[Snyk] Upgrade bootstrap from 5.1.3 to 5.3.3 #575
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade bootstrap from 5.1.3 to 5.3.3.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFORGE-2430339
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-DECODEURICOMPONENT-3149970
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-DNSPACKET-1293563
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-EJS-2803307
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1579155
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-MOMENT-2440688
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-MOMENT-2944238
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-6141137
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TMPL-1583443
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-WEBPACK-3358798
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1536528
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1536531
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1579147
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1579152
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-IP-6240864
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-JSONSCHEMA-1920922
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3043105
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3043105
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-ANSIREGEX-1583908
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-ASYNC-2441827
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NWSAPI-2841516
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFORGE-2430341
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-6476909
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-6476909
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-MINIMATCH-3050818
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFETCH-2342118
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFETCH-674311
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFORGE-2430337
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-EXPRESS-6474509
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-2332181
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-6444610
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-HTTPCACHESEMANTICS-3248783
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TERSER-2806366
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-BROWSERSLIST-1090194
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-2396346
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1536758
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-WORDWRAP-3149973
Why? Proof of Concept exploit, CVSS 7.5
npm:debug:20170905
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-BABELTRAVERSE-5962462
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-BABELTRAVERSE-5962462
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-BABELTRAVERSE-5962462
Why? Proof of Concept exploit, CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: bootstrap
-
5.3.3 - 2024-02-20
- Fixed a breaking change introduced with color modes where it was required to manually import
- Fixed a regression in the selector engine that wasn't able to handle multiple IDs anymore.
- Badges now use the
- Fixed our
- Fixed color schemes description in the color modes documentation to show that
- Allowed
- Dropped evenly items distribution for modal and offcanvas headers.
- Fixed the accordion CSS selectors to avoid inheritance issues when nesting accordions.
- Fixed the focus box-shadow for the validation stated form controls.
- Fixed the focus ring on focused checked buttons.
- Fixed the product example mobile navbar toggler.
- Changed the RTL processing of carousel control icons.
- #37508: Use child combinators to avoid inheriting parent accordion's flush styles
- #38719: Fix focus box-shadow for validation stated form-controls
- #38884: fix border-radius on radio-switch
- #39294: Tests: update navbar in visual modal test
- #39373: refactor css: modal and offcanvas header spacing
- #39380: Fix Sass compilation breaking change in v5.3
- #39387: docs: fix typo
- #39411: Optimize the accordion icon
- #39497: Fix a typo
- #39536: Changed RTL processing of carousel control icons
- #39560: Drop
- #39595: CSS: Fix the focus ring on focused checked buttons
- #39201: Selector Engine: fix multiple IDs
- #39224: Fix edge case in
- #39376: Allow
- #39200: Typo Fix
- #39214: Doc: use
- #39246: Docs: fix for example code blocks have unnecessary 30px right-margin
- #39249: Doc: consistent rendering of 'Heads up!' callouts
- #39281: Fix
- #39293: Update background.md
- #39304: Doc: add expanded accordion explanation
- #39320: Drop
- #39340: Doc: add
- #39378: Docs: fix sentence in modal
- #39417: Fix color schemes description in Sass customization documentation
- #39418: Docs: change vite config path import in vite guide
- #39435: Docs: add
- #39458: Docs: enhance
- #39503: Minor image compression improvements
- #39519: Docs: use consistent HTML elements in Utilities -> Background page
- #39520: Docs: drop unused
- #39528: docs: clean up example.html
- #39537: Docs: fix desc around deprecated Sass mixins for alerts and list groups
- #39539: Update links on get-started page
- #39592: Update vite.md
- #39604: Fix typo in 'media-breakpoint-between' in migration docs
- #39617: Docs: add missing comma in native font stack code source in Content -> Reboot
- #39663: updated table to be responsive
- #39657: Fix product example mobile navbar toggler
- #39585: Docs: Add missing type="button" to Cheatsheet nav buttons
- #39294: Tests: update navbar in visual modal test
- #39096: CI: stop running coveralls in forks
- #39501: CI: switch to Node.js 20
- Updated numerous devDependencies
-
5.3.2 - 2023-09-14
-
5.3.1 - 2023-07-26
-
5.3.0 - 2023-05-30
-
5.3.0-alpha3 - 2023-04-03
- Fixed wrong interpolated variables with node-sass/Hugo.
- Added a check for interpolated variables to catch compilation errors with Node Sass when using Sass variables in
- Started using
- Added
- Fixed
- Fix selectors for dark mode carousel overrides when compiling with
- Updated the styling of floating labels when "floated" to include a
- Updated RFS to v10.0.0.
-
5.3.0-alpha2 - 2023-03-24
-
5.3.0-alpha1 - 2022-12-24
-
5.2.3 - 2022-11-22
- #37377: Import root in bootstrap-utilities
- #37425: Fix deprecation warning with sass 1.56.0
- #37266: Carousel: Fix RTL
- #37235: fix tooltip/popper disposal inconsistencies
-
5.2.2 - 2022-10-03
-
5.2.1 - 2022-09-07
-
5.2.0 - 2022-07-19
-
5.2.0-beta1 - 2022-05-13
-
5.1.3 - 2021-10-09
from bootstrap GitHub release notesHighlights
variables-dark.scsswhen building Bootstrap with Sass. Now,_variables.scsswill automatically import_variables-dark.scss. If you were already importing_variables-dark.scssmanually, you should keep doing it as it won't break anything and will be the way to go in v6.Color modes
.text-bg-*text utilities to be certain that the text is always readable (especially when the customized colors are different in light and dark modes).color-modes.jsscript to handle the case where the OS is set to light mode and the auto color mode is used on the website. If you copied the script from our docs, you should apply this change to your own script.color-scheme()only acceptlightanddarkvalues as parameters.Miscellaneous
<dl>,<dt>and<dd>in the sanitizer.🎨 CSS
--bs-accordion-btn-focus-border-colorand deprecate$accordion-button-focus-border-color☕️ JavaScript
color-mode.jsdl,dtandddin sanitizer📖 Docs
.text-bg-{color}for all badgesgetOrCreateInstance()doc example.table-lightfrom table foot exampledispose()to Offcanvas methodsshift-color()usage example in sass customization page.card-img-*description.theme-iconclass🛠 Examples
🏭 Tests
🧰 Misc
📦 Dependencies
Read more
Read more
Release v5.3.0 (#38657)
* Bump version to 5.3.0
* Dist
calc()functions.--bs-border-radiusvariables across more components..d-inline-gridutility class..tooltip-innerplacement when using variations infallbackPlacements.$color-mode-type: media-query.background-colorto help with multiple lines of text intextareas. This also fixes the colors when form elements are disabled in floating forms.Full Changelog: v5.3.0-alpha2...v5.3.0-alpha3
Read more
Read more
Fixes
🎨 CSS
translate()direction☕️ JavaScript
Read more
Read more
Commit messages
Package name: bootstrap
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs