Skip to content

Conversation

viswasakthi3
Copy link
Owner

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • extensions/ms-toolsai.jupyter-2022.11.1003412109/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 541/1000
Why? Recently disclosed, Has a fix available, CVSS 5.1
Cross-site Scripting (XSS)
SNYK-JS-JQUERYUI-8230415
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @jupyter-widgets/controls The new version differs by 250 commits.
  • 9bf6225 Bump version
  • 8d35c3a ipywidgets 8.0.0, widgetsnbextension 4.0.0, jupyterlab_widgets 3.0.0
  • 497d13b Bump version
  • edb5e0b Merge pull request #3546 from jasongrout/spec8
  • 7abbd25 Update spec snapshot for ipywidgets 8
  • 91dfb9a Merge pull request #3545 from jasongrout/8tags
  • d46e594 Update changelog tags to refer to the 8.0 release
  • 70f8f55 Merge pull request #3543 from jasongrout/ondisplayed
  • 62ad153 Merge pull request #3540 from jasongrout/jlitecontents
  • 1c00fdc Update information for custom widget authors (#3542)
  • 8bb4d55 mention on_displayed in changelog
  • c483387 Use a dev build of widgetsnbextension and jupyterlab_manager in jupyterlite
  • b430df4 Add large note to the 8.x documentation indicating the new ipywidgets version.
  • b1762d9 Update to jupyterlite-sphinx 0.7.2, which now enables a string contents value again.
  • 9213d19 Update jupyterlite widgetsnbextension version
  • bf361d4 Fix jupyterlite contents
  • b95b6f9 Merge pull request #3539 from jasongrout/migrating
  • 2e107f2 Update FileUpload migration/changelog docs
  • 8886410 Fix docs typo
  • 783b4cf Simplify install instructions.
  • aafffd2 Move interact docs to front of widgets as a simple usecase
  • cae4516 Adjust order of layout docs and fix reference.
  • 7a0b921 Update changelog and migration guide to suggest adapting changes from the new cookiecutter.
  • c7eac80 ipywidgets 8.0.0rc2, widgetsnbextension 4.0.0rc2, jupyterlab_widgets 3.0.0rc2

See the full diff

Package name: slickgrid The new version differs by 15 commits.
  • 7e7328d chore(release): publish version 3.0.0
  • b25be57 fix: gitCurrentBranchName should return the branch name not a process result object
  • 6dd4649 fix: ensure npm exits (otherwise need to ctrl-c to get back to command prompt)
  • 7f12612 fix: replace inquirer with direct keyboard input
  • f213d8b fix: ignore untracked files in update script
  • 017bc7f feat: add npm scripts to create new version release & npm publish (#701)
  • 19bea2e chore: add all new minified files in dist folder (#698)
  • 386cd58 feat: BREAKING CHANGE - replace jQueryUI with SortableJS (#695)
  • af513e2 Updates to Autosize Code - fixes #688 (#693)
  • bcc55a0 resolving issue with the `setOptions` function in resizer plugin (#686)
  • 34f2f95 fix getScrollBarWidth bug (#687)
  • d3de81c fix: adjust the left/right canvas width properly when fullWidthRows is used (#664)
  • 571dc12 ignore scrolling if options.autoHeight is true, fixes #674
  • b02d093 Update CODE_OF_CONDUCT.md
  • 4a15383 docs: add missing Code of Conduct (#677)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Scripting (XSS)

… reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-JQUERYUI-8230415
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants