Skip to content

Conversation

@snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-JS-BOOTSTRAPSASS-598772
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-JS-BOOTSTRAPSASS-598777
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-JS-BOOTSTRAPSASS-598782
No No Known Exploit
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Cross-site Scripting (XSS)
SNYK-JS-BOOTSTRAPSASS-598787
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: bootstrap-sass The new version differs by 24 commits.
  • bb7dbf8 v3.4.0
  • 3c126b3 Revert relative imports change
  • dcdef9b Test Rails app: Depend on sassc-rails
  • cd1542b rake convert[v3.4.0]
  • 07b9b64 less_conversion.rb: Update stylelint comment removal
  • 6634d0a Remove compass support
  • 489b6f2 lotus -> hanami
  • a1c5ec5 sass -> sassc
  • 3db610a rake convert[v3.4.0-dev]
  • 58db771 Fix test/node_sass_compile_test.sh
  • fe4599d Stop testing with sass-head and rails-head
  • 7319f3b travis
  • 2e15e66 Fix "$a-$b" -> "#{$a}-#{$b}" conversion
  • 8c0b5db rake convert[v3.4.0-dev]
  • 92aa0c8 Update converter to support v3.4.0
  • 418073f Fix test/compass_test.rb for recent bundler
  • b6e3c54 Update package.json devDependencies
  • 2dd87b0 readme [ci skip]
  • eb15fe0 Merge pull request #1168 from coliff/patch-1
  • 16c5dff HTTPS relevant links
  • 51486a8 Merge pull request #1145 from zhublik/readme
  • b9d2bd4 Update bootstrap-sass version in README.
  • 9766e03 Merge pull request #1141 from ltfschoen/patch-1
  • 1ef3411 Update README.md advising use of jquery-rails

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants