This repository was archived by the owner on May 5, 2025. It is now read-only.
[Snyk] Upgrade: , vue, , , postcss, , autoprefixer, axios, bootstrap, bootstrap-icons-vue, css-loader, dashjs, icecast-metadata-player, laravel-echo, moment, patch-package, sass, sass-loader, socket.io-client, vue-router, vue-tsc #181
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.



Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@babel/core
from 7.22.6 to 7.25.2 | 27 versions ahead of your current version | 2 months ago
on 2024-07-30
vue
from 3.4.35 to 3.4.38 | 3 versions ahead of your current version | a month ago
on 2024-08-15
@apollo/client
from 3.11.2 to 3.11.5 | 3 versions ahead of your current version | a month ago
on 2024-08-28
@vue/apollo-composable
from 4.0.2 to 4.2.1 | 3 versions ahead of your current version | a month ago
on 2024-08-23
postcss
from 8.4.41 to 8.4.44 | 3 versions ahead of your current version | 21 days ago
on 2024-09-02
@vue/compiler-sfc
from 3.4.35 to 3.4.38 | 3 versions ahead of your current version | a month ago
on 2024-08-15
autoprefixer
from 10.4.14 to 10.4.20 | 6 versions ahead of your current version | 2 months ago
on 2024-08-02
axios
from 1.7.4 to 1.7.7 | 3 versions ahead of your current version | 22 days ago
on 2024-08-31
bootstrap
from 5.3.2 to 5.3.3 | 1 version ahead of your current version | 7 months ago
on 2024-02-20
bootstrap-icons-vue
from 1.11.1 to 1.11.3 | 1 version ahead of your current version | 8 months ago
on 2024-01-26
css-loader
from 6.8.1 to 6.11.0 | 4 versions ahead of your current version | 6 months ago
on 2024-04-03
dashjs
from 4.7.2 to 4.7.4 | 2 versions ahead of your current version | 7 months ago
on 2024-02-20
icecast-metadata-player
from 1.17.1 to 1.17.3 | 2 versions ahead of your current version | 4 months ago
on 2024-05-13
laravel-echo
from 1.15.3 to 1.16.1 | 2 versions ahead of your current version | 5 months ago
on 2024-04-09
moment
from 2.29.4 to 2.30.1 | 2 versions ahead of your current version | 9 months ago
on 2023-12-27
patch-package
from 7.0.1 to 7.0.2 | 1 version ahead of your current version | a year ago
on 2023-07-12
sass
from 1.63.3 to 1.77.8 | 36 versions ahead of your current version | 2 months ago
on 2024-07-11
sass-loader
from 13.3.2 to 13.3.3 | 1 version ahead of your current version | 9 months ago
on 2023-12-25
socket.io-client
from 4.7.2 to 4.7.5 | 3 versions ahead of your current version | 6 months ago
on 2024-03-14
vue-router
from 4.4.2 to 4.4.3 | 1 version ahead of your current version | 2 months ago
on 2024-08-06
vue-tsc
from 2.0.29 to 2.1.4 | 3 versions ahead of your current version | 23 days ago
on 2024-08-31
Issues fixed by the recommended upgrade:
SNYK-JS-MICROMATCH-6838728
SNYK-JS-VITE-8023174
SNYK-JS-VITE-8022916
Release notes
Package name: @babel/core
-
7.25.2 - 2024-07-30
- #16695 Ensure that
- Huáng Jùnliàng (@ JLHwung)
- Nicolò Ribaudo (@ nicolo-ribaudo)
-
7.24.9 - 2024-07-15
- #16639 Avoid
- #16638 fix: provide legacy typings for TS < 4.1 (@ JLHwung)
- #16617 Avoid extra parens in TS
- #16629 Lazy top-level initializations for module transforms (@ guybedford)
- Babel Bot (@ babel-bot)
- Guy Bedford (@ guybedford)
- Huáng Jùnliàng (@ JLHwung)
- Nicolò Ribaudo (@ nicolo-ribaudo)
- @ liuxingbaoyu
-
7.24.8 - 2024-07-11
-
7.24.7 - 2024-06-05
-
7.24.6 - 2024-05-24
-
7.24.5 - 2024-04-29
-
7.24.4 - 2024-04-03
-
7.24.3 - 2024-03-20
-
7.24.1 - 2024-03-19
-
7.24.0 - 2024-02-28
-
7.23.9 - 2024-01-25
-
7.23.7 - 2023-12-29
-
7.23.6 - 2023-12-11
-
7.23.5 - 2023-11-29
-
7.23.3 - 2023-11-09
-
7.23.2 - 2023-10-12
-
7.23.0 - 2023-09-25
-
7.22.20 - 2023-09-16
-
7.22.19 - 2023-09-14
-
7.22.18 - 2023-09-14
-
7.22.17 - 2023-09-08
-
7.22.15 - 2023-09-04
-
7.22.11 - 2023-08-24
-
7.22.10 - 2023-08-07
-
7.22.9 - 2023-07-12
-
7.22.8 - 2023-07-06
-
7.22.7 - 2023-07-06
-
7.22.6 - 2023-07-04
from @babel/core GitHub release notesv7.25.2 (2024-07-30)
🐛 Bug Fix
babel-core,babel-traverserequeueComputedKeyAndDecoratorsis available (@ nicolo-ribaudo)Committers: 2
v7.24.9 (2024-07-15)
🐛 Bug Fix
babel-core,babel-standalonerequire()call in@ babel/standalonebundle (@ nicolo-ribaudo)babel-types💅 Polish
babel-generator,babel-plugin-transform-optional-chainingas/satisfies(@ nicolo-ribaudo)🏠 Internal
babel-helper-module-transformsCommitters: 5
Package name: vue
-
3.4.38 - 2024-08-15
-
3.4.37 - 2024-08-08
-
3.4.36 - 2024-08-06
-
3.4.35 - 2024-07-31
from vue GitHub release notesFor stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.Package name: @apollo/client
-
3.11.5 - 2024-08-28
-
-
-
3.11.4 - 2024-08-07
-
-
-
-
3.11.3 - 2024-08-05
-
-
-
-
-
3.11.2 - 2024-07-31
- #11980
from @apollo/client GitHub release notesPatch Changes
#12027
eb3e21bThanks @ JavaScriptBach! - TypeMutationResult.resetas an arrow function#12020
82d8cb4Thanks @ jerelmiller! - Better conform to Rules of React by avoiding write of ref in render foruseFragment.Patch Changes
#11994
41b17e5Thanks @ jerelmiller! - Update theModifierfunction type to allowcache.modifyto return deeply partial data.#11989
e609156Thanks @ phryneas! - Fix a potential crash when callingclearStorewhile a query was running.Previously, calling
client.clearStore()while a query was running had one of these results:useQuerywould stay in aloading: truestate.useLazyQuerywould stay in aloading: truestate, but also crash with a"Cannot read property 'data' of undefined"error.Now, in both cases, the hook will enter an error state with a
networkError, and the promise returned by theuseLazyQueryexecutefunction will return a result in an error state.#11994
41b17e5Thanks @ jerelmiller! - Prevent accidental distribution oncache.modifyfield modifiers when a field is a union type array.Patch Changes
#11984
5db1659Thanks @ jerelmiller! - Fix an issue where multiple fetches with results that returned errors would sometimes set thedataproperty with anerrorPolicyofnone.#11974
c95848eThanks @ jerelmiller! - Fix an issue wherefetchMorewould write its result data to the cache when using it with ano-cachefetch policy.#11974
c95848eThanks @ jerelmiller! - Fix an issue where executingfetchMorewith ano-cachefetch policy could sometimes result in multiple network requests.#11974
c95848eThanks @ jerelmiller! -Potentially disruptive change
When calling
fetchMorewith a query that has ano-cachefetch policy,fetchMorewill now throw if anupdateQueryfunction is not provided. This provides a mechanism to merge the results from thefetchMorecall with the query's previous result.Patch Changes
38c0a2cThanks @ jerelmiller! - Fix missinggetServerSnapshoterror when usinguseSubscriptionon the server.Package name: @vue/apollo-composable
-
4.2.1 - 2024-08-23
- Improved pinia support (#1571)
- Update broken circleci badge (9622392)
- Readme smaller logo (ff836ea)
- Use nightly.akryum.dev (7f3cf7d)
- Specify pnpm version in package.json (732e66e)
- Nick Messing (@ nickmessing)
- Guillaume Chau (@ Akryum)
-
4.2.0 - 2024-08-19
- Add updateQuery to useQuery (#1552)
- UseMutations onDone Event hook gets triggered too early (#1559)
- (@ vue/apollo-option) memory leak in wrapped ssrRender (#1553)
- Reuse previous result, fix #1483 (#1569, #1483)
- ResolveClient throwing too soon, fix #1557 (#1570, #1557)
- Add github link to documentation (#1549)
- Note about continuous releases (51e09e7)
- Switch some tests to script setup (c8e5106)
- Nightly releases (319f6ec)
- Guillaume Chau (@ Akryum)
- Matt Garrett [email protected]
- Mobsean (@ mobsean)
- Leonardo Santos (@ syllomex)
- Alex Liu (@ Mini-ghost)
-
4.1.0 - 2024-08-14
- Change teardown to use onScopeDispose (#1545)
- useQuery: Document refetch with new variables (#1564)
- Updqte pnpm to v9 (827ea6e)
- UseSubscription (0f5ae61)
- Fix subscription test (#1547)
- Update versions (fe66840)
- Guillaume Chau (@ Akryum)
- Nick Messing (@ nickmessing)
-
4.0.2 - 2024-03-08
- Use shallowRef on result & error (08f0fcd)
- Remove mentions of fetchResults, fix #1060 (#1060)
- Guillaume Chau (@ Akryum)
from @vue/apollo-composable GitHub release notes🩹 Fixes
📖 Documentation
🏡 Chore
❤️ Contributors
🚀 Enhancements
🩹 Fixes
📖 Documentation
🏡 Chore
🤖 CI
❤️ Contributors
🩹 Fixes
📖 Documentation
🏡 Chore
✅ Tests
🤖 CI
❤️ Contributors
🩹 Fixes
📖 Documentation
❤️ Contributors
Package name: postcss
-
8.4.44 - 2024-09-02
- Another way to fix
-
8.4.43 - 2024-09-01
- Fixed
-
8.4.42 - 2024-08-31
- Fixed CSS syntax error on long minified files (by @ varpstar).
-
8.4.41 - 2024-08-05
- Fixed types (by @ nex3 and @ querkmachine).
- Cleaned up RegExps (by @ bluwy).
from postcss GitHub release notesmarkClean is not a functionerror.markClean is not a functionerror.Package name: @vue/compiler-sfc
-
3.4.38 - 2024-08-15
-
3.4.37 - 2024-08-08
-
3.4.36 - 2024-08-06
-
3.4.35 - 2024-07-31
from @vue/compiler-sfc GitHub release notesFor stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.For stable releases, please refer to CHANGELOG.md for details.
For pre-releases, please refer to CHANGELOG.md of the
minorbranch.Package name: autoprefixer
-
10.4.20 - 2024-08-02
- Fixed
-
10.4.19 - 2024-03-20
- Removed
-
10.4.18 - 2024-03-01
- Fixed removing
-
10.4.17 - 2024-01-17
- Fixed
-
10.4.16 - 2023-09-20
- Improved performance (by @ romainmenke).
- Fixed docs (by @ coliff).
-
10.4.15 - 2023-08-13
- Fixed
- Fixed docs (by @ coliff).
-
10.4.14 - 2023-03-09
- Improved startup time and reduced JS bundle size (by @ Knagis).
from autoprefixer GitHub release notesfit-contentprefix for Firefox.end value has mixed support, consider using flex-endwarning sinceend/startnow have good support.-webkit-box-orienton-webkit-line-clamp(@ Goodwine).user-select: containprefixes.::backdropprefixes (by @ yisibl).Package name: axios
-
1.7.7 - 2024-08-31
- fetch: fix stream handling in Safari by fallback to using a stream reader instead of an async iterator; (#6584) (d198085)
- http: fixed support for IPv6 literal strings in url (#5731) (364993f)
Rishi556
Dmitriy Mozgovoy
-
1.7.6 - 2024-08-30
- fetch: fix content length calculation for FormData payload; (#6524) (085f568)
- fetch: optimize signals composing logic; (#6582) (df9889b)
Dmitriy Mozgovoy
Jacques Germishuys
kuroino721
-
1.7.5 - 2024-08-23
- adapter: fix undefined reference to hasBrowserEnv (#6572) (7004707)
- core: add the missed implementation of AxiosError#status property; (#6573) (6700a8a)
- core: fix
- fetch: fix credentials handling in Cloudflare workers (#6533) (550d885)
Dmitriy Mozgovoy
Antonin Bas
Hans Otto Wirtz
-
1.7.4 - 2024-08-13
- sec: CVE-2024-39338 (#6539) (#6543) (6b6b605)
- sec: disregard protocol-relative URL to remediate SSRF (#6539) (07a661a)
Lev Pachmanov
Đỗ Trọng Hải
from axios GitHub release notesRelease notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Release notes:
Bug Fixes
ReferenceError: navigator is not definedfor custom environments; (#6567) (fed1a4b)Contributors to this release
Release notes:
Bug Fixes
Contributors to this release
Package name: bootstrap
Highlights
variables-dark.scsswhen building Bootstrap with Sass. Now,_variables.scsswill automatically import_variables-dark.scss. If you were already importing_variables-dark.scssmanually, you should keep doing it as it won't break anything and will be the way to go in v6.Color modes
.text-bg-*text utilities to be certain that the text is always readable (especially when the customized colors are different in light and dark modes).color-modes.jsscript to handle the case where the OS is set to light mode and the auto color mode is used on the website. If you copied the script from our docs, you should apply this change to your own script.color-scheme()only acceptlightanddarkvalues as parameters.Miscellaneous
<dl>,<dt>and<dd>in the sanitizer.🎨 CSS
--bs-accordion-btn-focus-border-colorand deprecate$accordion-button-focus-border-color☕️ JavaScript
color-mode.jsdl,dtandddin sanitizer📖 Docs
.text-bg-{color}for all badgesgetOrCreateInstance()doc example.table-lightfrom table foot exampledispose()to Offcanvas methodsshift-color()usage example in sass customization page.card-img-*description.theme-iconclass🛠 Examples
🏭 Tests
🧰 Misc
📦 Dependencies
Highlights
abs()is deprecated since Dart Sass v1.65.0. It resulted in a deprecation warning when compiling Bootstrap with Dart Sass. This has been fixed internally by changing the values passed to thedivide()function. Thedivide()function has not been fixed itself so that we can keep supporting node-sass cross-compatibility. In v6, this won't be an issue as we plan to drop support for node-sass.ids in a collapse target wasn't working anymore and has been fixed.