flushSyncduring lifecycle methods (but warn). (@ sebmarkbage in #18759)codeproperty to the keyboard event objects. (@ bl00mber in #18287)disableRemotePlaybackproperty forvideoelements. (@ tombrowndev in #18619)enterKeyHintproperty forinputelements. (@ eps1lon in #18634)valueis provided to<Context.Provider>. (@ charlie1404 in #19054)memoorforwardRefcomponents returnundefined. (@ bvaughn in #19550)onTouchStart,onTouchMove, andonWheelpassive. (@ gaearon in #19654)setStatehanging in development inside a closed iframe. (@ gaearon in #19220)defaultProps. (@ jddxf in #18539)dangerouslySetInnerHTMLisundefined. (@ eps1lon in #18676)requireimplementation. (@ just-boris in #18632)onBeforeInputreporting an incorrectevent.type. (@ eps1lon in #19561)event.relatedTargetreported asundefinedin Firefox. (@ claytercek in #19607)movementX/Ypolyfill with capture events. (@ gaearon in #19672)onSubmitandonResetevents. (@ gaearon in #19333)React DOM Server
useCallbackbehavior consistent withuseMemofor the server renderer. (@ alexmckenley in #18783)React Test Renderer
findByTypeerror message. (@ henryqdineen in #17439)Concurrent Mode (Experimental)
unstable_prefix before the experimental APIs. (@ acdlite in #18825)unstable_discreteUpdatesandunstable_flushDiscreteUpdates. (@ trueadm in #18825)timeoutMsargument. (@ acdlite in #19703)<div hidden />prerendering in favor of a different future API. (@ acdlite in #18917)unstable_expectedLoadTimeto Suspense for CPU-bound trees. (@ acdlite in #19936)unstable_useOpaqueIdentifierHook. (@ lunaruan in #17322)unstable_startTransitionAPI. (@ rickhanlonii in #19696)actin the test renderer no longer flushes Suspense fallbacks. (@ acdlite in #18596)useMutableSourcethat may happen whengetSnapshotchanges. (@ bvaughn in #18297)useMutableSource. (@ bvaughn in #18912)Artifacts
Package name: react-dom
-
17.0.2 - 2021-03-22
- Remove an unused dependency to address the
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
-
17.0.1 - 2020-10-22
- Fix a crash in IE11. (@ gaearon in #20071)
-
17.0.0 - 2020-10-20
- Add
- Build component stacks from native error frames. (@ sebmarkbage in #18561)
- Allow to specify
- Prevent
- Stop using
- Delegate events to roots instead of
- Clean up all effects before running any next effects. (@ bvaughn in #17947)
- Run
- Use browser
- Make all
- Don't emulate bubbling of the
- Throw if
- Remove event pooling. (@ trueadm in #18969)
- Stop exposing internals that won’t be needed by React Native Web. (@ necolas in #18483)
- Attach all known event listeners when the root mounts. (@ gaearon in #19659)
- Disable
- Deprecate the undocumented and misleading
- Rename private field names used in the internals. (@ gaearon in #18377)
- Don't call User Timing API in development. (@ gaearon in #18417)
- Disable console during the repeated render in Strict Mode. (@ sebmarkbage in #18547)
- In Strict Mode, double-render components without Hooks too. (@ eps1lon in #18430)
- Allow calling
- Add the
- Add the
- Add the
- Warn when no
- Warn when
- Improve the error message for invalid updates. (@ JoviDeCroock in #18316)
- Exclude forwardRef and memo from stack frames. (@ sebmarkbage in #18559)
- Improve the error message when switching between controlled and uncontrolled inputs. (@ vcarl in #17070)
- Keep
- Fix
- Fix rendering bailout for lazy components with
- Fix a false positive warning when
- Fix Test Utils with non-standard
- Fix
- Fix
- Fix "unspecified error" in IE11. (@ hemakshis in #19664)
- Fix rendering into a shadow root. (@ Jack-Works in #15894)
- Fix
- Use delegation for
- Improve memory usage. (@ trueadm in #18970)
- Make
- Fix state leaking when a function component throws. (@ pmaccart in #19212)
- Improve
- Revamp the priority batching heuristics. (@ acdlite in #18796)
- Add the
- Remove
- Remove the
- Disable
- Add
- Add an experimental
- Add an experimental
- Using
- Use global render timeout for CPU Suspense. (@ sebmarkbage in #19643)
- Clear the existing root content before mounting. (@ bvaughn in #18730)
- Fix a bug with error boundaries. (@ acdlite in #18265)
- Fix a bug causing dropped updates in a suspended tree. (@ acdlite in #18384 and #18457)
- Fix a bug causing dropped render phase updates. (@ acdlite in #18537)
- Fix a bug in SuspenseList. (@ sebmarkbage in #18412)
- Fix a bug causing Suspense fallback to show too early. (@ acdlite in #18411)
- Fix a bug with class components inside SuspenseList. (@ sebmarkbage in #18448)
- Fix a bug with inputs that may cause updates to be dropped. (@ jddxf in #18515 and @ acdlite in #18535)
- Fix a bug causing Suspense fallback to get stuck. (@ acdlite in #18663)
- Don't cut off the tail of a SuspenseList if hydrating. (@ sebmarkbage in #18854)
- Fix a bug in
- Fix a tearing bug in
- Warn if calling setState outside of render but before commit. (@ sebmarkbage in #18838)
- react: https://unpkg.com/[email protected]/umd/
- react-art: https://unpkg.com/[email protected]/umd/
- react-dom: https://unpkg.com/[email protected]/umd/
- react-is: https://unpkg.com/[email protected]/umd/
- react-test-renderer: https://unpkg.com/[email protected]/umd/
- scheduler: https://unpkg.com/[email protected]/umd/
from react-dom GitHub release notesReact DOM
SharedArrayBuffercross-origin isolation warning. (@ koba04 and @ bvaughn in #20831, #20832, and #20840)Artifacts
React DOM
Today, we are releasing React 17!
Learn more about React 17 and how to update to it on the official React blog.
React
react/jsx-runtimeandreact/jsx-dev-runtimefor the new JSX transform. (@ lunaruan in #18299)displayNameon context for improved stacks. (@ eps1lon in #18224)'use strict'from leaking in the UMD bundles. (@ koba04 in #19614)fb.mefor redirects. (@ cylim in #19598)React DOM
document. (@ trueadm in #18195 and others)useEffectcleanup functions asynchronously. (@ bvaughn in #17925)focusinandfocusoutforonFocusandonBlur. (@ trueadm in #19186)Captureevents use the browser capture phase. (@ trueadm in #19221)onScrollevent. (@ gaearon in #19464)forwardReformemocomponent returnsundefined. (@ gaearon in #19550)consolein the second render pass of DEV mode double render. (@ sebmarkbage in #18547)ReactTestUtils.SimulateNativeAPI. (@ gaearon in #13407)ReactDOM.flushSyncduring lifecycle methods (but warn). (@ sebmarkbage in #18759)codeproperty to the keyboard event objects. (@ bl00mber in #18287)disableRemotePlaybackproperty forvideoelements. (@ tombrowndev in #18619)enterKeyHintproperty forinputelements. (@ eps1lon in #18634)valueis provided to<Context.Provider>. (@ charlie1404 in #19054)memoorforwardRefcomponents returnundefined. (@ bvaughn in #19550)onTouchStart,onTouchMove, andonWheelpassive. (@ gaearon in #19654)setStatehanging in development inside a closed iframe. (@ gaearon in #19220)defaultProps. (@ jddxf in #18539)dangerouslySetInnerHTMLisundefined. (@ eps1lon in #18676)requireimplementation. (@ just-boris in #18632)onBeforeInputreporting an incorrectevent.type. (@ eps1lon in #19561)event.relatedTargetreported asundefinedin Firefox. (@ claytercek in #19607)movementX/Ypolyfill with capture events. (@ gaearon in #19672)onSubmitandonResetevents. (@ gaearon in #19333)React DOM Server
useCallbackbehavior consistent withuseMemofor the server renderer. (@ alexmckenley in #18783)React Test Renderer
findByTypeerror message. (@ henryqdineen in #17439)Concurrent Mode (Experimental)
unstable_prefix before the experimental APIs. (@ acdlite in #18825)unstable_discreteUpdatesandunstable_flushDiscreteUpdates. (@ trueadm in #18825)timeoutMsargument. (@ acdlite in #19703)<div hidden />prerendering in favor of a different future API. (@ acdlite in #18917)unstable_expectedLoadTimeto Suspense for CPU-bound trees. (@ acdlite in #19936)unstable_useOpaqueIdentifierHook. (@ lunaruan in #17322)unstable_startTransitionAPI. (@ rickhanlonii in #19696)actin the test renderer no longer flushes Suspense fallbacks. (@ acdlite in #18596)useMutableSourcethat may happen whengetSnapshotchanges. (@ bvaughn in #18297)useMutableSource. (@ bvaughn in #18912)Artifacts
Package name: @chakra-ui/icons
-
1.1.7 - 2022-02-20
-
1.1.6 - 2022-02-17
-
1.1.5 - 2022-02-05
-
1.1.4 - 2022-02-04
-
1.1.3 - 2022-01-25
-
1.1.2 - 2021-12-09
-
1.1.1 - 2021-11-12
from @chakra-ui/icons GitHub release notesPackage name: @chakra-ui/react
-
1.8.9 - 2022-09-16
-
1.8.8 - 2022-04-07
-
1.8.7 - 2022-03-27
-
1.8.6 - 2022-02-28
-
1.8.5 - 2022-02-20
-
1.8.4 - 2022-02-14
-
1.8.3 - 2022-02-05
-
1.8.2 - 2022-01-31
-
1.8.1 - 2022-01-26
-
1.8.0 - 2022-01-25
-
1.7.5 - 2022-01-09
-
1.7.4 - 2022-01-04
-
1.7.3 - 2021-12-09
-
1.7.2 - 2021-11-17
from @chakra-ui/react GitHub release notesPackage name: @emotion/react
-
11.13.3 - 2024-08-21
-
-
- @ emotion/[email protected]
-
11.13.0 - 2024-07-20
-
-
- Updated dependencies [
- @ emotion/[email protected]
- @ emotion/[email protected]
- @ emotion/[email protected]
-
11.12.0 - 2024-07-19
-
11.11.4 - 2024-02-27
-
11.11.3 - 2023-12-23
-
11.11.1 - 2023-06-07
-
11.11.0 - 2023-05-06
-
11.10.8 - 2023-04-28
-
11.10.6 - 2023-02-16
-
11.10.5 - 2022-10-27
-
11.10.4 - 2022-08-30
-
11.10.0 - 2022-07-31
-
11.9.3 - 2022-06-12
-
11.9.0 - 2022-04-06
-
11.8.2 - 2022-03-10
-
11.8.1 - 2022-02-19
-
11.8.0 - 2022-02-19
-
11.7.1 - 2021-12-12
-
11.7.0 - 2021-11-26
from @emotion/react GitHub release notesPatch Changes
#3232
0ce3ed0Thanks @ ENvironmentSet! - Distributecssprop attachment over props that are union typesUpdated dependencies []:
Minor Changes
#3198
d8ff8a5Thanks @ Andarist! - Migrated away from relying onprocess.env.NODE_ENVchecks to differentiate between production and development builds.Development builds (and other environment-specific builds) can be used by using proper conditions (see here). Most modern bundlers/frameworks already preconfigure those for the user so no action has to be taken.
Default files should continue to work in all environments.
#3215
a9f6912Thanks @ Andarist! - Addededge-lightandworkerdconditions topackage.jsonmanifest to better serve users using Vercel Edge and Cloudflare Workers.Patch Changes
d8ff8a5,a9f6912]:Package name: formik
Patch Changes
f57ca9b#3949 Thanks @ DeveloperRaj! - Changing the state inside formik was changing reference of initialValues provided via props, deep cloning the initialvalues will fix it.Patch Changes
d7db9cd#3860 Thanks @ patik! - Add missing dependency@ types/hoist-non-react-statics, closes #3837fe4ed7e#3501 Thanks @ markspolakovs! - Markformikas side-effect free inpackage.jsonPatch Changes
41720c2#3862 Thanks @ yazaldefilimonepinto! - ForwardclassNamefor custom components used withField...