[Snyk] Upgrade sass from 1.26.3 to 1.63.6 #545
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade sass from 1.26.3 to 1.63.6.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3043105
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3043105
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-Y18N-1021887
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-INI-1048974
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-UAPARSERJS-1023599
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-UAPARSERJS-610226
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-Y18N-1021887
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-JSONSCHEMA-1920922
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1536531
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AJV-584908
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-ASYNC-2441827
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-ASYNC-2441827
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AWSSDK-1059424
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SEMVERREGEX-1584358
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SEMVERREGEX-1585624
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1579147
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1579152
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1579155
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TMPL-1583443
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-OBJECTPATH-1017036
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-OBJECTPATH-1585658
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3043105
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LODASH-1040724
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LODASH-567746
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MERGEDEEP-1070277
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SSRI-1246392
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SSRI-1246392
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1536528
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1536531
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1579147
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1579152
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1579155
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1536528
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AXIOS-1579269
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-DECODEURICOMPONENT-3149970
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-FINDPROCESS-1090284
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-PATHPARSE-1077067
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-PATHPARSE-1077067
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-POSTCSS-1090595
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-POSTCSS-1255640
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-POSTCSS-1090595
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-POSTCSS-1255640
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-PROMPTS-1729737
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-HIGHLIGHTJS-1048676
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-HOSTEDGITINFO-1088355
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-HTTPCACHESEMANTICS-3248783
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-ISTANBULREPORTS-2328088
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-UAPARSERJS-1072471
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-WS-1296835
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-WS-1296835
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-XML2JS-5414874
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-ACTIONSCORE-2980270
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-ALGOLIASEARCHHELPER-1570421
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SEMVERREGEX-1047770
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TERSER-2806366
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MINIMIST-559764
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-NODEFETCH-2342118
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-NODEFETCH-2342118
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-NODEFETCH-674311
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-NWSAPI-2841516
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-OBJECTPATH-1569453
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3042992
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LOADERUTILS-3105943
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-LODASH-1018905
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MINIMATCH-3050818
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-SEMVERREGEX-2824151
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-AXIOS-1038255
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-BROWSERSLIST-1090194
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-COOKIEJAR-3149984
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-ELLIPTIC-1064899
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-FLAT-596927
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-2332181
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1536758
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-TAR-1536758
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JS-FOLLOWREDIRECTS-2396346
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: sass
To install Sass 1.63.6, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.
Changes
JavaScript API
import sass from 'sass'
again after it was broken in the last release.Embedded Sass
exports
declaration inpackage.json
.See the full changelog for changes in earlier releases.
To install Sass 1.63.5, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.
Changes
JavaScript API
require()
and ESMimport
could crash on Node.js.Embedded Sass
Fix a deadlock when running at high concurrency on 32-bit systems.
Fix a race condition where the embedded compiler could deadlock or crash if a compilation ID was reused immediately after the compilation completed.
See the full changelog for changes in earlier releases.
To install Sass 1.63.4, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.
Changes
JavaScript API
Re-enable support for
import sass from 'sass'
when loading the package from an ESM module in Node.js. However, this syntax is now deprecated; ESM users should useimport * as sass from 'sass'
instead.On the browser and other ESM-only platforms, only
import * as sass from 'sass'
is supported.Properly export the legacy API values
TRUE
,FALSE
,NULL
, andtypes
from the ECMAScript module API.Embedded Sass
Fix a race condition where closing standard input while requests are in-flight could sometimes cause the process to hang rather than shutting down gracefully.
Properly include the root stylesheet's URL in the set of loaded URLs when it fails to parse.
See the full changelog for changes in earlier releases.
To install Sass 1.63.3, download one of the packages below and add it to your PATH, or see the Sass website for full installation instructions.
Changes
JavaScript API
See the full changelog for changes in earlier releases.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs