[Snyk] Upgrade @fortawesome/react-fontawesome from 0.1.19 to 0.2.0 #1428

Closed
opened 2026-04-05 16:27:19 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 11/24/2023

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade @fortawesome/react-fontawesome from 0.1.19 to 0.2.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.
  • The recommended version was released a year ago, on 2022-06-29.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @fortawesome/react-fontawesome
  • 0.2.0 - 2022-06-29

    Added

    • Support for React forwardRef if using React >= 16.3
  • 0.1.19 - 2022-06-29

    Fixed

    • Added missing beatFade, spinPulse, and spinReverse animations
from @fortawesome/react-fontawesome GitHub release notes
Commit messages
Package name: @fortawesome/react-fontawesome
  • f3585b7 Adjust CI to include FA deps in matrix
  • 295baab Removing React 16.2 as it's no longer supported
  • de58148 Update tag for release
  • e32a0cb Use forwardRef rather than custom `forwardedRef` prop (#503)
  • 6e1663b Fix a few missing animations (#516)
  • c28e82b Deps updates
  • c86b4e6 Deps updates from npm audit
  • fd719e8 Bump async from 2.6.3 to 2.6.4 in /examples/create-react-app (#507)
  • 11e4cea Bump minimist in /examples/create-react-app-typescript (#513)
  • f3005cd Bump async from 2.6.3 to 2.6.4 in /examples/create-react-app-typescript (#514)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

*Originally created by @simlarsen on 11/24/2023* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to upgrade @fortawesome/react-fontawesome from 0.1.19 to 0.2.0.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **1 version** ahead of your current version. - The recommended version was released **a year ago**, on 2022-06-29. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- <img src="https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png" width="20" height="20" title="high severity"/> | Regular Expression Denial of Service (ReDoS)<br/> [SNYK-JS-SEMVER-3247795](https://snyk.io/vuln/SNYK-JS-SEMVER-3247795) | **482/1000** <br/> **Why?** Proof of Concept exploit, CVSS 7.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>@fortawesome/react-fontawesome</b></summary> <ul> <li> <b>0.2.0</b> - <a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/releases/tag/0.2.0">2022-06-29</a></br><h3>Added</h3> <ul> <li>Support for React forwardRef if using React &gt;= 16.3</li> </ul> </li> <li> <b>0.1.19</b> - <a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/releases/tag/0.1.19">2022-06-29</a></br><h3>Fixed</h3> <ul> <li>Added missing beatFade, spinPulse, and spinReverse animations</li> </ul> </li> </ul> from <a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/releases">@fortawesome/react-fontawesome GitHub release notes</a> </details> </details> <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>@fortawesome/react-fontawesome</b></summary> <ul> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/f3585b7c0996d0011808b5a877d34de6221b8987">f3585b7</a> Adjust CI to include FA deps in matrix</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/295baabe9ecb21e9644a7d10119fbcf44fdcff9b">295baab</a> Removing React 16.2 as it&#x27;s no longer supported</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/de58148f282bd0a4f9dc03b216386eb81f45ff78">de58148</a> Update tag for release</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/e32a0cbc2d3c944e6cdc6d63d32ca1e275de6e43">e32a0cb</a> Use forwardRef rather than custom &#x60;forwardedRef&#x60; prop (#503)</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/6e1663b769e01bd236f9bae4f4979627e868edc1">6e1663b</a> Fix a few missing animations (#516)</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/c28e82b95da33126e69b2b5d3d6ba9d2350ef3f3">c28e82b</a> Deps updates</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/c86b4e633a058fa4bfd857fbb2789e80187c1f30">c86b4e6</a> Deps updates from npm audit</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/fd719e87237793ed8c8de9647d53c5b1bf64e90a">fd719e8</a> Bump async from 2.6.3 to 2.6.4 in /examples/create-react-app (#507)</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/11e4cea18bc884ead71bc9ef35ddb0ce025fa20f">11e4cea</a> Bump minimist in /examples/create-react-app-typescript (#513)</li> <li><a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/commit/f3005cd1e98f0e3bc9b7e810ccea6eda79372fea">f3005cd</a> Bump async from 2.6.3 to 2.6.4 in /examples/create-react-app-typescript (#514)</li> </ul> <a href="https://snyk.io/redirect/github/FortAwesome/react-fontawesome/compare/16710df0dad726be42a0df9711fd8fba90cda578...f3585b7c0996d0011808b5a877d34de6221b8987">Compare</a> </details> </details> <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIyMmM2MTJhNS1jNmEwLTQ1ODgtOGVjNC00MGU4ZjFkNmQ1ZGUiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjIyYzYxMmE1LWM2YTAtNDU4OC04ZWM0LTQwZThmMWQ2ZDVkZSJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/47001ef1-7b3a-49c2-88cd-8025c56346d0?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/47001ef1-7b3a-49c2-88cd-8025c56346d0/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/47001ef1-7b3a-49c2-88cd-8025c56346d0/settings/integration?pkg&#x3D;@fortawesome/react-fontawesome&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"22c612a5-c6a0-4588-8ec4-40e8f1d6d5de","prPublicId":"22c612a5-c6a0-4588-8ec4-40e8f1d6d5de","dependencies":[{"name":"@fortawesome/react-fontawesome","from":"0.1.19","to":"0.2.0"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/47001ef1-7b3a-49c2-88cd-8025c56346d0?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"47001ef1-7b3a-49c2-88cd-8025c56346d0","env":"prod","prType":"upgrade","vulns":["SNYK-JS-SEMVER-3247795"],"issuesToFix":[{"issueId":"SNYK-JS-SEMVER-3247795","severity":"high","title":"Regular Expression Denial of Service (ReDoS)","exploitMaturity":"proof-of-concept","priorityScore":482,"priorityScoreFactors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}]}],"upgrade":["SNYK-JS-SEMVER-3247795"],"upgradeInfo":{"versionsDiff":1,"publishedDate":"2022-06-29T15:07:55.159Z"},"templateVariants":["priorityScore"],"hasFixes":true,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[482]}) --->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1428