Skip to content

Comments

[Snyk] Security upgrade i18next-parser from 9.3.0 to 9.4.0#471

Open
patternfly-build wants to merge 1 commit intomainfrom
snyk-fix-5f90e0cbea278007438e3e537d3b2955
Open

[Snyk] Security upgrade i18next-parser from 9.3.0 to 9.4.0#471
patternfly-build wants to merge 1 commit intomainfrom
snyk-fix-5f90e0cbea278007438e3e537d3b2955

Conversation

@patternfly-build
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 5 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • packages/dev/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-15309438
  710  
medium severity Prototype Pollution
SNYK-JS-JSYAML-13961110
  645  
high severity Regular Expression Denial of Service (ReDoS)
npm:underscore.string:20170908
  525  
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-UNDICI-14943963
  415  
low severity Missing Release of Memory after Effective Lifetime
SNYK-JS-UNDICI-10176064
  340  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Missing Release of Memory after Effective Lifetime
🦉 More lessons are available in Snyk Learn

@netlify
Copy link

netlify bot commented Feb 23, 2026

Deploy Preview for quickstarts failed.

Name Link
🔨 Latest commit 165b849
🔍 Latest deploy log https://app.netlify.com/projects/quickstarts/deploys/699c0a4f4693880008d4c261

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants