Skip to content

[Snyk] Fix for 10 vulnerabilities - #47

Open
snyk-io[bot] wants to merge 1 commit into
mainfrom
snyk-fix-8b89cfde9456fee31b44319dc4645371
Open

[Snyk] Fix for 10 vulnerabilities#47
snyk-io[bot] wants to merge 1 commit into
mainfrom
snyk-fix-8b89cfde9456fee31b44319dc4645371

Conversation

@snyk-io

@snyk-io snyk-io Bot commented Jul 23, 2026

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 10 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Uncaught Exception
SNYK-JS-MULTER-10185673
  756  
high severity Uncontrolled Recursion
SNYK-JS-MULTER-17342512
  713  
critical severity Uncaught Exception
SNYK-JS-MULTER-10299078
  674  
high severity Missing Release of Memory after Effective Lifetime
SNYK-JS-MULTER-10185675
  649  
high severity Uncaught Exception
SNYK-JS-MULTER-10773732
  649  
high severity Missing Release of Resource after Effective Lifetime
SNYK-JS-MULTER-15365916
  649  
high severity Incomplete Cleanup
SNYK-JS-MULTER-15365918
  649  
high severity Uncontrolled Recursion
SNYK-JS-MULTER-15417528
  649  
medium severity Cross-site Scripting (XSS)
SNYK-JS-POSTCSS-16189065
  586  
low severity Arbitrary Code Injection
SNYK-JS-PRISMJS-9055448
  436  

Breaking Change Risk

Merge Risk: Medium

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncaught Exception
🦉 Missing Release of Memory after Effective Lifetime
🦉 Uncontrolled Recursion
🦉 More lessons are available in Snyk Learn

@snyk-io

snyk-io Bot commented Jul 23, 2026

Copy link
Copy Markdown
Author

Merge Risk: Medium

This set of upgrades includes a medium-risk update to styled-components and low-risk updates for gatsby and prismjs.

styled-components 6.1.12 → 6.4.0

This minor version bump for styled-components introduces several new features and a notable breaking change.

Breaking Change:

  • IE11 Support Dropped: As of v6.2.0, support for Internet Explorer 11 has been removed. This will impact projects that still require compatibility with this browser.

New Features & Improvements:

  • createTheme API: A new createTheme utility has been introduced for CSS variable theming that works across both React Server Components (RSC) and client components.
  • Performance Gains: Significant performance improvements have been made, with some applications seeing a 1.5-3.5x improvement.
  • .attrs() Improvements: Props supplied via .attrs() are now automatically made optional on the resulting component's types.

Recommendation:
Verify that dropping IE11 support is acceptable for your project. Review the new createTheme API if you are using or planning to use CSS variables for theming.

Other Upgrades

  • gatsby 5.14.0 → 5.14.4 (low risk): This is a patch release with bug fixes and dependency updates. No breaking changes are expected.
  • prismjs 1.29.0 → 1.30.0 (low risk): This update addresses an Arbitrary Code Injection vulnerability. It is a security fix with no expected breaking changes.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@snyk-io

snyk-io Bot commented Jul 23, 2026

Copy link
Copy Markdown
Author

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants