Skip to content

[Snyk] Upgrade antd from 4.3.3 to 4.24.14#1

Open
appsectr wants to merge 1 commit intodevelopfrom
snyk-upgrade-f185b87d7c6c7589656d998e9b240c58
Open

[Snyk] Upgrade antd from 4.3.3 to 4.24.14#1
appsectr wants to merge 1 commit intodevelopfrom
snyk-upgrade-f185b87d7c6c7589656d998e9b240c58

Conversation

@appsectr
Copy link
Owner

@appsectr appsectr commented Oct 5, 2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade antd from 4.3.3 to 4.24.14.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 159 versions ahead of your current version.
  • The recommended version was released a month ago, on 2023-09-06.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ASYNCVALIDATOR-2311201
586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: antd
  • 4.24.14 - 2023-09-06

    • 🐞 修复 Breadcrumb 使用 menu 属性时出现 overlay 废弃警告的问题。#43917 @ whalesink
    • 🐞 修复 Upload gif 缩略图不会动的问题。#44129 @ linxianxi
    • 🐞 修复 ConfigProvider 抛出 rc-util/lib/utils/set 不存在的问题。#44630 @ varown
  • 4.24.13 - 2023-08-03
  • 4.24.12 - 2023-06-30
  • 4.24.11 - 2023-06-27
  • 4.24.10 - 2023-05-04
  • 4.24.9 - 2023-04-20
  • 4.24.8 - 2023-02-13
  • 4.24.7 - 2022-12-30
  • 4.24.6 - 2022-12-26
  • 4.24.5 - 2022-12-06
  • 4.24.4 - 2022-11-25
  • 4.24.3 - 2022-11-17
  • 4.24.2 - 2022-11-12
  • 4.24.1 - 2022-11-04
  • 4.24.0 - 2022-11-01
  • 4.23.6 - 2022-10-17
  • 4.23.5 - 2022-10-10
  • 4.23.4 - 2022-10-02
  • 4.23.3 - 2022-09-28
  • 4.23.2 - 2022-09-17
  • 4.23.1 - 2022-09-09
  • 4.23.0 - 2022-09-04
  • 4.22.8 - 2022-08-26
  • 4.22.7 - 2022-08-21
  • 4.22.6 - 2022-08-17
  • 4.22.5 - 2022-08-15
  • 4.22.4 - 2022-08-08
  • 4.22.3 - 2022-08-01
  • 4.22.2 - 2022-07-28
  • 4.22.1 - 2022-07-27
  • 4.22.0 - 2022-07-26
  • 4.21.7 - 2022-07-18
  • 4.21.6 - 2022-07-11
  • 4.21.5 - 2022-07-03
  • 4.21.4 - 2022-06-27
  • 4.21.3 - 2022-06-17
  • 4.21.2 - 2022-06-14
  • 4.21.1 - 2022-06-13
  • 4.21.0 - 2022-06-06
  • 4.20.7 - 2022-05-30
  • 4.20.6 - 2022-05-22
  • 4.20.5 - 2022-05-15
  • 4.20.4 - 2022-05-11
  • 4.20.3 - 2022-05-09
  • 4.20.2 - 2022-04-30
  • 4.20.1 - 2022-04-26
  • 4.20.0 - 2022-04-24
  • 4.20.0-alpha.1 - 2022-04-18
  • 4.20.0-alpha.0 - 2022-04-12
  • 4.19.5 - 2022-04-02
  • 4.19.5-alpha.0 - 2022-03-28
  • 4.19.4 - 2022-03-27
  • 4.19.3 - 2022-03-21
  • 4.19.2 - 2022-03-13
  • 4.19.1 - 2022-03-08
  • 4.19.1-alpha.0 - 2022-03-08
  • 4.19.0 - 2022-03-08
  • 4.18.9 - 2022-02-28
  • 4.18.8 - 2022-02-21
  • 4.18.7 - 2022-02-14
  • 4.18.6 - 2022-02-08
  • 4.18.5 - 2022-01-24
  • 4.18.4 - 2022-01-18
  • 4.18.3 - 2022-01-10
  • 4.18.2 - 2021-12-30
  • 4.18.1 - 2021-12-29
  • 4.18.0 - 2021-12-27
  • 4.17.4 - 2021-12-20
  • 4.17.3 - 2021-12-08
  • 4.17.2 - 2021-11-26
  • 4.17.1 - 2021-11-22
  • 4.17.1-alpha.1 - 2021-11-17
  • 4.17.1-alpha.0 - 2021-11-16
  • 4.17.0 - 2021-11-15
  • 4.17.0-alpha.10 - 2021-11-08
  • 4.17.0-alpha.9 - 2021-10-31
  • 4.17.0-alpha.8 - 2021-10-25
  • 4.17.0-alpha.7 - 2021-10-18
  • 4.17.0-alpha.6 - 2021-10-11
  • 4.17.0-alpha.5 - 2021-09-30
  • 4.17.0-alpha.4 - 2021-09-25
  • 4.17.0-alpha.3 - 2021-09-14
  • 4.17.0-alpha.2 - 2021-09-07
  • 4.17.0-alpha.1 - 2021-09-06
  • 4.17.0-alpha.0 - 2021-09-01
  • 4.16.13 - 2021-08-23
  • 4.16.12 - 2021-08-16
  • 4.16.11 - 2021-08-08
  • 4.16.10 - 2021-08-02
  • 4.16.9 - 2021-07-27
  • 4.16.8 - 2021-07-19
  • 4.16.7 - 2021-07-12
  • 4.16.6 - 2021-06-29
  • 4.16.5 - 2021-06-23
  • 4.16.3 - 2021-06-15
  • 4.16.2 - 2021-06-07
  • 4.16.1 - 2021-05-31
  • 4.16.0 - 2021-05-25
  • 4.16.0-alpha.2 - 2021-05-08
  • 4.16.0-alpha.1 - 2021-05-08
  • 4.16.0-alpha.0 - 2021-05-07
  • 4.15.6 - 2021-05-18
  • 4.15.5 - 2021-05-10
  • 4.15.4 - 2021-04-30
  • 4.15.3 - 2021-04-26
  • 4.15.3-alpha.0 - 2021-04-21
  • 4.15.2 - 2021-04-19
  • 4.15.1 - 2021-04-10
  • 4.15.0 - 2021-03-29
  • 4.14.1 - 2021-03-22
  • 4.14.0 - 2021-03-14
  • 4.13.1 - 2021-03-06
  • 4.13.0 - 2021-02-28
  • 4.12.3 - 2021-02-10
  • 4.12.2 - 2021-02-04
  • 4.12.1 - 2021-02-03
  • 4.12.0 - 2021-02-02
  • 4.11.3 - 2021-02-02
  • 4.11.2 - 2021-01-26
  • 4.11.1 - 2021-01-24
  • 4.11.0 - 2021-01-24
  • 4.10.3 - 2021-01-18
  • 4.10.2 - 2021-01-11
  • 4.10.1 - 2021-01-10
  • 4.10.0 - 2021-01-04
  • 4.9.4 - 2020-12-16
  • 4.9.3 - 2020-12-14
  • 4.9.2 - 2020-12-07
  • 4.9.1 - 2020-12-01
  • 4.9.0 - 2020-11-30
  • 4.8.6 - 2020-11-27
  • 4.8.5 - 2020-11-22
  • 4.8.4 - 2020-11-16
  • 4.8.3 - 2020-11-16
  • 4.8.2 - 2020-11-09
  • 4.8.1 - 2020-11-09
  • 4.8.0 - 2020-11-02
  • 4.7.3 - 2020-10-24
  • 4.7.2 - 2020-10-19
  • 4.7.1 - 2020-10-19
  • 4.7.0 - 2020-10-10
  • 4.6.6 - 2020-09-27
  • 4.6.5 - 2020-09-20
  • 4.6.4 - 2020-09-13
  • 4.6.3 - 2020-09-07
  • 4.6.2 - 2020-08-31
  • 4.6.1 - 2020-08-24
  • 4.6.0 - 2020-08-23
  • 4.5.4 - 2020-08-12
  • 4.5.3 - 2020-08-09
  • 4.5.2 - 2020-08-02
  • 4.5.1 - 2020-07-28
  • 4.5.0 - 2020-07-27
  • 4.4.3 - 2020-07-20
  • 4.4.2 - 2020-07-11
  • 4.4.1 - 2020-07-06
  • 4.4.0 - 2020-06-29
  • 4.3.5 - 2020-06-21
  • 4.3.4 - 2020-06-14
  • 4.3.3 - 2020-06-07
from antd GitHub release notes
Commit messages
Package name: antd
  • bc46d4b docs(:sparkles:): release 4.24.14 (#44653)
  • 09a6f3c test: update jest snapshot and fix type (#44652)
  • 843c4b6 fix(Breadcrumb): fix wrong overlay warning (#44578)
  • a556f1f fix: 4.x gif thumb url base64 type should be corrected (#44129)
  • 7251397 demo: update 4.x dropdown deprecated menu (#43825)
  • 1a7de4b fix: update rc-util version (#44043)
  • 0b6920b docs: 4.24.13 changelog (#43985)
  • a0cf986 fix: getCurrentLink not trigger when scroll (#43917)
  • 2b43f73 feat: @ ant-design/react-slick upgrade (#39634) (#43806)
  • c501af9 fix: fix lint for 4.x (#43807)
  • 53ce254 fix: select check remove icon align (#43667)
  • f92abac demo: fixed 4.x Modal render (#43696)
  • 2c6d565 fix: rethrow error in ActionButton's onOk callback (#43536)
  • e59016b fix: `ConfigProvider` form validateMessages nesting error (#43480)
  • f57c688 style: Checkbox should use @ border-radius-sm (#43356)
  • 2afbf67 docs: 4.24.12 changelog (#43293)
  • 67ff988 fix: Form should not trigger unnescessary onFieldsChange (#43292)
  • 9a4ee2e Update site-deploy.yml
  • 01f62b1 Update site-deploy.yml (#43243)
  • 2269b8e docs: changelog 4.24.11 (#43206)
  • 753510b refactor: ConfigProvider form dependency inversion for v4 (#43207)
  • 7cc23de fix: first open timepicker right panel position error (#43179)
  • 02f876f chore: pick upload patch (#43200)
  • 93a6ee1 fix: notification should hide close icon when closeIcon={null} (#42791)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@secure-code-warrior-for-github

Micro-Learning Topic: Regular expression denial of service (Detected by phrase)

Matched on "Regular Expression Denial of Service"

What is this? (2min video)

Denial of Service (DoS) attacks caused by Regular Expression which causes the system to hang or cause them to work very slowly when attacker sends a well-crafted input(exponentially related to input size).Denial of service attacks significantly degrade the service quality experienced by legitimate users. These attacks introduce large response delays, excessive losses, and service interruptions, resulting in direct impact on availability.

Try a challenge in Secure Code Warrior

Micro-Learning Topic: Denial of service (Detected by phrase)

Matched on "Denial of Service"

The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed. There are many ways to make a service unavailable for legitimate users by manipulating network packets, programming, logical, or resources handling vulnerabilities, among others. Source: https://www.owasp.org/index.php/Denial_of_Service

Try a challenge in Secure Code Warrior

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants