-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk] Upgrade: gatsby, gatsby-plugin-manifest, gatsby-plugin-sharp, gatsby-source-wordpress, gatsby-transformer-sharp #511
base: master
Are you sure you want to change the base?
Conversation
Snyk has created this PR to upgrade: - gatsby from 5.0.0 to 5.13.2. See this package in npm: https://www.npmjs.com/package/gatsby - gatsby-plugin-manifest from 5.0.0 to 5.13.1. See this package in npm: https://www.npmjs.com/package/gatsby-plugin-manifest - gatsby-plugin-sharp from 5.0.0 to 5.13.1. See this package in npm: https://www.npmjs.com/package/gatsby-plugin-sharp - gatsby-source-wordpress from 7.0.0 to 7.13.2. See this package in npm: https://www.npmjs.com/package/gatsby-source-wordpress - gatsby-transformer-sharp from 5.0.0 to 5.13.1. See this package in npm: https://www.npmjs.com/package/gatsby-transformer-sharp See this project in Snyk: https://app.snyk.io/org/sammytezzy/project/20794044-5f49-41de-a492-223de49c2642?utm_source=github&utm_medium=referral&page=upgrade-pr
Run & review this pull request in StackBlitz Codeflow. |
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
PR Type: Enhancement
PR Summary: This pull request updates several key Gatsby dependencies to newer versions, including gatsby, gatsby-plugin-manifest, gatsby-plugin-sharp, gatsby-source-wordpress, and gatsby-transformer-sharp. These updates bring the project up to date with the latest features, performance improvements, and bug fixes provided by the Gatsby framework and its plugins.
Decision: Comment
📝 Type: 'Enhancement' - not supported yet.
- Sourcery currently only approves 'Typo fix' PRs.
✅ Issue addressed: this change correctly addresses the issue or implements the desired feature.
No details provided.
✅ Small diff: the diff is small enough to approve with confidence.
No details provided.
General suggestions:
- Ensure comprehensive testing is conducted, particularly focusing on the areas affected by the updated plugins such as image processing, PWA manifest generation, and WordPress data sourcing. This will help in identifying any potential issues arising from the updates.
- Consider reviewing the release notes of each updated package for a detailed understanding of the changes. This can provide insights into new features or adjustments that might benefit the project further or require specific attention.
- After updating and testing, monitor the application's performance metrics closely. The updates, especially to gatsby-plugin-sharp and gatsby-transformer-sharp, could impact build times and runtime performance.
Thanks for using Sourcery. We offer it for free for open source projects and would be very grateful if you could help us grow. If you like it, would you consider sharing Sourcery on your favourite social media? ✨
"gatsby-plugin-sharp": "^5.0.0", | ||
"gatsby-source-wordpress": "^7.0.0", | ||
"gatsby-transformer-sharp": "^5.0.0", | ||
"gatsby-plugin-manifest": "^5.13.1", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
suggestion (llm): The update to gatsby-plugin-manifest to version 5.13.1 should improve PWA support. It's good practice to verify the generated manifest file to ensure all configurations are correctly applied.
"gatsby-plugin-manifest": "^5.13.1", | ||
"gatsby-plugin-sharp": "^5.13.1", | ||
"gatsby-source-wordpress": "^7.13.2", | ||
"gatsby-transformer-sharp": "^5.13.1", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
suggestion (llm): The update to gatsby-transformer-sharp to version 5.13.1 should enhance image processing capabilities. It's important to check the build times and the quality of the generated images, especially if you're using advanced image processing features.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
from 5.0.0 to 5.13.2
on 2024-01-23
from 5.0.0 to 5.13.1
on 2024-01-23
from 5.0.0 to 5.13.1
on 2024-01-23
from 7.0.0 to 7.13.2
on 2024-01-23
from 5.0.0 to 5.13.1
on 2024-01-23
The recommended version fixes:
SNYK-JS-LOADERUTILS-3043105
Why? CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? CVSS 7.5
SNYK-JS-DECODEURICOMPONENT-3149970
Why? CVSS 7.5
SNYK-JS-ENGINEIO-3136336
Why? CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-6141137
Why? CVSS 7.5
SNYK-JS-IMMER-1019369
Why? CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? CVSS 7.5
SNYK-JS-SEMVER-3247795
Why? CVSS 7.5
SNYK-JS-SOCKETIOPARSER-5596892
Why? CVSS 7.5
SNYK-JS-WEBPACK-3358798
Why? CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? CVSS 7.5
SNYK-JS-MSGPACKR-6140431
Why? CVSS 7.5
SNYK-JS-POSTCSS-5926692
Why? CVSS 7.5
SNYK-JS-GATSBY-5671647
Why? CVSS 7.5
SNYK-JS-GATSBYCLI-5671903
Why? CVSS 7.5
SNYK-JS-GATSBYPLUGINSHARP-5425803
Why? CVSS 7.5
SNYK-JS-GATSBYPLUGINSHARP-5671648
Why? CVSS 7.5
SNYK-JS-GRAPHQL-5905181
Why? CVSS 7.5
SNYK-JS-HTTPCACHESEMANTICS-3248783
Why? CVSS 7.5
SNYK-JS-IMMER-1540542
Why? CVSS 7.5
SNYK-JS-JSON5-3182856
Why? CVSS 7.5
SNYK-JS-WORDWRAP-3149973
Why? CVSS 7.5
SNYK-JS-BABELTRAVERSE-5962462
Why? CVSS 7.5
SNYK-JS-JSON5-3182856
Why? CVSS 7.5
SNYK-JS-SHARP-5922108
Why? CVSS 7.5
SNYK-JS-SIDEWAYFORMULA-3317169
Why? CVSS 7.5
SNYK-JS-UAPARSERJS-3244450
Why? CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: gatsby
gatsby-transformer-yaml@5.13.1
Package name: gatsby-plugin-manifest
gatsby-transformer-yaml@5.13.1
Package name: gatsby-plugin-sharp
gatsby-transformer-yaml@5.13.1
Package name: gatsby-source-wordpress
Package name: gatsby-transformer-sharp
gatsby-transformer-yaml@5.13.1
Commit messages
Package name: gatsby
node:
onbuild-html
gatsbyjs/gatsby#38516) (fix(gatsby): support builtin modules prefixed withnode:
onbuild-html
(#38516) gatsbyjs/gatsby#38818)Compare
Package name: gatsby-plugin-manifest
node:
onbuild-html
gatsbyjs/gatsby#38516) (fix(gatsby): support builtin modules prefixed withnode:
onbuild-html
(#38516) gatsbyjs/gatsby#38818)Compare
Package name: gatsby-plugin-sharp
node:
onbuild-html
gatsbyjs/gatsby#38516) (fix(gatsby): support builtin modules prefixed withnode:
onbuild-html
(#38516) gatsbyjs/gatsby#38818)Compare
Package name: gatsby-source-wordpress
node:
onbuild-html
gatsbyjs/gatsby#38516) (fix(gatsby): support builtin modules prefixed withnode:
onbuild-html
(#38516) gatsbyjs/gatsby#38818)Compare
Package name: gatsby-transformer-sharp
node:
onbuild-html
gatsbyjs/gatsby#38516) (fix(gatsby): support builtin modules prefixed withnode:
onbuild-html
(#38516) gatsbyjs/gatsby#38818)Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs