8000 [Snyk] Upgrade react-dropzone from 14.3.5 to 14.3.8 by jschuler · Pull Request #611 · patternfly/chatbot · GitHub
[go: up one dir, main page]

Skip to content

[Snyk] Upgrade react-dropzone from 14.3.5 to 14.3.8#611

Merged
rebeccaalpert merged 2 commits intomainfrom
snyk-upgrade-d8dba2178e7cc08b5289e04fafe4591c
Jul 28, 2025
Merged

[Snyk] Upgrade react-dropzone from 14.3.5 to 14.3.8#611
rebeccaalpert merged 2 commits intomainfrom
snyk-upgrade-d8dba2178e7cc08b5289e04fafe4591c

Conversation

@jschuler
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to upgrade react-dropzone from 14.3.5 to 14.3.8.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.

  • The recommended version was released 5 months ago.

Release notes
Package name: react-dropzone from react-dropzone GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

@patternfly-build
Copy link
patternfly-build commented Jul 17, 2025

@rebeccaalpert
Copy link
Member

Fixed issues and did some quick testing - seems to still work ok where we are using it for things.

import rehypeExternalLinks from 'rehype-external-links';
import rehypeSanitize from 'rehype-sanitize';
import { PluggableList } from 'react-markdown/lib';
import { PluggableList } from 'unified';
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TS was suddenly complaining this is no longer exported for some reason? This is where it ultimately comes from in react-markdown.

Snyk has created this PR to upgrade react-dropzone from 14.3.5 to 14.3.8.

See this package in npm:
react-dropzone

See this project in Snyk:
https://app.snyk.io/org/patternfly-bD6TiY6PxAoojbR6oZkeJN/project/f71e63f8-7c3b-4f80-bcc1-456ac734cda1?utm_source=github&utm_medium=referral&page=upgrade-pr
@rebeccaalpert rebeccaalpert force-pushed the snyk-upgrade-d8dba2178e7cc08b5289e04fafe4591c branch from c0c7faa to f06b882 Compare July 28, 2025 16:03
@rebeccaalpert
Copy link
Member

Just rebasing after merge-a-palooza.

@rebeccaalpert rebeccaalpert force-pushed the snyk-upgrade-d8dba2178e7cc08b5289e04fafe4591c branch from f06b882 to 929bf2e Compare July 28, 2025 17:05
@rebeccaalpert rebeccaalpert merged commit 522da1d into main Jul 28, 2025
6 of 7 checks passed
@rebeccaalpert rebeccaalpert deleted the snyk-upgrade-d8dba2178e7cc08b5289e04fafe4591c branch July 30, 2025 20:51
rebeccaalpert added a commit to rebeccaalpert/virtual-assistant that referenced this pull request Oct 24, 2025
…#611)

Snyk created this PR to upgrade react-dropzone from 14.3.5 to 14.3.8. Manually fixed types/imports after version bump. Went through demos and made sure they still worked ok and that tests passed.

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
Co-authored-by: Rebecca Alpert <ralpert@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

0