Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade @wordpress/icons from 8.4.0 to 10.7.0 #716

Open
wants to merge 1 commit into
base: trunk
Choose a base branch
from

Conversation

WontonSam
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade @wordpress/icons from 8.4.0 to 10.7.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 91 versions ahead of your current version.

  • The recommended version was released on 23 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
67 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
67 Proof of Concept
Release notes
Package name: @wordpress/icons
  • 10.7.0 - 2024-09-05
  • 10.6.0 - 2024-08-21
  • 10.5.0 - 2024-08-07
  • 10.4.0 - 2024-07-24
  • 10.3.0 - 2024-07-10
  • 10.2.0 - 2024-06-26
  • 10.1.0 - 2024-06-15
  • 10.0.2 - 2024-06-25
  • 10.0.1 - 2024-06-11
  • 10.0.0 - 2024-05-31
  • 9.49.0 - 2024-05-16
  • 9.48.0 - 2024-05-02
  • 9.47.0 - 2024-04-19
  • 9.46.0 - 2024-04-03
  • 9.45.0 - 2024-03-21
  • 9.44.0 - 2024-03-06
  • 9.43.0 - 2024-02-21
  • 9.42.4 - 2024-03-12
  • 9.42.3 - 2024-03-04
  • 9.42.2 - 2024-02-27
  • 9.42.1 - 2024-02-20
  • 9.42.0 - 2024-02-09
  • 9.41.0 - 2024-01-24
  • 9.40.0 - 2024-01-16
  • 9.39.1-next.79a6196f.0 - 2024-01-11
  • 9.39.0 - 2023-12-13
  • 9.38.0 - 2023-11-29
  • 9.37.0 - 2023-11-16
  • 9.36.0 - 2023-11-02
  • 9.35.1-next.f8d8eceb.0 - 2023-11-01
  • 9.35.0 - 2023-10-18
  • 9.34.0 - 2023-10-05
  • 9.33.13 - 2023-11-13
  • 9.33.12 - 2023-11-05
  • 9.33.11 - 2023-11-01
  • 9.33.10 - 2023-10-28
  • 9.33.9 - 2023-10-23
  • 9.33.8 - 2023-10-17
  • 9.33.7 - 2023-10-16
  • 9.33.6 - 2023-10-12
  • 9.33.5 - 2023-10-10
  • 9.33.4 - 2023-10-09
  • 9.33.3 - 2023-10-02
  • 9.33.2 - 2023-09-26
  • 9.33.1 - 2023-09-25
  • 9.33.0 - 2023-09-20
  • 9.32.1-next.5a1d1283.0 - 2023-09-01
  • 9.32.0 - 2023-08-31
  • 9.31.1 - 2023-08-20
  • 9.31.0 - 2023-08-17
  • 9.30.0 - 2023-08-10
  • 9.29.0 - 2023-07-20
  • 9.28.0 - 2023-07-05
  • 9.27.0 - 2023-06-30
  • 9.26.3 - 2023-10-12
  • 9.26.2 - 2023-06-27
  • 9.26.1 - 2023-06-26
  • 9.26.0 - 2023-06-07
  • 9.25.0 - 2023-05-24
  • 9.24.0 - 2023-05-10
  • 9.23.0 - 2023-04-26
  • 9.22.0 - 2023-04-12
  • 9.21.0 - 2023-03-29
  • 9.20.0 - 2023-03-15
  • 9.19.0 - 2023-03-01
  • 9.18.0 - 2023-02-15
  • 9.17.3 - 2023-10-12
  • 9.17.2 - 2023-02-21
  • 9.17.1 - 2023-02-03
  • 9.17.0 - 2023-02-01
  • 9.16.0 - 2023-01-17
  • 9.15.0 - 2023-01-02
  • 9.14.0 - 2022-12-14
  • 9.13.0 - 2022-11-16
  • 9.12.0 - 2022-11-02
  • 9.11.0 - 2022-10-19
  • 9.10.0 - 2022-10-05
  • 9.9.1-next.4d3b314fd5.0 - 2022-09-27
  • 9.9.0 - 2022-09-21
  • 9.8.1 - 2022-09-20
  • 9.8.0 - 2022-09-13
  • 9.7.1-next.957ca95e4c.0 - 2022-08-29
  • 9.7.0 - 2022-08-24
  • 9.6.1-next.d6164808d3.0 - 2022-08-23
  • 9.6.0 - 2022-08-10
  • 9.5.0 - 2022-07-27
  • 9.4.0 - 2022-07-13
  • 9.3.0 - 2022-06-29

    Changelog

    Features

    Zoom Out

    • Remove experimental flag. (65404)

    Enhancements

    • Create Block: Update the minimum required PHP version to 7.2. (65166)
    • DataViews: remove unused .dataviews-view-table__cell-content-wrapper:Empty style rule. (65084)
    • Media Utils: Add TypeScript support and export more utils. (64784)
    • Media placeholders: Add "drag" to the text. (65149)
    • Restore: Move to trash button in Document settings. (65087)
    • Inspector Controls: Use custom block name in inspector controls when available. (65398)
    • Icons: Adds bell and bell-unread icons. (65324)
    • Editor topbar: Reorder the actions on the right. (65163)
    • Patterns: Add opt out preference to the 'Choose a Pattern' modal when adding a page. (65026)
    • Locked Templates: Blocks with contentOnly locking should not be transformable. (64917)
    • Block Locking: Add border to Replace item in content only image toolbar. (64849)
    • DataViews: Improve UX of bundled views for Pages. (65295)

    Components

    • Styling: Apply elevation scale in components package. (65159)
    • Tabs: Improve Tabs indicator animation and related utils. (64926)
    • Modal
      • Add exit animation. (65203)
      • Decrease close button size. (65131)
    • Navigator Screen: Warn if path doesn't follow a URL-like scheme. (65231)
    • Card: Update Card radius. (65053)
    • Combobox Control: Add placeholder attribute. (65254)

    Block Library

    • Allow dropping multiple images to the image block. (65030)
    • Categories List block: Add dropdown for taxonomies. (65272)
    • Image: Adds the block controls for uploading image. (64320)
    • Remove colons from control labels. (65205)
    • Terms List block: Add Categories-specific variation. (65434)

    Zoom Out

    • Add Zoom Out toggle to editor header when experiment enabled. (65183)
    • Add prompt for drag and drop in Patterns tab in Zoom Out mode. (65115)
    • Close inserter on exiting Zoom Out to edit. (65194)
    • Show top level sections in List View. (65202)
    • Try vertical displacement when dragging a pattern between existing patterns/sections. (63896)

    Block Editor

    • Link Editing: Automatically add tel to phone number when linking URL. (64865)
    • Drag and Drop: When dragging a mix of video, audio, and image blocks, create individual blocks as appropriate. (65144)
    • URLInput: Replace input with InputControl. (65158)
    • Normalize block inspector controls spacing. (64526)

    Post Editor

    • Add new Media section to preferences modal. (64846)
    • DocumentBar: Replace icon with post type label. (65170)
    • Page editor: Double-click to edit template part. (65024)
    • Post publish upload media dialog: Handle more block types. (65122)

    Block bindings

    • Populate block context with inherited post type from template slug. (65062)
    • Try gap 0 on attribute items. (65277)
    • Use post meta label from register_meta in block bindings workflows. (65099)

    Global Styles

    • Refactor site background controls and move site global styles into Background group. (65304)
    • Spacing control: Replace sides dropdwon with link button. (65193)

    Interactivity API

    • Refactor context proxies. (64713)
    • Update: Rephrase "Force page reload" and move to Advanced. (65081)

    REST API

    • Global Styles: Allow read access to users with edit_posts capabilities. (65071)
    • Query loop / Post template: Enable post format filter. (64167)

    New APIs

    • Add @ wordpress/fields package.
      • Introduce the package. (65230)
      • Make the package private. (65269)
    • Interactivity API: Add getServerState() and getServerContext(). (65151)

    Bug Fixes

    • Align popover alt variant styling with block toolbar. (65263)
    • Compose: Correctly call timer cleanup in 'useFocusOnMount'. (65184)
    • Fix some docblock types related to the Template Registration API. (65187)
    • Fix the issue where block spacing control not shown. (65371)
    • Fix unintentional block toolbar shadow. (65182)
    • Fix: Moving a page to the trash on the site editor does not goes back to the pages list. (65119)
    • Fix: Moving the last page item to the the trash causes a crash. (65236)
    • Preferences: Fix back button on mobile. (65141)
    • Post Summary Panel: Restore height:Auto for toggle buttons. (65362)
    • Fix Tabs styling in Font Library modal. (65330)
    • E2E: Change deprecated social icons for standard in end-to-end. (65312)
    • Typography: Make title blocks apply typographic styles consistently. (65307)
    • Target Hints REST API: Add missing param sanitization. (65280)
    • Interactivity API: Update iterable signals when deepMerge() adds new properties. (65135)
    • Navigation Menus: Typography styling support to the navigation submenu block. (65060)
    • Grid: In RTL languages, the resize handles point in the opposite direction. (64995)
    • Block Locking: Fix Content Only Toolbar icon focus style. (64940)
    • Image: Fix resizing to max width in classic themes. (64819)
    • Meta Boxes: Try split content view. (64351)
    • Distraction Free: Fix blurry edge along editor header. (64277)

    Block Library

    • Comments Pagination: Fix warning returned by comments pagination blocks. (65435)
    • Cover: Explicitly set isUserOverlayColor to false when media is updated. (65105)
    • Disallow setting grid block rows/columns to zero. (65217)
    • Fix image block crash. (65222)
    • Fix: Buttons block: Block spacing value does not apply to both vertical and horizontal alignment. (64971)
    • Fix: Embed blocks: Figcaption inserted via toolbar not nested within figure element - #64960. (64970)
    • Image cropping: Skip making an API request if there are no changes to apply. (65384)
    • Comments Pagination: Pass the comments query paged arg to functions get_next_comments_link and get_previous_comments_link. (63698)
    • Query Loop
      • Default to querying posts when on singular content. (65067)
      • Remove is_singular() check and fix test. (65483)
      • Format controls: Fix JavaScript error. (65551)

    Block Editor

    • Inserter: Fix loading indicator for reusable blocks. (64839)
    • Normalize spacing in Layout hook controls. (65132)
    • Pattern Inserter: Fix pattern list overflow. (65192)
    • Remove reset styles RTL from the iframe. (65150)
    • Revert "Block Insertion: Clear the insertion point when selecting a different block or clearing block selection (#64048)" (65208)

    Components

    • BoxControl: Unify input filed width whether linked or not. (65348)
    • ComboboxControl: Add more unit tests. (65255)
    • Fix: Button Replace remaining 40px default size violations [Edit widgets]. (65367)
    • Tabs: Fix vertical indicator. (65385)

    Block bindings

    • Fix empty strings placeholders in post meta bindings. (65089)
    • Remove key fallback in bindings get values and rely on source label. (65517)
    • Fix passing bindings context to canUserEditValue. (65599)
    • Prioritize existing placeholder over bindingsPlaceholder. (65220)
    • Only use canUserEditValue when setValues is defined. (65565)

    Zoom Out

    • Force device type to Desktop whenever zoom out is invoked. (64476)
    • Hide toolbar icon on smaller viewports. (65437)
    • Remove zoom out toggle when editor is not iframed. (65452)

    Accessibility

    • A11y: Add script-module. (65101)
    • Interactivity API: Use a11y Script Module in Gutenberg. (65123)
    • Script Modules API: Print script module live regions HTML in page HTML. (65380)
    • DatePicker: Better hover/focus styles. (65117)
    • Form Input: Don't use flex-direction: Row-reverse for checkbox field. (64232)
    • Navigation Menus: Remove Warning and add notice for Navigation. (63921)
    • Global Styles: Fix the shadows Range control accessibility and usability. (63908)
    • Block Editor: Fix accessibility of the hooked blocks toggles. (63133)

    Post Editor

    • Support keyboard resizing of meta boxes pane. (65325)
    • Swap position of the Pre-publish checks buttons. (65317)

    Performance

    • Core Data: Batch remaining actions in resolvers. (65176)
    • Block Editor: Use static access for selector in 'useZoomOutModeExit'. (65337)
    • Editor: Optimize global styles permission check. (65177)

    Experiments

    • Block bindings REST API: Bring bindings UI in Site Editor. (64072)

    Documentation

    • Add JSDoc block for getSectionRootClientId in block editor package. (65219)
    • ButtonGroup: Fix story to show what the component does. (65336)
    • DataViews storybook
      • Better styles for combined fields story. (65078)
      • Enable all layouts for combined fields storybook. (65082)
    • Docs: Fix minor typos in Build your first block tutorial. (64961)
    • Docs: Update the content of the API version 3 section in the Block API Reference. (65375)
    • Fix typo in Slot Fills documentation. (65275)

    Code Quality

    • Components: Transition to the new 40px default size.
      • Button:
        • Add __next40pxDefaultSize for files in editor 3. (65139)
        • Add __next40pxDefaultSize for files in editor 4. (65140)
        • Add props for buttons in editor 1. (65068)
        • Add props for buttons in editor 2. (65083)
        • Fix: Replace remaining 40px default size violations [Block Editor 4]. (65257)
        • Fix: Replace remaining 40px default size violation [Block library 3]. (65110)
        • Fix: Replace remaining 40px default size violation [Block library 4]. (65143)
        • Fix: Replace remaining 40px default size violation [Block library]. (65075)
        • Fix: Replace remaining 40px default size violation [Edit Site 2]. (65258)
        • Fix: Replace remaining 40px default size violations [Block library 1]. (65033)
        • Fix: Replace remaining 40px default size violations [Block Editor 1]. (65034)
      • BoxControl
        • Add lint rule for 40px size prop usage. (65341)
      • DimensionsPanel: Apply 40px default size to UI when no spacing preset is available. (65300)
    • Add useEvent and revamped useResizeObserver to @ wordpress/compose. (64943)
    • DataViews: Use Dropdown for views configuration dialog. (65314)
    • Platform docs: Upgrade dependencies. (65445)
    • Rename edit-post__fade-in-animation and unify keyframe definitions. (65377)
    • Update minimum required version in PHP. (65301)
    • Editor: Use hooks instead of HoC in BlockManager. (65349)
    • Data Views Fields: Migrate store and actions from editor package to fields package. (65261)
    • Plugin: Remove 'function_exists' checks for methods with 'gutenberg' prefix. (65260)
    • Global Styles: Update REST controller override method and backport changes from Core. (65259)
    • Patterns: Remove unused method returned from 'mapSelect'. (65073)
    • Embed: Convert EmbedPreview component to functional component. (51325)

    Components

    • BoxControl: Fix critical error when null value is passed. (65287)
    • Composite:
      • Deprecate legacy, unstable version. (63572)
      • Remove store prop and useCompositeStore hook. (64723)
      • Stabilize APIs. (63569)
    • @ wordpress/components: Add local copy of use-lilius. (65097)

    Block bindings

    • Always prioritize using context in post meta source logic. (65449)
    • Improve getRegisteredPostMeta resolver. (65450)
    • Remove extra filtering of empty sources. (65447)

    Block Editor

    • Remove the 'PrivateInserter' component. (65111)
    • Use the tooltip from a button in 'ButtonBlockAppender'. (65113)
    • Remove unused css selectors. (65276)

    Tools

    • Scripts: Update stylelint dependency and the default configuration. (64828)
    • Styleling config: Fix stylelint configuration missing files for npm. (65313)

    Build Tooling

    • Build Plugin: Simplify and improve zip contents. (65232)
    • Build zip artifact on release and wp production branches. (65471)
    • Build: Include Core blocks' render and variations files. (63311)
    • Script Modules
      • Prepare build for more script modules. (65064)
      • Remove babel from script-modules build. (65279)
      • Remove es-module shims and importmap-polyfill. (65210)
    • Correctly generate PHP files for server-side rendering of blocks on Windows OS. (65248)
    • Packages: Only add polyfills where needed. (65292)
    • Switch from UglifyJS to Terser to build the polyfill script. (65278)

    Testing

    • Unit tests: Mock matchMedia to enforce prefers-reduce-motion. (65438)
    • Upgrade Playwright to v1.47. (65156)

    First-time contributors

    The following PRs were merged by first-time contributors:

    Contributors

    The following contributors merged PRs in this release:

    @ aaronrobertshaw @ afercia @ AKSHAT2802 @ Aljullu @ andrewserong @ carolinan @ cbravobernal @ ciampo @ colorful-tones @ creativecoder @ DaniGuardiola @ DAreRodz @ devansh016 @ dhruvang21 @ ellatrix @ farid-hadi @ getdave @ gigitux @ greenworld @ gziolo @ hbhalodia @ jameskoster @ jasmussen @ javierarce @ jeryj @ jorgefilipecosta @ jsnajdr @ kevin940726 @ louwie17 @ madhusudhand @ MaggieCabrera @ Mamaduka @ mikeybinns @ mirka @ ntsekouras @ oandregal @ ockham @ peterwilsoncc @ rahulharpal1603 @ ramonjd @ richtabor @ rohitmathur-7 @ SantosGuillamot @ scruffian @ sgomes @ sirreal @ stokesman @ swissspidy @ t-hamano @ talldan @ vipul0425 @ zaguiini

  • 9.2.0 - 2022-06-15
  • 9.1.0 - 2022-06-01
  • 9.0.0 - 2022-05-18
  • 8.4.0 - 2022-05-04
from @wordpress/icons GitHub release notes

Important

  • Warning: This PR contains a major version upgrade, and may be a breaking change.
  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information: <img src="https://api.segment.io/...

Snyk has created this PR to upgrade @wordpress/icons from 8.4.0 to 10.7.0.

See this package in npm:
@wordpress/icons

See this project in Snyk:
https://app.snyk.io/org/cachiman/project/c0348dc4-ca66-4638-a670-4b7fd9c9a262?utm_source=github&utm_medium=referral&page=upgrade-pr
Copy link

google-cla bot commented Sep 28, 2024

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants