Skip to content

[Snyk] Upgrade core-js from 3.27.2 to 3.37.1 #3

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

gitafolabi
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade core-js from 3.27.2 to 3.37.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 22 versions ahead of your current version.

  • The recommended version was released on 3 months ago.

Release notes
Package name: core-js from core-js GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade core-js from 3.27.2 to 3.37.1.

See this package in npm:
core-js

See this project in Snyk:
https://app.snyk.io/org/gitafolabi/project/98c3ec3f-f970-40be-bb31-35ca7f65e8d2?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

dryrunsecurity bot commented Aug 15, 2024

DryRun Security Summary

This GitHub Pull Request updates the major version of the core-js dependency in the package.json file, which requires careful review and testing to ensure the application continues to function securely and without any regressions.

Expand for full summary

Summary:

The changes made in this GitHub Pull Request focus on updating the major version of the core-js dependency in the package.json file. While keeping dependencies up-to-date is generally a good practice, this significant version bump requires careful review and testing to ensure that the application continues to function securely and without any regressions.

As an application security engineer, I recommend performing a comprehensive audit of the updated core-js dependency to identify and address any known security vulnerabilities. Additionally, thorough regression testing should be conducted to verify that the application's behavior remains intact and that no new security issues have been introduced. The project's dependency management strategy and the CI/CD pipeline should also be reviewed to ensure that security checks and scans are in place to catch potential issues before deploying changes to production.

Files Changed:

  • package.json: The major version of the core-js dependency has been updated from 3.26.1 to 3.37.1. This is a significant version bump that may introduce breaking changes or new features, and it should be thoroughly tested to ensure that no security vulnerabilities or other issues are introduced. The versions of other dependencies, such as @testing-library/jest-dom, @testing-library/react, and @testing-library/user-event, have been kept up-to-date, which is a good practice to maintain the security and stability of the application.

Code Analysis

We ran 9 analyzers against 2 files and 1 analyzer had findings. 8 analyzers had no findings.

Analyzer Findings
Sensitive Files Analyzer 2 findings

Riskiness

🟢 Risk threshold not exceeded.

View PR in the DryRun Dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants