Skip to content

Conversation

@Security-Test-Account
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade antd from 4.3.3 to 4.24.16.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 161 versions ahead of your current version.
  • The recommended version was released 21 days ago, on 2024-03-19.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Improper Verification of Cryptographic Signature
SNYK-JS-BROWSERIFYSIGN-6037026
537/1000
Why? Proof of Concept exploit, CVSS 8.6
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ES5EXT-6095076
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Improper Input Validation
SNYK-JS-FOLLOWREDIRECTS-6141137
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Open Redirect
SNYK-JS-EXPRESS-6474509
537/1000
Why? Proof of Concept exploit, CVSS 8.6
No Known Exploit
Information Exposure
SNYK-JS-FOLLOWREDIRECTS-6444610
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Denial of Service (DoS)
SNYK-JS-NWSAPI-2841516
537/1000
Why? Proof of Concept exploit, CVSS 8.6
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ASYNCVALIDATOR-2311201
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept
Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
537/1000
Why? Proof of Concept exploit, CVSS 8.6
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: antd
  • 4.24.16 - 2024-03-19

    • 🐞 修复 Select 组件在选项较少时不显示滚动条的问题。#47050
    • 🐞 修复 Transfer 反选当页错误的问题。#47134 @ linxianxi
    • 🐞 修复点击 Form tooltip 图标会触发 Switch 切换的问题。#46159 @ Wxh16144
    • 🐞 修复 Segmented optionsclassName 会覆盖组件自带 className 的问题。rc-segmented#175 @ stoil-terziev
  • 4.24.15 - 2023-11-21
  • 4.24.14 - 2023-09-06
  • 4.24.13 - 2023-08-03
  • 4.24.12 - 2023-06-30
  • 4.24.11 - 2023-06-27
  • 4.24.10 - 2023-05-04
  • 4.24.9 - 2023-04-20
  • 4.24.8 - 2023-02-13
  • 4.24.7 - 2022-12-30
  • 4.24.6 - 2022-12-26
  • 4.24.5 - 2022-12-06
  • 4.24.4 - 2022-11-25
  • 4.24.3 - 2022-11-17
  • 4.24.2 - 2022-11-12
  • 4.24.1 - 2022-11-04
  • 4.24.0 - 2022-11-01
  • 4.23.6 - 2022-10-17
  • 4.23.5 - 2022-10-10
  • 4.23.4 - 2022-10-02
  • 4.23.3 - 2022-09-28
  • 4.23.2 - 2022-09-17
  • 4.23.1 - 2022-09-09
  • 4.23.0 - 2022-09-04
  • 4.22.8 - 2022-08-26
  • 4.22.7 - 2022-08-21
  • 4.22.6 - 2022-08-17
  • 4.22.5 - 2022-08-15
  • 4.22.4 - 2022-08-08
  • 4.22.3 - 2022-08-01
  • 4.22.2 - 2022-07-28
  • 4.22.1 - 2022-07-27
  • 4.22.0 - 2022-07-26
  • 4.21.7 - 2022-07-18
  • 4.21.6 - 2022-07-11
  • 4.21.5 - 2022-07-03
  • 4.21.4 - 2022-06-27
  • 4.21.3 - 2022-06-17
  • 4.21.2 - 2022-06-14
  • 4.21.1 - 2022-06-13
  • 4.21.0 - 2022-06-06
  • 4.20.7 - 2022-05-30
  • 4.20.6 - 2022-05-22
  • 4.20.5 - 2022-05-15
  • 4.20.4 - 2022-05-11
  • 4.20.3 - 2022-05-09
  • 4.20.2 - 2022-04-30
  • 4.20.1 - 2022-04-26
  • 4.20.0 - 2022-04-24
  • 4.20.0-alpha.1 - 2022-04-18
  • 4.20.0-alpha.0 - 2022-04-12
  • 4.19.5 - 2022-04-02
  • 4.19.5-alpha.0 - 2022-03-28
  • 4.19.4 - 2022-03-27
  • 4.19.3 - 2022-03-21
  • 4.19.2 - 2022-03-13
  • 4.19.1 - 2022-03-08
  • 4.19.1-alpha.0 - 2022-03-08
  • 4.19.0 - 2022-03-08
  • 4.18.9 - 2022-02-28
  • 4.18.8 - 2022-02-21
  • 4.18.7 - 2022-02-14
  • 4.18.6 - 2022-02-08
  • 4.18.5 - 2022-01-24
  • 4.18.4 - 2022-01-18
  • 4.18.3 - 2022-01-10
  • 4.18.2 - 2021-12-30
  • 4.18.1 - 2021-12-29
  • 4.18.0 - 2021-12-27
  • 4.17.4 - 2021-12-20
  • 4.17.3 - 2021-12-08
  • 4.17.2 - 2021-11-26
  • 4.17.1 - 2021-11-22
  • 4.17.1-alpha.1 - 2021-11-17
  • 4.17.1-alpha.0 - 2021-11-16
  • 4.17.0 - 2021-11-15
  • 4.17.0-alpha.10 - 2021-11-08
  • 4.17.0-alpha.9 - 2021-10-31
  • 4.17.0-alpha.8 - 2021-10-25
  • 4.17.0-alpha.7 - 2021-10-18
  • 4.17.0-alpha.6 - 2021-10-11
  • 4.17.0-alpha.5 - 2021-09-30
  • 4.17.0-alpha.4 - 2021-09-25
  • 4.17.0-alpha.3 - 2021-09-14
  • 4.17.0-alpha.2 - 2021-09-07
  • 4.17.0-alpha.1 - 2021-09-06
  • 4.17.0-alpha.0 - 2021-09-01
  • 4.16.13 - 2021-08-23
  • 4.16.12 - 2021-08-16
  • 4.16.11 - 2021-08-08
  • 4.16.10 - 2021-08-02
  • 4.16.9 - 2021-07-27
  • 4.16.8 - 2021-07-19
  • 4.16.7 - 2021-07-12
  • 4.16.6 - 2021-06-29
  • 4.16.5 - 2021-06-23
  • 4.16.3 - 2021-06-15
  • 4.16.2 - 2021-06-07
  • 4.16.1 - 2021-05-31
  • 4.16.0 - 2021-05-25
  • 4.16.0-alpha.2 - 2021-05-08
  • 4.16.0-alpha.1 - 2021-05-08
  • 4.16.0-alpha.0 - 2021-05-07
  • 4.15.6 - 2021-05-18
  • 4.15.5 - 2021-05-10
  • 4.15.4 - 2021-04-30
  • 4.15.3 - 2021-04-26
  • 4.15.3-alpha.0 - 2021-04-21
  • 4.15.2 - 2021-04-19
  • 4.15.1 - 2021-04-10
  • 4.15.0 - 2021-03-29
  • 4.14.1 - 2021-03-22
  • 4.14.0 - 2021-03-14
  • 4.13.1 - 2021-03-06
  • 4.13.0 - 2021-02-28
  • 4.12.3 - 2021-02-10
  • 4.12.2 - 2021-02-04
  • 4.12.1 - 2021-02-03
  • 4.12.0 - 2021-02-02
  • 4.11.3 - 2021-02-02
  • 4.11.2 - 2021-01-26
  • 4.11.1 - 2021-01-24
  • 4.11.0 - 2021-01-24
  • 4.10.3 - 2021-01-18
  • 4.10.2 - 2021-01-11
  • 4.10.1 - 2021-01-10
  • 4.10.0 - 2021-01-04
  • 4.9.4 - 2020-12-16
  • 4.9.3 - 2020-12-14
  • 4.9.2 - 2020-12-07
  • 4.9.1 - 2020-12-01
  • 4.9.0 - 2020-11-30
  • 4.8.6 - 2020-11-27
  • 4.8.5 - 2020-11-22
  • 4.8.4 - 2020-11-16
  • 4.8.3 - 2020-11-16
  • 4.8.2 - 2020-11-09
  • 4.8.1 - 2020-11-09
  • 4.8.0 - 2020-11-02
  • 4.7.3 - 2020-10-24
  • 4.7.2 - 2020-10-19
  • 4.7.1 - 2020-10-19
  • 4.7.0 - 2020-10-10
  • 4.6.6 - 2020-09-27
  • 4.6.5 - 2020-09-20
  • 4.6.4 - 2020-09-13
  • 4.6.3 - 2020-09-07
  • 4.6.2 - 2020-08-31
  • 4.6.1 - 2020-08-24
  • 4.6.0 - 2020-08-23
  • 4.5.4 - 2020-08-12
  • 4.5.3 - 2020-08-09
  • 4.5.2 - 2020-08-02
  • 4.5.1 - 2020-07-28
  • 4.5.0 - 2020-07-27
  • 4.4.3 - 2020-07-20
  • 4.4.2 - 2020-07-11
  • 4.4.1 - 2020-07-06
  • 4.4.0 - 2020-06-29
  • 4.3.5 - 2020-06-21
  • 4.3.4 - 2020-06-14
  • 4.3.3 - 2020-06-07
from antd GitHub release notes
Commit messages
Package name: antd
  • 7c06024 docs(:sparkles:): release 4.24.16 (#47932)
  • 426ae12 chore: bump rc-* (#47935)
  • 6a0f811 fix: 4.x Transfer selectInvert should be corrected (#47134)
  • df63d1c demo: demo mock data address spelling error (#40432)
  • e18bc84 fix: Select should show scrollbar when overflowed (#47050)
  • a52e205 fix: Form label tooltip icon trigger Switch (#46159)
  • 352fac8 ci: remove argos usage (#46208)
  • 916332c docs: changelog for 4.24.15 (#45997)
  • 0e6fe5f feat: export sider context from layout for v4 (#45947)
  • 6695e7d chore: bump deps (#45174)
  • 775b119 type: fix type errors of React.Key (#45018)
  • 5f82d5b chore: bump rc-* (#44924)
  • 8ed4c2f fix(radio): use its own disabled first (#44837)
  • b3f0468 fix(DatePicker): disabled style is overridden in Form hover (#44779)
  • a014f7c chore: fix 4.x-stable publish script (#44665)
  • bc46d4b docs(:sparkles:): release 4.24.14 (#44653)
  • 09a6f3c test: update jest snapshot and fix type (#44652)
  • 843c4b6 fix(Breadcrumb): fix wrong overlay warning (#44578)
  • a556f1f fix: 4.x gif thumb url base64 type should be corrected (#44129)
  • 7251397 demo: update 4.x dropdown deprecated menu (#43825)
  • 1a7de4b fix: update rc-util version (#44043)
  • 0b6920b docs: 4.24.13 changelog (#43985)
  • a0cf986 fix: getCurrentLink not trigger when scroll (#43917)
  • 2b43f73 feat: @ ant-design/react-slick upgrade (#39634) (#43806)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants