[Snyk] Upgrade uswds from 2.13.3 to 2.14.0 #431
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade uswds from 2.13.3 to 2.14.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
Release notes
Package name: uswds
Long-term archive of Version 2
As we noted when we released Version 3.0, we will support Version 2 through May 2023. As a part of our long-term archive support for Version 2.x, we're releasing USWDS 2.14.0. This release has no functional changes, but it strips all nonessential development dependencies from the codebase. This will allow both the design system and long-term users of 2.x to treat this and any subsequent 2.x release as a long-term archival release, with a limited security vulnerability footprint.
If you use USWDS 2.13.3 and will not be upgrading to 3.0, consider updating to USWDS 2.14.0.
Details
This release removes all dependencies, except those required to build and release. There were no vulnerabilities in the standard dependencies, but there were critical vulnerabilities in a few development dependencies:
@ frctl/fractal
@ frctl/mandelbrot
@ frctl/nunjucks
mocha
gulp-spawn-mocha
nswatch
: Legacy watch task, wasn't used.gulp-svg-sprite
: Added compiled SVG to repo.handlebars
andhandlebars-helpers
: Used in generating formatted tokensin SASS
We removed all these dependencies and committed any necessary static assets to the package. We've committed an archival version of the Fractal site in GitHub, but it is not included in the package.
Finally, we added an
overrides
field topackage.json
to handle the last remaining vulnerability ingulp
.Security and dependencies
overrides
0
vulnerabilities in regular dependencies (dependencies for USWDS projects installed with npm install uswds) fromnpm audit
Internal only:
0
vulnerabilities in devDependencies (development dependencies) fromnpm audit
Release ZIP SHA-256 hash:
8fb2fc84bcb73f3e7155fcacd35b2f96ae3be872716a91118b69991c6e0bb44b
Commit messages
Package name: uswds
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs