[Snyk] Upgrade: bootstrap, countup.js, jquery, jquery-ui, jquery-waypoints #1767
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
bootstrap
from 4.3.1 to 4.6.2 | 9 versions ahead of your current version | 2 years ago
on 2022-07-19
countup.js
from 2.0.7 to 2.8.0 | 15 versions ahead of your current version | a year ago
on 2023-08-25
jquery
from 3.6.0 to 3.7.1 | 6 versions ahead of your current version | a year ago
on 2023-08-28
jquery-ui
from 1.12.1 to 1.14.0 | 11 versions ahead of your current version | 2 months ago
on 2024-08-05
jquery-waypoints
from 2.0.3 to 2.0.5 | 1 version ahead of your current version | 8 years ago
on 2016-05-02
Issues fixed by the recommended upgrade:
SNYK-JS-JQUERYUI-1767167
SNYK-JS-JQUERYUI-1767175
SNYK-JS-JQUERYUI-1767767
SNYK-JS-JQUERYUI-2946728
Release notes
Package name: bootstrap
-
4.6.2 - 2022-07-19
- Added an example to our Collapse plugin docs to show how to use horizontal collapsing. This has long been possible via our JS, but we never had an official class to utilize it.
- We've replaced the deprecated
- Tweaked the size of
- Improved accessibility around our dropdowns, color contrast, and
- Fixed some broken links to supporting documentation.
- Updated dependencies across the board.
- Removed blurred background reference from the Toast Docs. by @ pricop in #35190
- Update links to CCA, MQ5 prefers-reduced-motion, evergreen WCAG urls, more resources by @ patrickhlauke in #35427
- v4-dev backports and updates by @ XhmikosR in #35482
- Backport #35556 by @ julien-deramond in #35558
- Tweak toast docs by @ patrickhlauke in #35633
- v4-dev backports and updates by @ XhmikosR in #35642
- Doc: Reorder alphabetically lists of components by @ julien-deramond in #36128
- Updated the small-font-size to use a round value by @ pricop in #36172
- v4 dev backports and updates by @ XhmikosR in #35767
- _custom-forms.scss: fix order of attributes by @ twin-elements in #36231
- Replace the deprecated
- [v4] Doc: remove
- Dynamic tabs: use buttons rather than links (backport to v4) by @ patrickhlauke in #33163
- v4 dev updates by @ XhmikosR in #36430
- Fix closing HTML tag in navs docs by @ julien-deramond in #36466
- v4: Horizontal collapse by @ mdo in #36434
- Fixing tabs' tests v4 by @ louismaximepiton in #36485
- Docs: fix some ARIA Authoring Practices Guides broken links by @ julien-deramond in #36490
- v4 - Remove confusing unnecessary id/aria-labelledby for dropdown menus by @ patrickhlauke in #36491
- v4 Docs: outdated ARIA/PF link, expand contrast explanation in
- v4: Improve accessible name of version dropdown in docs navbar by @ patrickhlauke in #36504
- Update devDependencies by @ XhmikosR in #36522
- Docs: update clipboard.js to v2.0.11 by @ julien-deramond in #36631
- Update devDependencies by @ XhmikosR in #36724
- v4: Add Fathom by @ mdo in #36727
- Docs: Capitalize Unicode by @ julien-deramond in #36735
- Release v4.6.2 by @ XhmikosR in #36725
- @ twin-elements made their first contribution in #36231
- @ AdrianCurtin made their first contribution in #36283
-
4.6.1 - 2021-10-28
- Replace Sass division with multiplication and custom
- Update RFS to v8.1.0 by @ XhmikosR in #34571
- fix(forms): input-group and validation icons by @ ffoodd in #32968
- Fix minor visual bug in Firefox caused by
- Adjust
- Add
- Adjust feedback icon position and padding for
- Carousel: use buttons, not links, for prev/next controls by @ patrickhlauke in #33165
- v4: Sass docs for default variables by @ mdo in #33392
- Handle complex expressions in
- More concise improvements for
- Remove
- Dropdown: support
- Update Node versions in JS tests (drop Node 10, add Node 16), update docs JS assets and add variables for
- Replace Freenode with Libera IRC server by @ midzer #34050
- Fix repetition in the Navbar docs description by @ coliff in #34208
- Enable
- Remove print
- Fix prevented
- Input group validation with custom-file input by @ ffoodd in #33239
- Add eslint-plugin-qunit and tighten JS tests by @ XhmikosR in #32270
- Update our tests to Node 16 and npm 8 by @ XhmikosR in #35142
- Disabled link cleanup by @ patrickhlauke in #34924
- Updated our devDependencies including terser; also enabled two passes for terser by @ XhmikosR
-
4.6.0 - 2021-01-19
-
4.5.3 - 2020-10-13
-
4.5.2 - 2020-08-06
-
4.5.1 - 2020-08-04
-
4.5.0 - 2020-05-12
-
4.4.1 - 2019-11-28
-
4.4.0 - 2019-11-26
-
4.3.1 - 2019-02-13
from bootstrap GitHub release notesHighlights
color-adjustwithprint-color-adjustin our Sass files as part of the Autoprefixer v10.4.6 issues. This should quiet the issues folks have seen from that dependency change. If you're using our distribution CSS files, likebootstrap.min.css, you may still see the warning.smalland.smallto compute to a whole pixel value (was12.8pxand now is14px).roleattributes.What's Changed
color-adjustwithprint-color-adjustby @ AdrianCurtin in #36283role="group"from some split drop* buttons by @ julien-deramond in #36254accessibility.mdby @ patrickhlauke in #36492New Contributors
Full Changelog: v4.6.1...v4.6.2
What's changed
divide()function by @ mdo in #34571moz-focusringby @ kremit in #32821SAFE_URL_PATTERNregex for use with test method of regexes by @ nikonthethird in #33153smsin theSAFE_URL_PATTERNfor sanitizer by @ XhmikosR in #35074select.form-controlby @ mdo in #33206add()&subtract()by @ ffoodd in #34047add()andsubtract()by @ ffoodd in #34432aria-haspopupfrom dropdowns by @ patrickhlauke in #33624.dropdown-itemwrapped in<li>tags by @ cpsievert in #33649vertical-alignin spinners by @ XhmikosR in #338070.xwith negative margins in utilities by @ k-utsumi in #33593theadrule by @ coliff in #34426showevent disabling modals with fade class from being displayed again by @ alpadev in #34087Full changelog
v4.6.0...v4.6.1
Package name: countup.js
-
2.8.0 - 2023-08-25
-
2.7.1 - 2023-08-15
-
2.7.0 - 2023-06-28
-
2.6.2 - 2023-05-01
-
2.6.1 - 2023-04-30
-
2.6.0 - 2023-03-13
-
2.5.0 - 2023-03-01
-
2.4.2 - 2023-01-28
-
2.4.1 - 2023-01-24
- Added Indian separators option
- Added null check in
-
2.3.2 - 2022-07-08
-
2.3.1 - 2022-06-29
-
2.3.0 - 2022-06-27
-
2.2.0 - 2022-05-18
-
2.1.0 - 2022-03-02
-
2.0.8 - 2021-07-27
-
2.0.7 - 2020-08-25
from countup.js GitHub release notesAdded
onStartCallbackoption, useful for when scroll spy is enabled, thanks to @ cherrol !Reverted change which made "main" in package.json point to the module file, instead of the umd file. It now points again at the umd file.
When revamping the build, I tried to resolve a rollup warning that had been occurring on the build for a long time:
It occurs because of typescript's Object.assign polyfill, which uses
thison the global scope. If you setcontext: 'window'in the rollup config, it will silence the warning, but it will cause issues if CountUp is not run in the browser. Allowing rollup to rewrite this to undefined on just the global scope is harmless and doesn't break anything, so I reverted the change.This release doesn't change the CountUp code at all, just the distribution files - The requestAnimationFrame polyfill is no longer bundled with CountUp but served separately. The other files in dist remain the same. More details in the PR: #311
Support animation plugins: A plugin is a class instance or object passed in options for the
pluginparam that implements a render method:The plugin's render method will be called on each frame to display the formatted value instead of CountUp's.
Added new option,
onCompleteCallbackwhich gets called when the animation completes. You can still pass a callback to the start method, and it will override whatever is passed in the options.Make it so when scroll spy is enabled, and
scrollSpyOnceis false, CountUp will re-animate when scrolling up, as well as down, thanks to @ paidgeuseIndianSeparatorswhich will format a number like "1,00,000" instead of "100,000"printValuemethod to potentially fix react issueFixes #287 which was a bug where, when using smart easing and counting down, the animation would take longer than configured. It also fixed an issue which caused 2 easing cycles to run for the same scenario.
Fix window check for SSR, thanks to @ johakr
Package name: jquery
-
3.7.1 - 2023-08-28
-
3.7.0 - 2023-05-11
-
3.6.4 - 2023-03-08
-
3.6.3 - 2022-12-20
-
3.6.2 - 2022-12-13
-
3.6.1 - 2022-08-26
-
3.6.0 - 2021-03-02
from jquery GitHub release noteshttps://blog.jquery.com/2023/08/28/jquery-3-7-1-released-reliable-table-row-dimensions/
https://blog.jquery.com/2023/05/11/jquery-3-7-0-released-staying-in-order/
https://blog.jquery.com/2023/03/08/jquery-3-6-4-released-selector-forgiveness/
https://blog.jquery.com/2022/12/20/jquery-3-6-3-released-a-quick-selector-fix/
https://blog.jquery.com/2022/12/13/jquery-3-6-2-released/
https://blog.jquery.com/2022/08/26/jquery-3-6-1-maintenance-release/
https://blog.jquery.com/2021/03/02/jquery-3-6-0-released/
Package name: jquery-ui
-
1.14.0 - 2024-08-05
-
1.14.0-beta.2 - 2024-06-14
-
1.14.0-beta.1 - 2024-05-15
-
1.13.3 - 2024-04-26
-
1.13.2 - 2022-07-14
-
1.13.1 - 2022-01-20
-
1.13.0 - 2021-10-07
-
1.13.0-rc.3 - 2021-09-25
-
1.13.0-rc.2 - 2021-09-03
-
1.13.0-rc.1 - 2021-09-02
-
1.13.0-alpha.1 - 2021-08-06
-
1.12.1 - 2016-09-14
from jquery-ui GitHub release noteshttps://blog.jqueryui.com/2024/08/jquery-ui-1-14-0-released/
1.14.0-beta.2
1.14.0-beta.1
https://blog.jqueryui.com/2024/04/jquery-ui-1-13-3-released/
https://blog.jqueryui.com/2022/07/jquery-ui-1-13-2-released/
https://blog.jqueryui.com/2022/01/jquery-ui-1-13-1-released/
https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/
1.13.0-rc.3
1.13.0-rc.2
1.13.0-rc.1
Package name: jquery-waypoints
-
2.0.5 - 2016-05-02
-
2.0.3 - 2016-04-09
from jquery-waypoints GitHub release notesRestore jquery-waypoints bower install
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: