Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: @fortawesome/fontawesome-svg-core, @fortawesome/free-brands-svg-icons, @fortawesome/free-solid-svg-icons, @fortawesome/react-fontawesome #97

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

apwalden
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on
@fortawesome/fontawesome-svg-core
from 1.2.19 to 1.2.36
32 versions ahead of your current version a year ago
on 2021-08-04
@fortawesome/free-brands-svg-icons
from 5.9.0 to 5.15.4
32 versions ahead of your current version a year ago
on 2021-08-04
@fortawesome/free-solid-svg-icons
from 5.9.0 to 5.15.4
32 versions ahead of your current version a year ago
on 2021-08-04
@fortawesome/react-fontawesome
from 0.1.4 to 0.2.0
16 versions ahead of your current version 4 months ago
on 2022-06-29

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-URIJS-1319806
365/1000
Why? CVSS 7.3
No Known Exploit
Cross-site Scripting (XSS)
SNYK-JS-URIJS-2441239
365/1000
Why? CVSS 7.3
Proof of Concept
Misinterpretation of Input
SNYK-JS-URIJS-2440699
365/1000
Why? CVSS 7.3
Proof of Concept
Open Redirect
SNYK-JS-URIJS-2419067
365/1000
Why? CVSS 7.3
Proof of Concept
Improper Input Validation
SNYK-JS-URIJS-2415026
365/1000
Why? CVSS 7.3
Proof of Concept
Open Redirect
SNYK-JS-URIJS-2401466
365/1000
Why? CVSS 7.3
Proof of Concept
Open Redirect
SNYK-JS-URIJS-1319803
365/1000
Why? CVSS 7.3
Proof of Concept
Improper Input Validation
SNYK-JS-URIJS-1078286
365/1000
Why? CVSS 7.3
No Known Exploit
Improper Input Validation
SNYK-JS-URIJS-1055003
365/1000
Why? CVSS 7.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @fortawesome/fontawesome-svg-core
  • 1.2.36 - 2021-08-04
  • 1.2.35 - 2021-03-16
  • 1.2.34 - 2021-01-13
  • 1.2.32 - 2020-10-05
  • 1.2.31 - 2020-09-29
  • 1.2.30 - 2020-07-15
  • 1.2.29 - 2020-06-18
  • 1.2.28 - 2020-03-23
  • 1.2.27 - 2020-02-05
  • 1.2.26 - 2019-12-10
  • 1.2.26-2 - 2019-12-10
  • 1.2.26-1 - 2019-11-06
  • 1.2.25 - 2019-09-23
  • 1.2.24 - 2019-09-18
  • 1.2.23 - 2019-09-18
  • 1.2.22 - 2019-08-22
  • 1.2.21 - 2019-08-02
  • 1.2.20 - 2019-07-29
  • 1.2.20-14 - 2019-07-25
  • 1.2.20-13 - 2019-07-25
  • 1.2.20-12 - 2019-07-23
  • 1.2.20-11 - 2019-06-25
  • 1.2.20-10 - 2019-06-24
  • 1.2.20-9 - 2019-06-24
  • 1.2.20-8 - 2019-06-21
  • 1.2.20-7 - 2019-06-20
  • 1.2.20-6 - 2019-06-19
  • 1.2.20-5 - 2019-06-17
  • 1.2.20-4 - 2019-06-14
  • 1.2.20-3 - 2019-06-12
  • 1.2.20-2 - 2019-05-29
  • 1.2.20-1 - 2019-05-28
  • 1.2.19 - 2019-06-04
from @fortawesome/fontawesome-svg-core GitHub release notes
Package name: @fortawesome/free-brands-svg-icons
  • 5.15.4 - 2021-08-04

    Changed

    • Removed the tripadvisor brand icon by request of Tripadvisor
    • Update bug, bullseye, drone, icons #17800 #17106 #17730
    • Update bootstrap, discord, figma, and font-awesome-* brand icons #17436

    Fixed

    • Made font-family matching case-insensitive for SVG + JavaScript version of Font Awesome #17860
    • Corrected missing version hospital-user #17435
    • Removed useless .tgz file in @ fortawesome/fontawesome-pro and all @ fortawesome/pro-*-svg-icons
  • 5.15.3 - 2021-03-16

    Changed

    • Updated air-freshener's design due to trademark violation notice
  • 5.15.2 - 2021-01-13

    Changed

    • Support release to improve Font Awesome Kits performance
  • 5.15.1 - 2020-10-05

    Changed

    • Update to the ravelry brand icon

    Fixed

    • Removed fill attribute from the vest and vest-patches icon
    • Moved attribution comment to correct location for sprites
    • Fixed duotone icons not rendering in Kits
  • 5.15.0 - 2020-09-29

    Minor version upgrade notice: there are some backward-incompatible changes to this release. See the
    UPGRADING.md guide for more
    information.

    Added

    • Added guilded, hive, innosoft, instalod, ns8, octopus-deploy, perbyte,
      uncharted, watchman-monitoring, wodu sponsored brand icons
    • Added commissioned vest and vest-patch icon
    • Added cloudflare brand icon

    Changed

    • Removed the adobe icon at the request of Adobe
    • Update rocketchat brand icon

    Fixed

    • Conflict detection now includes Kits when checking for conflicts
  • 5.14.0 - 2020-07-15
  • 5.13.1 - 2020-06-18
  • 5.13.0 - 2020-03-23
  • 5.12.1 - 2020-02-05
  • 5.12.0 - 2019-12-10
  • 5.12.0-2 - 2019-12-10
  • 5.12.0-1 - 2019-11-06
  • 5.11.2 - 2019-09-23
  • 5.11.1 - 2019-09-18
  • 5.11.0 - 2019-09-18
  • 5.10.2 - 2019-08-22
  • 5.10.1 - 2019-08-02
  • 5.10.0 - 2019-07-29
  • 5.10.0-14 - 2019-07-25
  • 5.10.0-13 - 2019-07-25
  • 5.10.0-12 - 2019-07-23
  • 5.10.0-11 - 2019-06-25
  • 5.10.0-10 - 2019-06-24
  • 5.10.0-9 - 2019-06-24
  • 5.10.0-8 - 2019-06-21
  • 5.10.0-7 - 2019-06-20
  • 5.10.0-6 - 2019-06-19
  • 5.10.0-5 - 2019-06-17
  • 5.10.0-4 - 2019-06-14
  • 5.10.0-3 - 2019-06-12
  • 5.10.0-2 - 2019-05-29
  • 5.10.0-1 - 2019-05-28
  • 5.9.0 - 2019-06-04
from @fortawesome/free-brands-svg-icons GitHub release notes
Package name: @fortawesome/free-solid-svg-icons
  • 5.15.4 - 2021-08-04

    Changed

    • Removed the tripadvisor brand icon by request of Tripadvisor
    • Update bug, bullseye, drone, icons #17800 #17106 #17730
    • Update bootstrap, discord, figma, and font-awesome-* brand icons #17436

    Fixed

    • Made font-family matching case-insensitive for SVG + JavaScript version of Font Awesome #17860
    • Corrected missing version hospital-user #17435
    • Removed useless .tgz file in @ fortawesome/fontawesome-pro and all @ fortawesome/pro-*-svg-icons
  • 5.15.3 - 2021-03-16

    Changed

    • Updated air-freshener's design due to trademark violation notice
  • 5.15.2 - 2021-01-13

    Changed

    • Support release to improve Font Awesome Kits performance
  • 5.15.1 - 2020-10-05

    Changed

    • Update to the ravelry brand icon

    Fixed

    • Removed fill attribute from the vest and vest-patches icon
    • Moved attribution comment to correct location for sprites
    • Fixed duotone icons not rendering in Kits
  • 5.15.0 - 2020-09-29

    Minor version upgrade notice: there are some backward-incompatible changes to this release. See the
    UPGRADING.md guide for more
    information.

    Added

    • Added guilded, hive, innosoft, instalod, ns8, octopus-deploy, perbyte,
      uncharted, watchman-monitoring, wodu sponsored brand icons
    • Added commissioned vest and vest-patch icon
    • Added cloudflare brand icon

    Changed

    • Removed the adobe icon at the request of Adobe
    • Update rocketchat brand icon

    Fixed

    • Conflict detection now includes Kits when checking for conflicts
  • 5.14.0 - 2020-07-15
  • 5.13.1 - 2020-06-18
  • 5.13.0 - 2020-03-23
  • 5.12.1 - 2020-02-05
  • 5.12.0 - 2019-12-10
  • 5.12.0-2 - 2019-12-10
  • 5.12.0-1 - 2019-11-06
  • 5.11.2 - 2019-09-23
  • 5.11.1 - 2019-09-18
  • 5.11.0 - 2019-09-18
  • 5.10.2 - 2019-08-22
  • 5.10.1 - 2019-08-02
  • 5.10.0 - 2019-07-29
  • 5.10.0-14 - 2019-07-25
  • 5.10.0-13 - 2019-07-25
  • 5.10.0-12 - 2019-07-23
  • 5.10.0-11 - 2019-06-25
  • 5.10.0-10 - 2019-06-24
  • 5.10.0-9 - 2019-06-24
  • 5.10.0-8 - 2019-06-21
  • 5.10.0-7 - 2019-06-20
  • 5.10.0-6 - 2019-06-19
  • 5.10.0-5 - 2019-06-17
  • 5.10.0-4 - 2019-06-14
  • 5.10.0-3 - 2019-06-12
  • 5.10.0-2 - 2019-05-29
  • 5.10.0-1 - 2019-05-28
  • 5.9.0 - 2019-06-04
from @fortawesome/free-solid-svg-icons GitHub release notes
Package name: @fortawesome/react-fontawesome
  • 0.2.0 - 2022-06-29

    Added

    • Support for React forwardRef if using React >= 16.3
  • 0.1.19 - 2022-06-29

    Fixed

    • Added missing beatFade, spinPulse, and spinReverse animations
  • 0.1.18 - 2022-03-16

    Added

    • Animations bounce, shake, fade, and beat-fade
    • Property maskId and titleId to allow consistent rendering on client and server

    Changed

    • Peer dependencies now include major version 6
  • 0.1.17 - 2022-01-28

    Added

    • New v6 sizes and animations
  • 0.1.16 - 2021-10-18

    Fixed

    • Include 1.3.0-beta versions in peer dependencies
  • 0.1.15 - 2021-08-03

    Fixed

    • Skip parse.icon if the icon is imported directly from an icon package
  • 0.1.14 - 2020-12-22

    Added

    • Support for the new parse.icon function from the Font Awesome version 6 @ fortawesome/fontawesome-svg-core
  • 0.1.13 - 2020-11-23

    Fixed

    • Update forwardRef Typescript definition #396
  • 0.1.12 - 2020-10-26
  • 0.1.11 - 2020-06-16

    Fixed

    • Accept rotation value of 0 #344
  • 0.1.10 - 2020-06-02

    Added

    • Support for forward ref #341
  • 0.1.9 - 2020-03-05
  • 0.1.8 - 2019-12-06
  • 0.1.7 - 2019-10-19
  • 0.1.6 - 2019-10-10
  • 0.1.5 - 2019-09-29
  • 0.1.4 - 2019-01-15
from @fortawesome/react-fontawesome GitHub release notes
Commit messages
Package name: @fortawesome/react-fontawesome
  • f3585b7 Adjust CI to include FA deps in matrix
  • 295baab Removing React 16.2 as it's no longer supported
  • de58148 Update tag for release
  • e32a0cb Use forwardRef rather than custom `forwardedRef` prop (#503)
  • 6e1663b Fix a few missing animations (#516)
  • c28e82b Deps updates
  • c86b4e6 Deps updates from npm audit
  • fd719e8 Bump async from 2.6.3 to 2.6.4 in /examples/create-react-app (#507)
  • 11e4cea Bump minimist in /examples/create-react-app-typescript (#513)
  • f3005cd Bump async from 2.6.3 to 2.6.4 in /examples/create-react-app-typescript (#514)
  • 872d0b0 Don't skip the majority of tests (#502)
  • 77e6da9 Release 0.0.18
  • fddf603 Allow 6 in peer deps
  • 8d6680d Removing `.only` on a test
  • 9f83d49 Adding maskId (#491)
  • ac63cd4 Adding titleId (#489)
  • 797dd75 Fixing duplicate props after merging two PRs (#488)
  • 77b9bde Fix fade prop and support beat-fade, bounce and shake props (#483) (#484)
  • 6b6af65 Add bounce and shake along with tests (#469)
  • 83a50e0 V6 Readme update (#461)
  • a038faf Release 0.1.17
  • 5b286b3 New v6 sizes and animations (#466)
  • c28de56 Removed second entry of Brian Talbot (#468)
  • 174bd60 Release 0.1.16

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Snyk has created this PR to upgrade:
  - @fortawesome/fontawesome-svg-core from 1.2.19 to 1.2.36.
    See this package in npm: https://www.npmjs.com/package/@fortawesome/fontawesome-svg-core
  - @fortawesome/free-brands-svg-icons from 5.9.0 to 5.15.4.
    See this package in npm: https://www.npmjs.com/package/@fortawesome/free-brands-svg-icons
  - @fortawesome/free-solid-svg-icons from 5.9.0 to 5.15.4.
    See this package in npm: https://www.npmjs.com/package/@fortawesome/free-solid-svg-icons
  - @fortawesome/react-fontawesome from 0.1.4 to 0.2.0.
    See this package in npm: https://www.npmjs.com/package/@fortawesome/react-fontawesome

See this project in Snyk:
https://app.snyk.io/org/apwalden/project/493dd612-d680-4cd8-817e-6a0b65e9f61d?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants