Skip to content

Dependency updates #71571

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 49 commits into
base: canary
Choose a base branch
from
Open

Dependency updates #71571

wants to merge 49 commits into from

Conversation

Abuchtela
Copy link

@Abuchtela Abuchtela commented Oct 21, 2024

Dependency Updates for Example Projects

This pull request includes multiple dependency updates across various example projects to ensure compatibility and leverage the latest features and bug fixes. The most important changes include upgrading dependencies for cookie, @keystone-next, @tinacms, web3, and aws-amplify.

Additionally, this PR adds a GitHub workflow for npm package publishing that triggers when a release is created.

Dependency updates:

  • Updated cookie from ^0.5.0 to ^0.7.0 in multiple examples
  • Updated nanoid from ^4.0.0 to ^5.0.9 in blog and CSP examples
  • Updated next to newer versions in multiple examples (from older versions to 14.2.x)
  • Updated @keystone-next/fields from ^9.0.0 to ^15.0.0 and @keystone-next/keystone from ^18.0.0 to ^29.0.0
  • Updated @tinacms/cli from ^0.60.16 to ^1.5.47
  • Updated web3 from ^1.7.4 to ^4.0.1
  • Updated aws-amplify from 4.3.39 to 5.3.4
  • Updated bootstrap from ^4.x to ^5.0.0 in React Bootstrap examples
  • Updated @graphql-mesh/cli from 0.68.1 to 0.82.35

snyk-bot and others added 25 commits July 7, 2024 23:45
…b3a7ef4acb5

[Snyk] Security upgrade next from 10.0.4 to 14.2.7
@ijjk ijjk added the examples Issue was opened via the examples template. label Oct 21, 2024
@@ -6,7 +6,7 @@
"start": "next start"
},
"dependencies": {
"next": "^9.5.1",
"next": "^12.0.8",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems unexpected, (current one is already unexpected) since it's not latest like the other examples. If it no longer works on Next.js 15 it might be worth removing the file.

snyk-bot and others added 16 commits December 12, 2024 19:20
A new binary file, `slnx.sqlite`, has been added to the project. This file is likely a SQLite database file, indicating that the project now includes or will include functionality that requires database storage.
Copy link
Author

@Abuchtela Abuchtela left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fixes #71571

snyk-bot and others added 2 commits May 17, 2025 00:47
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)

### Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

#### Snyk changed the following file(s):

- `examples/app-dir-mdx/package.json`




#### Vulnerabilities that will be fixed with an upgrade:

|  | Issue | Score | 
:-------------------------:|:-------------------------|:-------------------------
![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Race Condition <br/>[SNYK-JS-NEXT-10176058](https://snyk.io/vuln/SNYK-JS-NEXT-10176058) | &nbsp;&nbsp;**82**&nbsp;&nbsp; 




---

> [!IMPORTANT]
>
> - Check the changes in this PR to ensure they won't cause issues with your project.
> - Max score is 1000. Note that the real score may have changed since the PR was raised.
> - This PR was automatically created by Snyk using the credentials of a real user.

---

**Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._

For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0NzMzZWU4NS01YjlkLTRiNzYtOWMzMS02YzY2OGE4Nzg5MWQiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjQ3MzNlZTg1LTViOWQtNGI3Ni05YzMxLTZjNjY4YTg3ODkxZCJ9fQ==" width="0" height="0"/>
🧐 [View latest project report](https://app.snyk.io/org/abuchtela/project/08a788c4-7e48-42a4-a913-1b667d4a01da?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr)
📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=github&utm_content=fix-pr-template)
🛠 [Adjust project settings](https://app.snyk.io/org/abuchtela/project/08a788c4-7e48-42a4-a913-1b667d4a01da?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings)
📚 [Read about Snyk's upgrade logic](https://docs.snyk.io/scan-with-snyk/snyk-open-source/manage-vulnerabilities/upgrade-package-versions-to-fix-vulnerabilities?utm_source=github&utm_content=fix-pr-template)

---

**Learn how to fix vulnerabilities with free interactive lessons:**

🦉 [Race Condition](https://learn.snyk.io/lesson/race-condition/?loc&#x3D;fix-pr)

[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"next","from":"13.1.1","to":"14.2.24"}],"env":"prod","issuesToFix":["SNYK-JS-NEXT-10176058"],"prId":"4733ee85-5b9d-4b76-9c31-6c668a87891d","prPublicId":"4733ee85-5b9d-4b76-9c31-6c668a87891d","packageManager":"npm","priorityScoreList":[82],"projectPublicId":"08a788c4-7e48-42a4-a913-1b667d4a01da","projectUrl":"https://app.snyk.io/org/abuchtela/project/08a788c4-7e48-42a4-a913-1b667d4a01da?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","priorityScore"],"type":"auto","upgrade":["SNYK-JS-NEXT-10176058"],"vulns":["SNYK-JS-NEXT-10176058"],"patch":[],"isBreakingChange":true,"remediationStrategy":"vuln"}'
Copy link

changeset-bot bot commented May 18, 2025

🦋 Changeset detected

Latest commit: 793915d

The changes in this PR will be included in the next version bump.

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
examples Issue was opened via the examples template.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants