[Snyk] Fix for 2 vulnerabilities - #13251
Conversation
…ties The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-SHARP-19653587 - https://snyk.io/vuln/SNYK-JS-OPENTELEMETRYCORE-17373280
|
This release includes a high-risk major version upgrade for @c15t/react from 1.8.5 to 2.0.0 (High Risk) This is a major version upgrade with significant breaking changes requiring a manual migration. The update introduces a completely new styling system, a rewritten backend, and numerous API changes. Key Breaking Changes:
Recommendation: A migration is required. The maintainers have provided a CLI tool ( sharp from 0.34.5 to 0.35.4 (Medium Risk) This upgrade crosses a minor version boundary (0.34.x to 0.35.x) and introduces breaking changes, primarily related to the environment and installation process. Key Changes:
Recommendation: Verify that your environment meets the new Node.js version requirement. Review your build and deployment processes to ensure they are compatible with the removal of the installation script. Check your codebase for any usage of the removed or renamed APIs.
|
Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
docs/package.jsondocs/package-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-SHARP-19653587
SNYK-JS-OPENTELEMETRYCORE-17373280
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling
🦉 Heap-based Buffer Overflow