[Snyk] Upgrade posthog-js from 1.111.0 to 1.116.6 #1044

Closed
opened 2026-04-05 16:25:05 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 4/15/2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade posthog-js from 1.111.0 to 1.116.6.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 23 versions ahead of your current version.
  • The recommended version was released 21 days ago, on 2024-03-25.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
432/1000
Why? Proof of Concept exploit, CVSS 6.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: posthog-js
  • 1.116.6 - 2024-03-25

    1.116.6 - 2024-03-25

    • fix: Reloading toolbar after closing (#1095)
  • 1.116.5 - 2024-03-23

    1.116.5 - 2024-03-23

    • fix: posthog init should reject invalid config in TypeScript (#1097)
  • 1.116.4 - 2024-03-22

    1.116.4 - 2024-03-22

    • fix: custom event on sampling decision (#1094)
    • feat: signal we have wrapped fetch (#1083)
  • 1.116.3 - 2024-03-20

    1.116.3 - 2024-03-20

    • fix: Return this if already loaded (#1092)
  • 1.116.2 - 2024-03-18

    1.116.2 - 2024-03-18

    • feat: add property so we can check if a client is using a proxy (#1084)
  • 1.116.1 - 2024-03-18

    1.116.1 - 2024-03-18

    • chore: Remove v2 rrweb checks (#1080)
  • 1.116.0 - 2024-03-15

    1.116.0 - 2024-03-15

    • fix: allow payload scrubbing override (#1085)
  • 1.115.2 - 2024-03-15

    1.115.2 - 2024-03-15

    • fix: canvas recording patches (#1082)
    • chore: remove cypress log noise (#1086)
  • 1.115.1 - 2024-03-15

    1.115.1 - 2024-03-15

    • chore: remove v1 rrweb loading (#1078)
  • 1.115.0 - 2024-03-14

    1.115.0 - 2024-03-14

    • feat: track recording URL without pageview capture (#1076)
    • fix: return typing of global functions (#1081)
  • 1.114.2 - 2024-03-12
  • 1.114.1 - 2024-03-12
  • 1.114.0 - 2024-03-12
  • 1.113.4 - 2024-03-12
  • 1.113.3 - 2024-03-12
  • 1.113.2 - 2024-03-11
  • 1.113.1 - 2024-03-11
  • 1.113.0 - 2024-03-11
  • 1.112.1 - 2024-03-11
  • 1.112.0 - 2024-03-08
  • 1.111.3 - 2024-03-07
  • 1.111.2 - 2024-03-06
  • 1.111.1 - 2024-03-06
  • 1.111.0 - 2024-03-05
from posthog-js GitHub release notes
Commit messages
Package name: posthog-js

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

*Originally created by @simlarsen on 4/15/2024* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to upgrade posthog-js from 1.111.0 to 1.116.6.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **23 versions** ahead of your current version. - The recommended version was released **21 days ago**, on 2024-03-25. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- <img src="https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png" width="20" height="20" title="medium severity"/> | Information Exposure<br/> [SNYK-JS-FOLLOWREDIRECTS-6444610](https://snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6444610) | **432/1000** <br/> **Why?** Proof of Concept exploit, CVSS 6.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>posthog-js</b></summary> <ul> <li> <b>1.116.6</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.116.6">2024-03-25</a></br><h2>1.116.6 - 2024-03-25</h2> <ul> <li>fix: Reloading toolbar after closing (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2202243787" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1095" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1095/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1095">#1095</a>)</li> </ul> </li> <li> <b>1.116.5</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.116.5">2024-03-23</a></br><h2>1.116.5 - 2024-03-23</h2> <ul> <li>fix: posthog init should reject invalid config in TypeScript (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2203989178" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1097" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1097/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1097">#1097</a>)</li> </ul> </li> <li> <b>1.116.4</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.116.4">2024-03-22</a></br><h2>1.116.4 - 2024-03-22</h2> <ul> <li>fix: custom event on sampling decision (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2202206773" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1094" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1094/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1094">#1094</a>)</li> <li>feat: signal we have wrapped fetch (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2187204380" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1083" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1083/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1083">#1083</a>)</li> </ul> </li> <li> <b>1.116.3</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.116.3">2024-03-20</a></br><h2>1.116.3 - 2024-03-20</h2> <ul> <li>fix: Return this if already loaded (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2197505833" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1092" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1092/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1092">#1092</a>)</li> </ul> </li> <li> <b>1.116.2</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.116.2">2024-03-18</a></br><h2>1.116.2 - 2024-03-18</h2> <ul> <li>feat: add property so we can check if a client is using a proxy (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2187457413" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1084" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1084/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1084">#1084</a>)</li> </ul> </li> <li> <b>1.116.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.116.1">2024-03-18</a></br><h2>1.116.1 - 2024-03-18</h2> <ul> <li>chore: Remove v2 rrweb checks (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2185734987" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1080" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1080/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1080">#1080</a>)</li> </ul> </li> <li> <b>1.116.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.116.0">2024-03-15</a></br><h2>1.116.0 - 2024-03-15</h2> <ul> <li>fix: allow payload scrubbing override (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2188270378" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1085" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1085/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1085">#1085</a>)</li> </ul> </li> <li> <b>1.115.2</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.115.2">2024-03-15</a></br><h2>1.115.2 - 2024-03-15</h2> <ul> <li>fix: canvas recording patches (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2186867014" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1082" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1082/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1082">#1082</a>)</li> <li>chore: remove cypress log noise (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2188456178" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1086" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1086/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1086">#1086</a>)</li> </ul> </li> <li> <b>1.115.1</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.115.1">2024-03-15</a></br><h2>1.115.1 - 2024-03-15</h2> <ul> <li>chore: remove v1 rrweb loading (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2184397997" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1078" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1078/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1078">#1078</a>)</li> </ul> </li> <li> <b>1.115.0</b> - <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases/tag/v1.115.0">2024-03-14</a></br><h2>1.115.0 - 2024-03-14</h2> <ul> <li>feat: track recording URL without pageview capture (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2182652454" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1076" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1076/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1076">#1076</a>)</li> <li>fix: return typing of global functions (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2185968908" data-permission-text="Title is private" data-url="https://github.com/PostHog/posthog-js/issues/1081" data-hovercard-type="pull_request" data-hovercard-url="/PostHog/posthog-js/pull/1081/hovercard" href="https://snyk.io/redirect/github/PostHog/posthog-js/pull/1081">#1081</a>)</li> </ul> </li> <li> <b>1.114.2</b> - 2024-03-12 </li> <li> <b>1.114.1</b> - 2024-03-12 </li> <li> <b>1.114.0</b> - 2024-03-12 </li> <li> <b>1.113.4</b> - 2024-03-12 </li> <li> <b>1.113.3</b> - 2024-03-12 </li> <li> <b>1.113.2</b> - 2024-03-11 </li> <li> <b>1.113.1</b> - 2024-03-11 </li> <li> <b>1.113.0</b> - 2024-03-11 </li> <li> <b>1.112.1</b> - 2024-03-11 </li> <li> <b>1.112.0</b> - 2024-03-08 </li> <li> <b>1.111.3</b> - 2024-03-07 </li> <li> <b>1.111.2</b> - 2024-03-06 </li> <li> <b>1.111.1</b> - 2024-03-06 </li> <li> <b>1.111.0</b> - 2024-03-05 </li> </ul> from <a href="https://snyk.io/redirect/github/PostHog/posthog-js/releases">posthog-js GitHub release notes</a> </details> </details> <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>posthog-js</b></summary> <ul> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/174f83b5b9b3b150ba8c099511552380fa5b7e0d">174f83b</a> chore: Bump version to 1.116.6</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/b5f783c1a0906190d6c956e1771339a1cd7266f2">b5f783c</a> fix: Reloading toolbar after closing (#1095)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/f1771a02fe78e805bdc49e5fa88390d29bebb143">f1771a0</a> chore: Bump version to 1.116.5</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/3f6f5507b90a2788070535f729e553eca9569dbb">3f6f550</a> fix: posthog init should reject invalid config in TypeScript (#1097)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/d6280fb9cefb0a09cef7bc717d0951105ed7b6c0">d6280fb</a> chore: Bump version to 1.116.4</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/d80af4cff2ac515e7850ec99ec607ddf89833a56">d80af4c</a> fix: custom event on sampling decision (#1094)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/123bd01838734281ff198a5aaca6ec9cbccc4db0">123bd01</a> feat: signal we have wrapped fetch (#1083)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/77148cbec812da48138aa1fb48784d63ddb760b9">77148cb</a> chore: Bump version to 1.116.3</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/6fd350de4816ccb462439c56a7d240c7cab47f85">6fd350d</a> fix: Return this if already loaded (#1092)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/8e4eef23a34866f8fa0b3a0e71f766cb0ca2c1d6">8e4eef2</a> chore: Bump version to 1.116.2</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/e0d080114589ece0996257fd324c92ce95f62910">e0d0801</a> feat: add property so we can check if a client is using a proxy (#1084)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/5b3c1d33753af6a82bcacb48030650fcc95d1b57">5b3c1d3</a> chore: Bump version to 1.116.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/0e1bc8cf14f3ced4158c14b061ce38f086a2dc83">0e1bc8c</a> chore: Remove v2 rrweb checks (#1080)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/ec6fb944c466ac39bad2a21ac6eb39c4e904b53e">ec6fb94</a> chore: Bump version to 1.116.0</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/7ceed28cd913764f19c402a5b452f289a2e1a4e2">7ceed28</a> fix: allow payload scrubbing override (#1085)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/bf605f91b1e1ffc36e622f05a2c4b19fdf59ad82">bf605f9</a> chore: Bump version to 1.115.2</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/7dbde87fabd0ed56258d14a9089028104a33aeef">7dbde87</a> fix: canvas recording patches (#1082)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/59ac3f27cd361e7d38ae35e0a67ae1f789db4bc4">59ac3f2</a> chore: remove cypress log noise (#1086)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/9df1369f3bd4a3b9936c1f20817ec5d8b7bc6a01">9df1369</a> chore: Bump version to 1.115.1</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/b40a9681268be7dc86fb77133dac78b0990a044d">b40a968</a> chore: remove v1 rrweb loading (#1078)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/b635a77f5dd9032cb51a32993e6c081df02359b0">b635a77</a> chore: Bump version to 1.115.0</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/cdb1fb9b921fcc590dea77a9f20dcc9ca4e3e2da">cdb1fb9</a> feat: track recording URL without pageview capture (#1076)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/f6442ef59c3c4858ffb8b50fa7263e4e997533b8">f6442ef</a> fix: return typing of global functions (#1081)</li> <li><a href="https://snyk.io/redirect/github/PostHog/posthog-js/commit/18479b4ff36b709fc05c970ce392c23b1732381a">18479b4</a> chore: Bump version to 1.114.2</li> </ul> <a href="https://snyk.io/redirect/github/PostHog/posthog-js/compare/7c236692be8426d50ccc07ef21bcb4eac9d4232d...174f83b5b9b3b150ba8c099511552380fa5b7e0d">Compare</a> </details> </details> <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIwZjc5YTJjZC1mZDg2LTRmMzgtOGNiYy1mYjFiMzZkMGIyNjAiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjBmNzlhMmNkLWZkODYtNGYzOC04Y2JjLWZiMWIzNmQwYjI2MCJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213/settings/integration?pkg&#x3D;posthog-js&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"0f79a2cd-fd86-4f38-8cbc-fb1b36d0b260","prPublicId":"0f79a2cd-fd86-4f38-8cbc-fb1b36d0b260","dependencies":[{"name":"posthog-js","from":"1.111.0","to":"1.116.6"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/f6446ec8-d441-487e-b58f-38373430e213?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"f6446ec8-d441-487e-b58f-38373430e213","env":"prod","prType":"upgrade","vulns":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"issuesToFix":[{"issueId":"SNYK-JS-FOLLOWREDIRECTS-6444610","severity":"medium","title":"Information Exposure","exploitMaturity":"proof-of-concept","priorityScore":432,"priorityScoreFactors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}]}],"upgrade":["SNYK-JS-FOLLOWREDIRECTS-6444610"],"upgradeInfo":{"versionsDiff":23,"publishedDate":"2024-03-25T09:33:44.705Z"},"templateVariants":["priorityScore"],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[432]}) --->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1044