Skip to content

Bump eslint-plugin-react from 7.30.0 to 7.32.0#322

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-react-7.32.0
Closed

Bump eslint-plugin-react from 7.30.0 to 7.32.0#322
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-react-7.32.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 11, 2023

Copy link
Copy Markdown
Contributor

Bumps eslint-plugin-react from 7.30.0 to 7.32.0.

Release notes

Sourced from eslint-plugin-react's releases.

v7.32.0

Added

Fixed

Changed

#3429: jsx-eslint/eslint-plugin-react#3429 #3461: jsx-eslint/eslint-plugin-react#3461 #1000: jsx-eslint/eslint-plugin-react#1000 #1002: jsx-eslint/eslint-plugin-react#1002 #1005: jsx-eslint/eslint-plugin-react#1005 #100: jsx-eslint/eslint-plugin-react#100 #1010: jsx-eslint/eslint-plugin-react#1010 #1013: jsx-eslint/eslint-plugin-react#1013 #1022: jsx-eslint/eslint-plugin-react#1022 #1029: jsx-eslint/eslint-plugin-react#1029 #102: jsx-eslint/eslint-plugin-react#102 #1034: jsx-eslint/eslint-plugin-react#1034 #1038: jsx-eslint/eslint-plugin-react#1038 #1041: jsx-eslint/eslint-plugin-react#1041 #1043: jsx-eslint/eslint-plugin-react#1043 #1046: jsx-eslint/eslint-plugin-react#1046 #1047: jsx-eslint/eslint-plugin-react#1047 #1050: jsx-eslint/eslint-plugin-react#1050 #1053: jsx-eslint/eslint-plugin-react#1053 #1057: jsx-eslint/eslint-plugin-react#1057 #105: jsx-eslint/eslint-plugin-react#105 #1061: jsx-eslint/eslint-plugin-react#1061 #1062: jsx-eslint/eslint-plugin-react#1062

... (truncated)

Changelog

Sourced from eslint-plugin-react's changelog.

7.32.0 - 2023.01.10

Added

Fixed

Changed

#3511: jsx-eslint/eslint-plugin-react#3511 #3510: jsx-eslint/eslint-plugin-react#3510 #3504: jsx-eslint/eslint-plugin-react#3504 #3502: jsx-eslint/eslint-plugin-react#3502 #3499: jsx-eslint/eslint-plugin-react#3499 #3494: jsx-eslint/eslint-plugin-react#3494 #3493: jsx-eslint/eslint-plugin-react#3493 #3488: jsx-eslint/eslint-plugin-react#3488 #3483: jsx-eslint/eslint-plugin-react#3483 #3474: jsx-eslint/eslint-plugin-react#3474 #3471: jsx-eslint/eslint-plugin-react#3471 #3468: jsx-eslint/eslint-plugin-react#3468 #3461: jsx-eslint/eslint-plugin-react#3461 #3452: jsx-eslint/eslint-plugin-react#3452 #3449: jsx-eslint/eslint-plugin-react#3449 #3429: jsx-eslint/eslint-plugin-react#3429 #2848: jsx-eslint/eslint-plugin-react#2848 #2797: jsx-eslint/eslint-plugin-react#2797 #1861: jsx-eslint/eslint-plugin-react#1861

[7.31.11] - 2022.11.17

... (truncated)

Commits
  • c8f2813 Update CHANGELOG and bump version
  • e312953 [Dev Deps] update @babel/core, eslint-doc-generator
  • a5f7065 [Dev Deps] update eslint-remote-tester-repositories
  • 6756c95 [Dev Deps] update @babel/core, aud, eslint-remote-tester-repositories, ...
  • 3256c92 [meta] add missing changelog entry
  • 523db20 [Fix] destructuring-assignment: Handle destructuring of useContext in SFC
  • a60f020 [docs] run npm run update:eslint-docs
  • f350303 [Fix] jsx-no-leaked-render: invalid fixes in coerce mode
  • 12fe944 [meta] fix changelog links
  • 85ae820 [Perf] use anyOf instead of oneOf
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [eslint-plugin-react](https://github.com/jsx-eslint/eslint-plugin-react) from 7.30.0 to 7.32.0.
- [Release notes](https://github.com/jsx-eslint/eslint-plugin-react/releases)
- [Changelog](https://github.com/jsx-eslint/eslint-plugin-react/blob/master/CHANGELOG.md)
- [Commits](jsx-eslint/eslint-plugin-react@v7.30.0...v7.32.0)

---
updated-dependencies:
- dependency-name: eslint-plugin-react
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jan 11, 2023
@guardrails

guardrails Bot commented Jan 11, 2023

Copy link
Copy Markdown

⚠️ We detected 44 security issues in this pull request:

Vulnerable Libraries (44)
Severity Details
High glob-watcher@5.0.5 (t) upgrade to: >=3.0.0
High gulp@4.0.2 (t) upgrade to: >=3.9.1
High ini@1.3.5 (t) upgrade to: >=1.3.6
High json5@1.0.1 (t) upgrade to: >=1.0.2
High tar@4.4.13 (t) upgrade to: >4.4.17
High terser@5.10.0 (t) upgrade to: >5.14.1
Low pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
Low pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
N/A pkg:npm/node-forge@0.10.0@0.10.0 (t) upgrade to: 1.0.0
High pkg:npm/fast-json-patch@2.2.1@2.2.1 (t) - no patch available
High pkg:npm/fast-json-patch@2.2.1@2.2.1 (t) - no patch available
High pkg:npm/file-type@11.1.0@11.1.0 (t) - no patch available
High pkg:npm/file-type@11.1.0@11.1.0 (t) - no patch available
Critical pkg:npm/msrcrypto@1.5.8@1.5.8 (t) - no patch available
Medium pkg:npm/node-notifier@9.0.0@9.0.0 (t) - no patch available
High pkg:npm/flat@5.0.2@5.0.2 (t) - no patch available
High pkg:npm/flat@5.0.2@5.0.2 (t) - no patch available
N/A pkg:npm/decode-uri-component@0.2.0@0.2.0 (t) - no patch available
N/A pkg:npm/decode-uri-component@0.2.0@0.2.0 (t) - no patch available
Medium pkg:npm/react@18.1.0@18.1.0 (t) - no patch available
Medium pkg:npm/react@18.1.0@18.1.0 (t) - no patch available
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
Medium pkg:npm/got@8.3.2@8.3.2 (t) - no patch available
Medium pkg:npm/got@8.3.2@8.3.2 (t) - no patch available
Critical pkg:npm/qs@6.9.6@6.9.6 (t) - no patch available
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
Medium pkg:npm/jszip@3.7.1@3.7.1 (t) - no patch available
Medium pkg:npm/jszip@3.7.1@3.7.1 (t) - no patch available
Critical pkg:npm/unset-value@1.0.0@1.0.0 (t) - no patch available
High pkg:npm/yargs-parser@5.0.0-security.0@5.0.0-security.0 (t) - no patch available
Medium pkg:npm/express@4.17.2@4.17.2 (t) - no patch available
Medium pkg:npm/express@4.17.2@4.17.2 (t) - no patch available
Critical pkg:npm/set-value@2.0.1@2.0.1 (t) - no patch available
Critical pkg:npm/set-value@2.0.1@2.0.1 (t) - no patch available
N/A pkg:npm/jsonwebtoken@8.5.1@8.5.1 (t) upgrade to: 9.0.0
N/A pkg:npm/jsonwebtoken@8.5.1@8.5.1 (t) upgrade to: 9.0.0
Low pkg:npm/request@2.88.2@2.88.2 (t) - no patch available
High pkg:npm/json5@1.0.1@1.0.1 (t) upgrade to: 2.2.2
High pkg:npm/moment@2.29.2@2.29.2 (t) upgrade to: 2.29.4,2.29.4
High pkg:npm/json-merge-patch@0.2.3@0.2.3 (t) - no patch available
High pkg:npm/json-merge-patch@0.2.3@0.2.3 (t) - no patch available

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@dependabot @github

dependabot Bot commented on behalf of github Jan 17, 2023

Copy link
Copy Markdown
Contributor Author

Superseded by #325.

@dependabot dependabot Bot closed this Jan 17, 2023
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/eslint-plugin-react-7.32.0 branch January 17, 2023 13:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants