Skip to content

Conversation

@snyk-bot
Copy link

@snyk-bot snyk-bot commented May 1, 2020

Snyk has created this PR to upgrade vuepress from 1.0.2 to 1.4.0.

merge advice

✨What is Merge Advice? We check thousands of dependency upgrade pull requests and CI tests every day to see which upgrades were successfully merged. After crunching this data, we give a recommendation on how safe we think the change is for you to merge without causing issues. Learn more, and share your feedback to help improve this feature. 🙏
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 7 versions ahead of your current version.
  • The recommended version was released a month ago, on 2020-03-18.

The recommended version fixes:

Severity Issue Exploit Maturity
Cross-site Scripting (XSS)
SNYK-JS-SERIALIZEJAVASCRIPT-536840
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ACORN-559469
No Known Exploit
Prototype Pollution
SNYK-JS-MINIMIST-559764
Proof of Concept
Prototype Pollution
SNYK-JS-MINIMIST-559764
Proof of Concept
Timing Attack
SNYK-JS-ELLIPTIC-511941
No Known Exploit
Prototype Pollution
SNYK-JS-DOTPROP-543489
Proof of Concept
Information Exposure
SNYK-JS-KINDOF-537849
Proof of Concept
Release notes
Package name: vuepress from vuepress GitHub release notes
Commit messages
Package name: vuepress
  • 58ed07f v1.4.0
  • 604052b fix($plugin-pwa): work with register-service-worker 1.7.0 (close #2222) (#2229)
  • f7a78b4 docs: update guide for project bootstrap
  • 3551e69 docs($theme-default): remove nested sidebar groups warning
  • c3a943c fix($theme-default): remove error logs for nested sidebar groups (#2191)
  • 27275ee docs($zh): fix sass-loader link (#2219)
  • 76da780 feat($core): Improve VuePress build time (#2163)
  • 0aadf05 fix: fail to test specific package (#2099)
  • e9fde5c feat($plugin-search): improve the native search algorithm (#1557)
  • 4c6fbcc docs: refine cli documentation (#2151)
  • 3abe265 docs: update CONTRIBUTING and README (#2052)
  • 369c315 feat($plugin-last-updated): add dateOptions to options (#2192)
  • a9759c0 fix: opencollective postinstall failure not being ignored on Windows(#2177)
  • 8d9968d fix($shared-utils): Slugify em/en dash in urls (#2174)
  • de64e81 chore: 1.3.1 changelog
  • eef0d2f v1.3.1
  • c9e59af docs: fix broken link to deploy with ZEIT Now (#2185)
  • 0ca620f fix($core): transpile vuepress packages and md files (close #1606, #1990) (#2064)
  • 560b3c6 fix($plugin-pwa): popup component does not work (close #2172) (#2187)
  • 606ae4a docs: remove filip from core team for now (#2170)
  • ca3679c fix($theme-default): non-ASCII hash causes wrong sidebar highlight (close #2078)(#2166)
  • 0ae73cb build($core): bump babel and core-js version (close #2046) (#2165)
  • ffd45c2 refactor($core): use stylus conditional assignment (close #2127) (#2129)
  • 8b43598 build: bump cac from 6.5.5 to 6.5.6 (#2157)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment