Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSPDF-15182654 - https://snyk.io/vuln/SNYK-JS-JSPDF-15182650 - https://snyk.io/vuln/SNYK-JS-JSPDF-15182644 - https://snyk.io/vuln/SNYK-JS-JSPDF-15182647
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Important
Looks good to me! 👍
Reviewed everything up to 1b9a2fe in 9 seconds. Click for details.
- Reviewed
13lines of code in1files - Skipped
0files when reviewing. - Skipped posting
0draft comments. View those below. - Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
Workflow ID: wflow_I8io6Be5xmbWz4iq
You can customize by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.
🤖 Augment PR SummarySummary: Upgrades 🤖 Was this summary useful? React with 👍 or 👎 |
| "i18next-browser-languagedetector": "^7.0.1", | ||
| "i18next-http-backend": "^2.1.1", | ||
| "jspdf": "^2.5.1", | ||
| "jspdf": "^4.1.0", |
There was a problem hiding this comment.
The PR description notes pnpm-lock.yaml wasn’t updated; if CI uses --frozen-lockfile, installs will fail or won’t pick up the intended jspdf version. Consider regenerating and committing the lockfile so the upgrade is reproducible.
Severity: high
🤖 Was this useful? React with 👍 or 👎, or 🚀 if it prevented an incident/outage.
| "i18next-browser-languagedetector": "^7.0.1", | ||
| "i18next-http-backend": "^2.1.1", | ||
| "jspdf": "^2.5.1", | ||
| "jspdf": "^4.1.0", |
There was a problem hiding this comment.
Snyk has created this PR to fix 4 vulnerabilities in the pnpm dependencies of this project.
Snyk changed the following file(s):
package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-JSPDF-15182654
SNYK-JS-JSPDF-15182650
SNYK-JS-JSPDF-15182644
SNYK-JS-JSPDF-15182647
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 XML Injection
🦉 Race Condition
🦉 Improper Encoding or Escaping of Output
🦉 More lessons are available in Snyk Learn
Important
Upgrade
jspdfto 4.1.0 inpackage.jsonto fix security vulnerabilities, with manualpnpm-lock.yamlupdate needed.jspdffrom2.5.2to4.1.0inpackage.jsonto fix security vulnerabilities.pnpm-lock.yamlupdate failed; requires manual update before merging.This description was created by
for 1b9a2fe. You can customize this summary. It will automatically update as commits are pushed.