Skip to content

Conversation

viswasakthi3
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • extensions/ms-toolsai.jupyter-renderers-1.0.12/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Information Exposure
SNYK-JS-SANITIZEHTML-6256334
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @jupyter-widgets/jupyterlab-manager The new version differs by 250 commits.
  • 5e86a96 Bump version
  • 34ebdc9 Missing rimraf dev dependency
  • feaa7cc Update dev release docs
  • 52616a2 Merge pull request #3794 from ferdnyc/patch-1
  • c789929 docs/environment: Use jupyterlab-myst from pypy
  • 311d83a Merge pull request #3752 from martinRenou/lab4_lum2
  • 518fc5f Make sure to support JupyterLab 3
  • 8c08faf Lab 4 Lumino 2
  • e226177 Merge pull request #3776 from paddymul/subproject-explanation
  • 52edd7c Merge pull request #3787 from martinRenou/fix_tab_widget
  • c3e60c7 Fix tab widget with JupyterLab 4
  • 2b1bb1e Merge pull request #3782 from jasongrout/lint
  • 0f7b334 Lint
  • 1acf37f Merge pull request #3779 from StefanieSenger/doc_installation_with_pip
  • 17db72a added instruction to Installing with pip section
  • f993156 Improved wording.
  • aa5bbd1 Explain that ipywidgets is part of jupyter-widgets software subproject in docs
  • e63ad8b Fixed syntax error.
  • 1d33470 Explain that ipywidgets is part of jupyter-widgets software subproject
  • 449f895 Merge pull request #3714 from djp52/patch-1
  • 511663a chore: update changelog and release instructions
  • 95250d2 Release: ipywidgets 8.0.6, widgetsnbextension 4.0.7, jupyterlab_widgets 3.0.7
  • 80cef44 Bump version
  • 759ac14 Merge pull request #3749 from maartenbreddels/fix_ipykernel_dep_8.x

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

…educe vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-SANITIZEHTML-6256334
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants