Skip to content

[Snyk] Upgrade: , bootstrap, jquery, moment, datatables.net, datatables.net-bs4, jquery-ui-dist, jquery-validation, bootstrap-touchspin, cldr-data, datatables.net-buttons, datatables.net-buttons-bs4, jquery-migrate, jsrender, magnific-popup, swiper, tinymce #20

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

shivajirepo
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@fortawesome/fontawesome-free
from 5.15.2 to 5.15.4 | 2 versions ahead of your current version | 3 years ago
on 2021-08-04
bootstrap
from 4.6.0 to 4.6.2 | 2 versions ahead of your current version | 2 years ago
on 2022-07-19
jquery
from 3.6.0 to 3.7.1 | 6 versions ahead of your current version | a year ago
on 2023-08-28
moment
from 2.29.4 to 2.30.1 | 2 versions ahead of your current version | 8 months ago
on 2023-12-27
datatables.net
from 1.12.1 to 1.13.11 | 11 versions ahead of your current version | 6 months ago
on 2024-02-27
datatables.net-bs4
from 1.12.1 to 1.13.11 | 11 versions ahead of your current version | 6 months ago
on 2024-02-27
jquery-ui-dist
from 1.13.2 to 1.13.3 | 1 version ahead of your current version | 3 months ago
on 2024-05-26
jquery-validation
from 1.19.5 to 1.21.0 | 3 versions ahead of your current version | 2 months ago
on 2024-07-17
bootstrap-touchspin
from 4.3.0 to 4.7.3 | 11 versions ahead of your current version | a year ago
on 2023-05-25
cldr-data
from 36.0.1 to 36.0.2 | 1 version ahead of your current version | 5 months ago
on 2024-04-12
datatables.net-buttons
from 1.6.5 to 1.7.1 | 2 versions ahead of your current version | 3 years ago
on 2021-06-04
datatables.net-buttons-bs4
from 1.6.5 to 1.7.1 | 2 versions ahead of your current version | 3 years ago
on 2021-06-04
jquery-migrate
from 3.4.0 to 3.5.2 | 4 versions ahead of your current version | 2 months ago
on 2024-07-17
jsrender
from 1.0.11 to 1.0.15 | 4 versions ahead of your current version | 2 months ago
on 2024-07-14
magnific-popup
from 1.1.0 to 1.2.0 | 1 version ahead of your current version | 3 months ago
on 2024-06-08
swiper
from 8.3.2 to 8.4.7 | 8 versions ahead of your current version | 2 years ago
on 2023-01-30
tinymce
from 5.10.7 to 5.10.9 | 2 versions ahead of your current version | 10 months ago
on 2023-11-15

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Cross-site Scripting (XSS)
SNYK-JS-TINYMCE-6016276
519 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-TINYMCE-6016290
519 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-TINYMCE-6062167
519 No Known Exploit
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
519 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
519 No Known Exploit
Release notes
Package name: @fortawesome/fontawesome-free
  • 5.15.4 - 2021-08-04
  • 5.15.3 - 2021-03-16
  • 5.15.2 - 2021-01-13
from @fortawesome/fontawesome-free GitHub release notes
Package name: bootstrap from bootstrap GitHub release notes
Package name: jquery from jquery GitHub release notes
Package name: moment from moment GitHub release notes
Package name: datatables.net
  • 1.13.11 - 2024-02-27
  • 1.13.10 - 2024-02-09
  • 1.13.8 - 2023-11-16
  • 1.13.7 - 2023-11-03
  • 1.13.6 - 2023-07-31
  • 1.13.5 - 2023-07-04
  • 1.13.4 - 2023-03-10
  • 1.13.3 - 2023-02-28
  • 1.13.2 - 2023-02-03
  • 1.13.1 - 2022-11-08
  • 1.13.0 - 2022-11-08
  • 1.12.1 - 2022-05-19
from datatables.net GitHub release notes
Package name: datatables.net-bs4
  • 1.13.11 - 2024-02-27
  • 1.13.10 - 2024-02-09
  • 1.13.8 - 2023-11-16
  • 1.13.7 - 2023-11-03
  • 1.13.6 - 2023-07-31
  • 1.13.5 - 2023-07-04
  • 1.13.4 - 2023-03-10
  • 1.13.3 - 2023-02-28
  • 1.13.2 - 2023-02-03
  • 1.13.1 - 2022-11-08
  • 1.13.0 - 2022-11-07
  • 1.12.1 - 2022-05-19
from datatables.net-bs4 GitHub release notes
Package name: jquery-ui-dist from jquery-ui-dist GitHub release notes
Package name: jquery-validation
  • 1.21.0 - 2024-07-17

    What's Changed

    New Contributors

    Full Changelog: 1.20.1...1.21.0

  • 1.20.1 - 2024-06-13

    What's Changed

    • Localization: Update Arabic translations by @ 5baddi in #2485
    • Core: fix remote validation when input is the same as in aborted request by @ bidord in #2481

    New Contributors

    Full Changelog: 1.20.0...1.20.1

  • 1.20.0 - 2023-10-09

    1.20.0 / 2023-10-10

    Additional

    • Fixed vinUS validation failing on valid vin numbers #2460

    Core

    • Fixed race condition in remote validation rules #2435
    • Removed pending class from fields with an aborted request #2436
    • Fixed remote validation error tracking #2242
    • Added escapeHtml option to avoid XSS attacks via showLabel method #2462

    Demo

    • Fixed minlength validation in ajaxSubmit-integration-demo.html #2454

    Localisation

    • Improved required translation in pt_BR #2445
    • Added Hindi translation #2453
    • Added French currency translation #2471
  • 1.19.5 - 2022-07-01

    1.19.5 / 2022-07-01

    Chore

    Core

    • Fixed jQuery .submit() event shorthand deprecation notice #2430
    • Fixed ReDos vulnerability in url, and url2 validation 5bbd80d

    Localisation

    • Added periods to messages #2266
from jquery-validation GitHub release notes
Package name: bootstrap-touchspin
  • 4.7.3 - 2023-05-25

    Disable tabindex on the up/down buttons

  • 4.7.2 - 2023-05-25

    Added Babel to the build process to make the dist file ES5 compatible.

  • 4.7.1 - 2023-05-25
    • Firing the min and max events as soon as the value reaches the minimum or the maximum.
      Beware that if step is not 1 then the minimum and maximum settings will be overwritten with the values that can be reached with the given step. Like if step is 3 and min is specified as 44 then the touchspin.on.min event will be fired as soon as the value reaches 45, which is the minimum value that can be reached with the given step.
  • 4.7.0 - 2023-05-24
    • Better RTL support
    • Refactored vertical button handling
    • Better support for initializing with existing input group addons
  • 4.6.2 - 2023-04-07

    Fixing callback related bugs

  • 4.6.1 - 2023-04-06

    Fixes #115

  • 4.6.0 - 2023-04-04
    • Changing license to MIT
    • Fixing bugs with readonly inputs
  • 4.5.4 - 2023-04-04
    • Adding support for the min/max/step attributes on an input
    • If step is other than 1 then min and max values will be tweaked to be sure they are divisible by step
  • 4.5.3 - 2023-04-04

    Fixing change events for out-of-range values

  • 4.5.2 - 2023-04-03
  • 4.4.0 - 2023-03-30
  • 4.3.0 - 2020-04-09
from bootstrap-touchspin GitHub release notes
Package name: cldr-data from cldr-data GitHub release notes
Package name: datatables.net-buttons
  • 1.7.1 - 2021-06-04
  • 1.7.0 - 2021-03-09
  • 1.6.5 - 2020-10-09
from datatables.net-buttons GitHub release notes
Package name: datatables.net-buttons-bs4
  • 1.7.1 - 2021-06-04
  • 1.7.0 - 2021-03-09
  • 1.6.5 - 2020-10-09
from datatables.net-buttons-bs4 GitHub release notes
Package name: jquery-migrate
  • 3.5.2 - 2024-07-17

    This release introduces only one change:

    • Make Migrate properly recognized as a CommonJS module in Node.js (#523, #525)

    Note: you may also find jQuery Migrate 3.5.1 on npm. Do not use it, it's a result of a bad release.

  • 3.5.1 - 2024-07-17
  • 3.5.0 - 2024-07-12

    Changes:

    • Manipulation: Deprecate jQuery.UNSAFE_restoreLegacyHtmlPrefilter (#518)
    • Attributes: Fix compatibility with jQuery 4.x (#496,

Snyk has created this PR to upgrade:
  - @fortawesome/fontawesome-free from 5.15.2 to 5.15.4.
    See this package in npm: https://www.npmjs.com/package/@fortawesome/fontawesome-free
  - bootstrap from 4.6.0 to 4.6.2.
    See this package in npm: https://www.npmjs.com/package/bootstrap
  - jquery from 3.6.0 to 3.7.1.
    See this package in npm: https://www.npmjs.com/package/jquery
  - moment from 2.29.4 to 2.30.1.
    See this package in npm: https://www.npmjs.com/package/moment
  - datatables.net from 1.12.1 to 1.13.11.
    See this package in npm: https://www.npmjs.com/package/datatables.net
  - datatables.net-bs4 from 1.12.1 to 1.13.11.
    See this package in npm: https://www.npmjs.com/package/datatables.net-bs4
  - jquery-ui-dist from 1.13.2 to 1.13.3.
    See this package in npm: https://www.npmjs.com/package/jquery-ui-dist
  - jquery-validation from 1.19.5 to 1.21.0.
    See this package in npm: https://www.npmjs.com/package/jquery-validation
  - bootstrap-touchspin from 4.3.0 to 4.7.3.
    See this package in npm: https://www.npmjs.com/package/bootstrap-touchspin
  - cldr-data from 36.0.1 to 36.0.2.
    See this package in npm: https://www.npmjs.com/package/cldr-data
  - datatables.net-buttons from 1.6.5 to 1.7.1.
    See this package in npm: https://www.npmjs.com/package/datatables.net-buttons
  - datatables.net-buttons-bs4 from 1.6.5 to 1.7.1.
    See this package in npm: https://www.npmjs.com/package/datatables.net-buttons-bs4
  - jquery-migrate from 3.4.0 to 3.5.2.
    See this package in npm: https://www.npmjs.com/package/jquery-migrate
  - jsrender from 1.0.11 to 1.0.15.
    See this package in npm: https://www.npmjs.com/package/jsrender
  - magnific-popup from 1.1.0 to 1.2.0.
    See this package in npm: https://www.npmjs.com/package/magnific-popup
  - swiper from 8.3.2 to 8.4.7.
    See this package in npm: https://www.npmjs.com/package/swiper
  - tinymce from 5.10.7 to 5.10.9.
    See this package in npm: https://www.npmjs.com/package/tinymce

See this project in Snyk:
https://app.snyk.io/org/batchusivaji/project/81d396d3-6007-4ea9-80a9-16232b61295b?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Bootstrap 4 classes form-control-sm and form-control-lg not supported
2 participants
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy