[Snyk] Upgrade: , , , , , , , moment, , applicationinsights, ffc-messaging, govuk-frontend, joi, hapi-pino #98
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@azure/identity
from 4.3.0 to 4.4.1 | 11 versions ahead of your current version | 2 months ago
on 2024-07-31
@azure/msal-node
from 2.9.2 to 2.13.1 | 9 versions ahead of your current version | 21 days ago
on 2024-08-29
@azure/storage-blob
from 12.13.0 to 12.24.0 | 114 versions ahead of your current version | 2 months ago
on 2024-07-23
@hapi/boom
from 9.1.1 to 9.1.4 | 3 versions ahead of your current version | 3 years ago
on 2021-08-20
@hapi/wreck
from 17.1.0 to 17.2.0 | 1 version ahead of your current version | 2 years ago
on 2022-03-25
@hapi/hapi
from 20.2.1 to 20.3.0 | 2 versions ahead of your current version | 2 years ago
on 2023-02-14
@hapi/inert
from 6.0.3 to 6.0.5 | 2 versions ahead of your current version | 3 years ago
on 2022-01-16
moment
from 2.29.4 to 2.30.1 | 2 versions ahead of your current version | 9 months ago
on 2023-12-27
@joi/date
from 2.1.0 to 2.1.1 | 1 version ahead of your current version | 5 months ago
on 2024-04-22
applicationinsights
from 2.5.1 to 2.9.6 | 13 versions ahead of your current version | a month ago
on 2024-08-15
ffc-messaging
from 2.10.0 to 2.10.1 | 2 versions ahead of your current version | 2 months ago
on 2024-07-30
govuk-frontend
from 4.7.0 to 4.8.0 | 1 version ahead of your current version | 7 months ago
on 2024-02-05
joi
from 17.4.0 to 17.13.3 | 32 versions ahead of your current version | 3 months ago
on 2024-06-19
hapi-pino
from 10.1.0 to 10.2.0 | 1 version ahead of your current version | 2 years ago
on 2022-08-26
Release notes
Package name: @azure/msal-node
2.13.0
Tue, 13 Aug 2024 23:25:05 GMT
Minor changes
Patches
2.12.0
Tue, 23 Jul 2024 14:19:34 GMT
Minor changes
Package name: @hapi/boom
9.1.4
9.1.3
9.1.2
Package name: @hapi/wreck
17.2.0
version 17.1.0
Package name: @hapi/hapi
20.3.0
20.2.2
Package name: @hapi/inert
No content.
No content.
No content.
Package name: moment
2.30.1
2.30.0
2.29.4
Package name: @joi/date
2.1.1
2.1.0
Package name: ffc-messaging
Patch vuln in azure library (#32)
Support Workload Identity (#31)
Package name: govuk-frontend
This release includes the ability to update the crown logo. You must do this between 19 February and 1 March 2024.
We’ll send reminders to our mailing list and cross-government Slack as soon as you can make this change.
New features
Update to the new GOV.UK logo (between 19 February and 1 March 2024)
We’ve updated the GOV.UK logo to reflect the changing of the monarch. King Charles III uses the Tudor Crown, rather than the St Edward’s Crown chosen by Queen Elizabeth II.
If your service uses GOV.UK branding, you must update your service to use the new crown.
These changes were made in the following pull requests:
Include the new logo assets
Multiple new image assets are included in this release. You’ll need to copy these to your service's image assets folder if they are not being used directly from the Frontend package. By default this folder is located at
/assets/images
.If you’re using Nunjucks, the asset path may have been changed by the
assetPath
global variable orassetsPath
parameter on the header component.Copy the following files from
/dist/assets/images
into your assets folder. Any images with the same name as an existing image can be safely overwritten.Update the logo in the header of your page
If you are using the
govukHeader
Nunjucks macro in your service, add theuseTudorCrown
parameter to the macro instantiation.If you are not using the Nunjucks macro, locate the HTML for the existing crown and replace it with this updated HTML. Make sure the URL for the new PNG fallback image is correct.
New features
Added the Exit This Page component to help users quickly exit a page or service
You can now choose to use the exit this page component to help users quickly leave a page or service which contains sensitive information.
This was added in pull request #2545: Add exit this page component.
Added inverse modifier for buttons on dark backgrounds
You can now choose to use the
govuk-button--inverse
class to style buttons on dark backgrounds with a white background colour.This change was made in pull request #3556: Add inverse button styles.
Added inverse modifier for breadcrumbs on dark backgrounds
You can now choose to use the
govuk-breadcrumbs--inverse
class to style breadcrumbs on dark backgrounds with white text, links and arrows.This change was made in pull request #3774: Add inverse breadcrumb and back link modifiers and styles.
Added inverse modifier for back links on dark backgrounds
You can now choose to use the
govuk-back-link--inverse
class to style back links on dark backgrounds with white links and arrows.This change was made in pull request #3774: Add inverse breadcrumb and back link modifiers and styles.
Fixes
We’ve made fixes to GOV.UK Frontend in the following pull requests:
Package name: joi
17.13.3
17.13.2
17.13.1
17.13.0
17.12.3
17.12.2
17.12.1
17.12.0
17.11.1
Package name: hapi-pino
What's Changed
New Contributors
Full Changelog: v10.1.0...v10.2.0
What's Changed
Full Changelog: v10.0.0...v10.1.0
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: