Skip to content

[Snyk] Upgrade style-loader from 0.21.0 to 0.23.1#4

Open
snyk-bot wants to merge 1 commit into
mainfrom
snyk-upgrade-bbd552aeb0c1de13a4a08365117e0f9b
Open

[Snyk] Upgrade style-loader from 0.21.0 to 0.23.1#4
snyk-bot wants to merge 1 commit into
mainfrom
snyk-upgrade-bbd552aeb0c1de13a4a08365117e0f9b

Conversation

@snyk-bot

@snyk-bot snyk-bot commented Aug 7, 2021

Copy link
Copy Markdown

Snyk has created this PR to upgrade style-loader from 0.21.0 to 0.23.1.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 4 versions ahead of your current version.
  • The recommended version was released 3 years ago, on 2018-10-08.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Remote Memory Exposure
SNYK-JS-DNSPACKET-1293563
385/1000
Why? CVSS 7.7
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
385/1000
Why? CVSS 7.7
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
385/1000
Why? CVSS 7.7
No Known Exploit
Open Redirect
SNYK-JS-URLPARSE-1533425
385/1000
Why? CVSS 7.7
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
385/1000
Why? CVSS 7.7
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: style-loader from style-loader GitHub release notes
Commit messages
Package name: style-loader
  • 8003966 chore(release): 0.23.1
  • 9561368 docs(readme): fix malformed symbols
  • 33aebed fix(addStyles): support exports of transpiled transforms (`options.transform`) (#333)
  • e821fe8 Update README.md (#345)
  • 84fe908 chore(package): update `schema-utils` v0.4.5...1.0.0 (`dependencies`) (#342)
  • da83a28 chore(release): 0.23.0
  • 2588aca feat(useable): add `insertInto` support (`options.insertInto`) (#341)
  • 4217bd1 chore(release): 0.22.1
  • 1ca12ab fix(addStyles): use `var` instead of `const` (IE fix) (#338)
  • e973fe2 chore(release): 0.22.0
  • 001159d docs(readme): clarify `useable` usage (#314)
  • fc24512 feat: add support for __webpack_nonce__ (#319)
  • c7d8fec fix: insertInto and insertAt collaboration (#325)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant