Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: upgrade dependencies with vulnerability issues #302

Merged
merged 6 commits into from
Jan 19, 2024

Conversation

theashraf
Copy link
Member

@theashraf theashraf commented Jan 19, 2024

Description

fixes #298
fixes #297

Type of change

  • Patch: Bug (non-breaking change which fixes an issue)
  • Minor: New feature (non-breaking change which adds functionality)
  • Major: Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Docs: Documentation updates (if none of the other choices apply)

Checklist

  • Lint and unit tests pass locally with my changes.
  • I have added tests that prove my fix is effective or that my feature works.
  • I have tested my changes on the player-component and React player.

Copy link

changeset-bot bot commented Jan 19, 2024

⚠️ No Changeset found

Latest commit: 26591bb

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@theashraf theashraf marked this pull request as ready for review January 19, 2024 03:40
Copy link
Contributor

github-actions bot commented Jan 19, 2024

size-limit report 📦

Path Size Loading time (3g) Running time (snapdragon) Total time
packages/common/dist/index.js 7.46 KB (-0.02% 🔽) 150 ms (-0.02% 🔽) 96 ms (+146.62% 🔺) 245 ms
packages/player-component/dist/dotlottie-player.mjs 31.67 KB (-0.09% 🔽) 634 ms (-0.09% 🔽) 97 ms (+143.08% 🔺) 730 ms

@theashraf theashraf changed the title fix: 🐛 postcss & sharp vulnerability chore: upgrade dependencies with vulnerability issues Jan 19, 2024
@theashraf theashraf merged commit 970e565 into master Jan 19, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

sharp Heap-based Buffer Overflow postcss Improper Input Validation
2 participants