[Snyk] Fix for 1 vulnerabilities
Created by: GTVolk
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
|
980/1000 Why? Currently trending on Twitter, Mature exploit, Recently disclosed, Has a fix available, CVSS 9.6 |
Heap-based Buffer Overflow SNYK-JS-SHARP-5922108 |
Yes | Mature |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: gatsby-plugin-manifest
The new version differs by 250 commits.- ceb5527 chore(release): Publish
- 5bd48a5 chore(docs): update algolia guide (#38085)
- 89a3232 chore(gatsby-source-contentful): Fix docs pageLimit default value (#38082)
- 7501d18 chore(docs): Typo in v4 to v5 migration guide (#38081)
- cbc0b35 feat(create-gatsby): Add Tailwind as a styling choice (#37944)
- 768581f chore(changelogs): update changelogs (#38077)
- 9284520 fix(deps): update starters and examples gatsby packages to ^5.9.1 (#38073)
- 22394b9 fix(deps): update e2e tests (major) (#38071)
- 9bb9037 chore(deps): update starters and examples (#38067)
- ed5855e fix(gatsby): don't serve codeframes for files outside of compilation (#38059)
- 4cd23bf chore(release): Publish next
- dfdeed4 fix(gatsby-source-drupal): add image cdn support for `files` type and `typePrefix` (#38057)
- e5e2bb7 fix(gatsby-source-drupal): find mimetype field (#38056)
- 38fae7a chore(docs): Improve wording in main tutorial part 6 (#38054)
- a9c54f7 chore(release): Publish next
- d611439 fix(deps): update minor and patch dependencies for gatsby-source-graphql (#38028)
- 213d8b0 fix(deps): update minor and patch dependencies for gatsby-plugin-mdx (#38027)
- 272dacd fix(gatsby): handle cyclic chunkgroup children (#38052)
- a83ed19 fix(deps): update minor and patch dependencies for gatsby (#38005)
- d7cccfe fix(deps): update dependency sharp to ^0.32.1 (#38024)
- 2d2b7c2 chore: Fix dirty lock file
- 1a4b234 chore(deps): update dependency @ jridgewell/trace-mapping to ^0.3.18 for gatsby-legacy-polyfills (#37996)
- ccecd9d chore(deps): update dependency rimraf to v5 for gatsby-page-utils (#38039)
- 94099a9 chore(deps): update dependency rimraf to v5 for gatsby-plugin-utils (#38040)
Package name: gatsby-plugin-sharp
The new version differs by 250 commits.- ceb5527 chore(release): Publish
- 5bd48a5 chore(docs): update algolia guide (#38085)
- 89a3232 chore(gatsby-source-contentful): Fix docs pageLimit default value (#38082)
- 7501d18 chore(docs): Typo in v4 to v5 migration guide (#38081)
- cbc0b35 feat(create-gatsby): Add Tailwind as a styling choice (#37944)
- 768581f chore(changelogs): update changelogs (#38077)
- 9284520 fix(deps): update starters and examples gatsby packages to ^5.9.1 (#38073)
- 22394b9 fix(deps): update e2e tests (major) (#38071)
- 9bb9037 chore(deps): update starters and examples (#38067)
- ed5855e fix(gatsby): don't serve codeframes for files outside of compilation (#38059)
- 4cd23bf chore(release): Publish next
- dfdeed4 fix(gatsby-source-drupal): add image cdn support for `files` type and `typePrefix` (#38057)
- e5e2bb7 fix(gatsby-source-drupal): find mimetype field (#38056)
- 38fae7a chore(docs): Improve wording in main tutorial part 6 (#38054)
- a9c54f7 chore(release): Publish next
- d611439 fix(deps): update minor and patch dependencies for gatsby-source-graphql (#38028)
- 213d8b0 fix(deps): update minor and patch dependencies for gatsby-plugin-mdx (#38027)
- 272dacd fix(gatsby): handle cyclic chunkgroup children (#38052)
- a83ed19 fix(deps): update minor and patch dependencies for gatsby (#38005)
- d7cccfe fix(deps): update dependency sharp to ^0.32.1 (#38024)
- 2d2b7c2 chore: Fix dirty lock file
- 1a4b234 chore(deps): update dependency @ jridgewell/trace-mapping to ^0.3.18 for gatsby-legacy-polyfills (#37996)
- ccecd9d chore(deps): update dependency rimraf to v5 for gatsby-page-utils (#38039)
- 94099a9 chore(deps): update dependency rimraf to v5 for gatsby-plugin-utils (#38040)
Package name: gatsby-transformer-sharp
The new version differs by 250 commits.- ceb5527 chore(release): Publish
- 5bd48a5 chore(docs): update algolia guide (#38085)
- 89a3232 chore(gatsby-source-contentful): Fix docs pageLimit default value (#38082)
- 7501d18 chore(docs): Typo in v4 to v5 migration guide (#38081)
- cbc0b35 feat(create-gatsby): Add Tailwind as a styling choice (#37944)
- 768581f chore(changelogs): update changelogs (#38077)
- 9284520 fix(deps): update starters and examples gatsby packages to ^5.9.1 (#38073)
- 22394b9 fix(deps): update e2e tests (major) (#38071)
- 9bb9037 chore(deps): update starters and examples (#38067)
- ed5855e fix(gatsby): don't serve codeframes for files outside of compilation (#38059)
- 4cd23bf chore(release): Publish next
- dfdeed4 fix(gatsby-source-drupal): add image cdn support for `files` type and `typePrefix` (#38057)
- e5e2bb7 fix(gatsby-source-drupal): find mimetype field (#38056)
- 38fae7a chore(docs): Improve wording in main tutorial part 6 (#38054)
- a9c54f7 chore(release): Publish next
- d611439 fix(deps): update minor and patch dependencies for gatsby-source-graphql (#38028)
- 213d8b0 fix(deps): update minor and patch dependencies for gatsby-plugin-mdx (#38027)
- 272dacd fix(gatsby): handle cyclic chunkgroup children (#38052)
- a83ed19 fix(deps): update minor and patch dependencies for gatsby (#38005)
- d7cccfe fix(deps): update dependency sharp to ^0.32.1 (#38024)
- 2d2b7c2 chore: Fix dirty lock file
- 1a4b234 chore(deps): update dependency @ jridgewell/trace-mapping to ^0.3.18 for gatsby-legacy-polyfills (#37996)
- ccecd9d chore(deps): update dependency rimraf to v5 for gatsby-page-utils (#38039)
- 94099a9 chore(deps): update dependency rimraf to v5 for gatsby-plugin-utils (#38040)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
Learn how to fix vulnerabilities with free interactive lessons: