Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade vue from 2.5.16 to 2.6.12 #3

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented Jun 8, 2021

Snyk has created this PR to upgrade vue from 2.5.16 to 2.6.12.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 24 versions ahead of your current version.
  • The recommended version was released 10 months ago, on 2020-08-20.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Cross-site Scripting (XSS)
npm:vue:20180802
646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: vue from vue GitHub release notes
Commit messages
Package name: vue
  • bb253db build: release 2.6.12
  • 60a71ea build: build 2.6.12
  • 5b39961 fix(security): upgrade serialize-javascript (#11434)
  • 46ae952 chore: update sponsors [ci skip] (#11570)
  • d9a41d2 build(deps): bump elliptic from 6.4.1 to 6.5.3 (#11554)
  • 6c1f387 chore: update sponsors [ci skip]
  • 4611a44 chore: update backers [ci skip] (#11566)
  • 38cfb2b chore: update sponsors [ci skip] (#11542)
  • 8ead9d2 chore: spelling and grammar (#11481)
  • 98b4d68 chore: update sponsors [ci skip] (#11435)
  • 319294d chore: update sponsors [ci skip] (#11433)
  • d25a455 chore: update sponsors [ci skip] (#11420)
  • fb589e6 chore: improve note about DefinePlugin (#11425)
  • 0baa129 chore: update sponsors [ci skip] (#11365)
  • e1fbfac chore: add issue template config.yml (#10777) [ci skip]
  • 0551226 chore: update sponsors [ci skip] (#11280)
  • 0aa4077 chore: update backers [ci skip] (#11279)
  • 2be3b10 chore: typo unnecesarry -> unnecessary (#11286)
  • 5396342 chore: https link to editorconfig.org (#11267)
  • e68f83d chore: fix typo in `bind-dynamic-keys.js` comment (#11262)
  • a59e05c chore(readme): svg images (#11200)
  • 98b9270 chore: fix svg logos
  • caa33e0 chore: update sponsors [ci skip] (#11196)
  • 01852a7 chore: update sponsors [ci skip] (#11180)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant