Skip to content

Bump eslint-plugin-react from 7.30.0 to 7.32.1#325

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-react-7.32.1
Closed

Bump eslint-plugin-react from 7.30.0 to 7.32.1#325
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/eslint-plugin-react-7.32.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 17, 2023

Copy link
Copy Markdown
Contributor

Bumps eslint-plugin-react from 7.30.0 to 7.32.1.

Release notes

Sourced from eslint-plugin-react's releases.

v7.32.1

Fixed

  • prevent circular dependency in index and "all" config (#3519[] @​ljharb)
  • [destructuring-assignment]: do not force destructuring of optionally chained properties (#3520[] @​ljharb)

#3519: jsx-eslint/eslint-plugin-react#3519

#1000: jsx-eslint/eslint-plugin-react#1000 #1002: jsx-eslint/eslint-plugin-react#1002 #1005: jsx-eslint/eslint-plugin-react#1005 #100: jsx-eslint/eslint-plugin-react#100 #1010: jsx-eslint/eslint-plugin-react#1010 #1013: jsx-eslint/eslint-plugin-react#1013 #1022: jsx-eslint/eslint-plugin-react#1022 #1029: jsx-eslint/eslint-plugin-react#1029 #102: jsx-eslint/eslint-plugin-react#102 #1034: jsx-eslint/eslint-plugin-react#1034 #1038: jsx-eslint/eslint-plugin-react#1038 #1041: jsx-eslint/eslint-plugin-react#1041 #1043: jsx-eslint/eslint-plugin-react#1043 #1046: jsx-eslint/eslint-plugin-react#1046 #1047: jsx-eslint/eslint-plugin-react#1047 #1050: jsx-eslint/eslint-plugin-react#1050 #1053: jsx-eslint/eslint-plugin-react#1053 #1057: jsx-eslint/eslint-plugin-react#1057 #105: jsx-eslint/eslint-plugin-react#105 #1061: jsx-eslint/eslint-plugin-react#1061 #1062: jsx-eslint/eslint-plugin-react#1062 #1070: jsx-eslint/eslint-plugin-react#1070 #1071: jsx-eslint/eslint-plugin-react#1071 #1073: jsx-eslint/eslint-plugin-react#1073 #1076: jsx-eslint/eslint-plugin-react#1076 #1079: jsx-eslint/eslint-plugin-react#1079 #1088: jsx-eslint/eslint-plugin-react#1088 #1098: jsx-eslint/eslint-plugin-react#1098 #1101: jsx-eslint/eslint-plugin-react#1101 #1103: jsx-eslint/eslint-plugin-react#1103 #110: jsx-eslint/eslint-plugin-react#110 #1116: jsx-eslint/eslint-plugin-react#1116 #1117: jsx-eslint/eslint-plugin-react#1117 #1119: jsx-eslint/eslint-plugin-react#1119 #1121: jsx-eslint/eslint-plugin-react#1121 #1122: jsx-eslint/eslint-plugin-react#1122 #1123: jsx-eslint/eslint-plugin-react#1123 #1130: jsx-eslint/eslint-plugin-react#1130 #1131: jsx-eslint/eslint-plugin-react#1131 #1132: jsx-eslint/eslint-plugin-react#1132 #1134: jsx-eslint/eslint-plugin-react#1134 #1135: jsx-eslint/eslint-plugin-react#1135

... (truncated)

Changelog

Sourced from eslint-plugin-react's changelog.

7.32.1 - 2023.01.16

Fixed

  • prevent circular dependency in index and "all" config (#3519[] @​ljharb)
  • [destructuring-assignment]: do not force destructuring of optionally chained properties (#3520[] @​ljharb)

#3520: jsx-eslint/eslint-plugin-react#3520 #3519: jsx-eslint/eslint-plugin-react#3519

7.32.0 - 2023.01.10

Added

Fixed

Changed

#3511: jsx-eslint/eslint-plugin-react#3511 #3510: jsx-eslint/eslint-plugin-react#3510 #3504: jsx-eslint/eslint-plugin-react#3504 #3502: jsx-eslint/eslint-plugin-react#3502 #3499: jsx-eslint/eslint-plugin-react#3499 #3494: jsx-eslint/eslint-plugin-react#3494 #3493: jsx-eslint/eslint-plugin-react#3493 #3488: jsx-eslint/eslint-plugin-react#3488 #3483: jsx-eslint/eslint-plugin-react#3483 #3474: jsx-eslint/eslint-plugin-react#3474 #3471: jsx-eslint/eslint-plugin-react#3471 #3468: jsx-eslint/eslint-plugin-react#3468

... (truncated)

Commits
  • b2e069e Update CHANGELOG and bump version
  • 74a9522 [Fix] destructuring-assignment: do not force destructuring of optionally ch...
  • 161e5a8 [patch] destructuring-assignment: use report helper for all warnings
  • c4c54cb Update link to eslint-plugin-jsx-a11y in README
  • a847c84 [Fix] prevent circular dependency in index and "all" config
  • c8f2813 Update CHANGELOG and bump version
  • e312953 [Dev Deps] update @babel/core, eslint-doc-generator
  • a5f7065 [Dev Deps] update eslint-remote-tester-repositories
  • 6756c95 [Dev Deps] update @babel/core, aud, eslint-remote-tester-repositories, ...
  • 3256c92 [meta] add missing changelog entry
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [eslint-plugin-react](https://github.com/jsx-eslint/eslint-plugin-react) from 7.30.0 to 7.32.1.
- [Release notes](https://github.com/jsx-eslint/eslint-plugin-react/releases)
- [Changelog](https://github.com/jsx-eslint/eslint-plugin-react/blob/master/CHANGELOG.md)
- [Commits](jsx-eslint/eslint-plugin-react@v7.30.0...v7.32.1)

---
updated-dependencies:
- dependency-name: eslint-plugin-react
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jan 17, 2023
@guardrails

guardrails Bot commented Jan 17, 2023

Copy link
Copy Markdown

⚠️ We detected 48 security issues in this pull request:

Vulnerable Libraries (48)
Severity Details
High @unimodules/react-native-adapter@6.1.0 (t) upgrade to: >6.1.0
High gulp@4.0.2 (t) upgrade to: >=3.9.1
High ini@1.3.5 (t) upgrade to: >=1.3.6
High json5@1.0.1 (t) upgrade to: >=1.0.2
N/A pkg:npm/node-forge@0.10.0@0.10.0 (t) upgrade to: 1.0.0
High pkg:npm/fast-json-patch@2.2.1@2.2.1 (t) - no patch available
High pkg:npm/fast-json-patch@2.2.1@2.2.1 (t) - no patch available
Critical pkg:npm/express@4.17.2@4.17.2 (t) - no patch available
Critical pkg:npm/express@4.17.2@4.17.2 (t) - no patch available
Critical pkg:npm/qs@6.9.6@6.9.6 (t) - no patch available
High pkg:npm/flat@5.0.2@5.0.2 (t) - no patch available
High pkg:npm/flat@5.0.2@5.0.2 (t) - no patch available
Medium pkg:npm/node-notifier@9.0.0@9.0.0 (t) - no patch available
Medium pkg:npm/ua-parser-js@0.7.32@0.7.32 (t) - no patch available
Medium pkg:npm/ua-parser-js@0.7.32@0.7.32 (t) - no patch available
High pkg:npm/moment@2.29.2@2.29.2 (t) upgrade to: 2.29.4,2.29.4
Medium pkg:npm/got@8.3.2@8.3.2 (t) - no patch available
Medium pkg:npm/got@8.3.2@8.3.2 (t) - no patch available
Medium pkg:npm/jszip@3.7.1@3.7.1 (t) - no patch available
Medium pkg:npm/jszip@3.7.1@3.7.1 (t) - no patch available
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
Low pkg:npm/node-fetch@2.6.8@2.6.8 (t) - no patch available
Low pkg:npm/node-fetch@2.6.8@2.6.8 (t) - no patch available
N/A pkg:npm/decode-uri-component@0.2.0@0.2.0 (t) - no patch available
N/A pkg:npm/decode-uri-component@0.2.0@0.2.0 (t) - no patch available
Low pkg:npm/request@2.88.2@2.88.2 (t) - no patch available
High pkg:npm/json-merge-patch@0.2.3@0.2.3 (t) - no patch available
High pkg:npm/json-merge-patch@0.2.3@0.2.3 (t) - no patch available
High pkg:npm/file-type@11.1.0@11.1.0 (t) - no patch available
High pkg:npm/file-type@11.1.0@11.1.0 (t) - no patch available
Critical pkg:npm/msrcrypto@1.5.8@1.5.8 (t) - no patch available
Critical pkg:npm/unset-value@1.0.0@1.0.0 (t) - no patch available
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
N/A pkg:npm/jsonwebtoken@8.5.1@8.5.1 (t) upgrade to: 9.0.0
N/A pkg:npm/jsonwebtoken@8.5.1@8.5.1 (t) upgrade to: 9.0.0
High pkg:npm/yargs-parser@5.0.0-security.0@5.0.0-security.0 (t) - no patch available
Critical pkg:npm/set-value@2.0.1@2.0.1 (t) - no patch available
Critical pkg:npm/set-value@2.0.1@2.0.1 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
High pkg:npm/json5@1.0.1@1.0.1 (t) upgrade to: 2.2.2

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@dependabot @github

dependabot Bot commented on behalf of github Jan 30, 2023

Copy link
Copy Markdown
Contributor Author

Superseded by #328.

@dependabot dependabot Bot closed this Jan 30, 2023
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/eslint-plugin-react-7.32.1 branch January 30, 2023 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants