[Snyk] Upgrade bulma from 0.4.4 to 0.9.4#17
Open
dmh34 wants to merge 1 commit into
Open
Conversation
Snyk has created this PR to upgrade bulma from 0.4.4 to 0.9.4. See this package in npm: https://www.npmjs.com/package/bulma See this project in Snyk: https://app.snyk.io/org/dmh34/project/76d8201a-82f7-4ec5-a64d-797d16c0fb6d?utm_source=github&utm_medium=referral&page=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade bulma from 0.4.4 to 0.9.4.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-IP-6240864
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-JSONSCHEMA-1920922
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TAR-1579155
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TMPL-1583443
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASH-1040724
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-CRYPTOJS-6028119
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-DECODEURICOMPONENT-3149970
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-DNSPACKET-1293563
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MIXINDEEP-450212
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ACORN-559469
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ACORN-559469
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-AJV-584908
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASHES-2434290
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MERGEDEEP-1070277
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-QS-3153490
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-BROWSERIFYSIGN-6037026
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASH-450202
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASH-567746
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASH-608086
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASHES-2434283
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ISSVG-1085627
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ISSVG-1243891
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TAR-6476909
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-AXIOS-174505
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASH-1018905
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-DOTPROP-543489
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HANDLEBARS-567742
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HAPIHOEK-548452
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MINIMIST-559764
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-NWSAPI-2841516
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-PATHPARSE-1077067
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-POSTCSS-1255640
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-PROMPTS-1729737
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-COLORSTRING-1082939
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-KINDOF-537849
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HANDLEBARS-534988
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-AUTH0JS-565004
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MINIMIST-559764
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MINIMIST-559764
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-POSTCSS-1090595
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-MINIMIST-2429795
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-BABELTRAVERSE-5962462
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASHES-2434284
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASHES-2434285
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-NODEFORGE-598677
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ELLIPTIC-571484
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ESLINTUTILS-460220
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-INI-1048974
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HANDLEBARS-1056767
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HANDLEBARS-469063
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HANDLEBARS-480388
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HANDLEBARS-534478
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-SETVALUE-1540541
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-SETVALUE-450213
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-SSRI-1246392
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TAR-1536528
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TAR-1536531
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TAR-1579147
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-SETVALUE-1540541
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-SETVALUE-450213
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-UAPARSERJS-1023599
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-UAPARSERJS-610226
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TAR-1579152
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-URLPARSE-2407770
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-WEBSOCKETEXTENSIONS-570623
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-Y18N-1021887
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-LODASHES-2434289
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-COOKIEJAR-3149984
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-NODEFETCH-2342118
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-NODEFETCH-674311
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-NODENOTIFIER-1035794
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ELLIPTIC-1064899
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-ELLIPTIC-511941
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-EVENTSOURCE-2823375
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-EXPRESS-6474509
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HOSTEDGITINFO-1088355
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HTTPPROXY-569139
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-HANDLEBARS-1279029
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-UAPARSERJS-1072471
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-URLPARSE-1078283
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-URLPARSE-1533425
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-URLPARSE-2401205
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-URLPARSE-2407759
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-URLPARSE-2412697
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-WS-1296835
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-WS-1296835
Why? Proof of Concept exploit, CVSS 8.6
SNYK-JS-TAR-1536758
Why? Proof of Concept exploit, CVSS 8.6
npm:debug:20170905
Why? Proof of Concept exploit, CVSS 8.6
npm:debug:20170905
Why? Proof of Concept exploit, CVSS 8.6
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: bulma
-
0.9.4 - 2022-05-08
- Responsive buttons: the size of a button will change for each breakpoint (Fix #1572)
- Add missing variables for content customization
- Fix #683 Modal - example javascript toggle
- Fix #3461 Bulma logo with wordmark in SVG
- Fix #3383 'Variables' sections on docs page (#3513)
- Fixes #3510 The navbar overlaps with sidebars in "Fullheight hero with navbar" (#3516)
- Setup Cypress testing (#3436)
- Replace disabled attr on pagination anchor elements with is-disabled
- #3500 Fix hidden disabled buttons on iOS 15.4 (#3521)
- #3076 Fix Table headers centered aligned in Safari
-
0.9.3 - 2021-06-18
- New
- New
- New
- New
- New
- Add
- New
- #3362 Fix slash divide
-
0.9.2 - 2021-01-26
- Fix #1583 New
- New
- #3005 Fix
- Fix #3145 Dropdown content is bounded by a parent card
- Fix #3089 Sub columns of a variable columns have weird gap
- Fix #2937 Add
- #3208 Fix #3163 Do not override is-rounded with button-small
- #3216 Removed duplicate
- #3216 Removed all references to the
- Fix #3012 Add
- Fix #2797 Import dependencies individually for each component
- Remove list style from pagination list
-
0.9.1 - 2020-09-28
- #3047 Flexbox helpers
- #3085 Add
- #3086 Allow each component to have its own colors and default to global ones
- New variables
- #2630 Fixes #2598 -> Add
- Add
- #2540 Fixes #2539 -> Fix indeterminate progress styling in IE11
- #3057 Make the default text color of
- #3088 Adds not allowed cursor to missing inputs
- #3101 Add
- #3107 Add
-
0.9.0 - 2020-06-07
-
-
-
-
-
-
- for a
- for a
- for both
- light and dark color helpers
- light and dark background color helpers
- #2925 Center table cell content vertically with
- #2955 Fix issue when there's only one
-
0.8.2 - 2020-04-11
- Fix #2885 -> Revert
-
0.8.1 - 2020-03-23
- #2709 Add light colors to the
- #2740 Fixes #2739 -> Add variables size for layout
- Fix #2741 -> Create
- #2756 Add
- #2664 Fixes #2671 -> Add
-
0.8.0 - 2019-10-18
-
0.7.5 - 2019-05-18
-
0.7.4 - 2019-02-08
-
0.7.3 - 2019-02-07
-
0.7.2 - 2018-10-12
-
0.7.1 - 2018-04-18
-
0.7.0 - 2018-04-13
-
0.6.2 - 2018-01-10
-
0.6.1 - 2017-11-06
-
0.6.0 - 2017-10-10
-
0.5.3 - 2017-09-18
-
0.5.2 - 2017-09-11
-
0.5.1 - 2017-08-07
-
0.5.0 - 2017-07-29
-
0.4.4 - 2017-07-24
from bulma GitHub release notesNew features
@ mixin between: takes 2 breakpoint values, outputs a media query for the range between these 2 values$breakpointsSass map: a map of named breakpoints and their type (from,untilor both)@ mixin breakpoint: uses the new$breakpointsSass map to output a media queryImprovements
Bugfix
New features
is-underlinedclass for underlined text and linksautovalue for margin and padding helper classesImprovements
$section-padding-desktopSass variable$hero-body-padding-tabletSass variable$shadowSass variable (used for.box,.card,.dropdownand.panel)is-normalsize modifiers to.fileand.content%resetplaceholderBugfix
Breaking change
To fix duplicate imports, all Sass placeholders have moved from the
utilities/mixinsfile to its ownutilities/extendsfile.The Sass placeholders are:
%control%unselectable%arrow%block%delete%loader%overlayIf you were importing them directly from
utilities/mixins, you'll need to importutilities/extendsinstead.If you were importing
utilities/_allor evenbulma.sassdirectly, no change is required.New features
is-ghostbutton that behaves / looks like a regular linkicon-textcomponent, to combine an icon with text on its sideBug fixes
columnoffsets in RTLwidth: unsetfor narrow columnsmixinsimports, created a singleextendsfile.sassfile extension have been removed, since they're unnecessary when there's no ambiguity between a.sassfile or a.scssfileImprovements
$media-*variables, set to!defaultNew features
is-clickablehelper$navbar-colors,$button-colors,$notification-colors,$progress-colors,$table-colors,$tag-colors,$file-colors,$textarea-colors,$select-colors,$form-colors,$label-colorsand$hero-colorsImprovements
$card-radiusvariable$card-overflowvariable$codelistings more accessible$modal-breakpointvariable for modal breakpointoptgrouptogeneric.sassDeprecation warning
The
base/helpers.sassfile is deprecated. It has moved into its own/helpersfolder. If you were importingbase/helpers.sassorbase/_all.sass, please importsass/helpers/_all.sassnow.If you were simply importing the whole of Bulma with
@ import "~/bulma/bulma.sass"or similar, you won't have to change anything, and everything will work as before.The
listcomponent is also deprecated: thecomponents/list.sassfile has been deleted. It was never officialy supported as it was too similar topanelcomponent. Use that one instead.RTL support
Bulma now has RTL support.
By setting the Sass flag
$rtltotrue, you can create an RTL version of Bulma, thanks to 4 new Sass mixins:=ltr=rtl=ltr-property($property, $spacing, $right: true)=ltr-position($spacing, $right: true)The Bulma package now also comes with a
bulma-rtl.cssandbulma-rtl.min.cssfile to be used straight away.Spacing helpers
Bulma now has spacing helpers: https://bulma.io/documentation/helpers/spacing-helpers/
Bulma provides margin
m*and paddingp*helpers in all directions:*tfor top*rfor right*bfor bottom*lfor left*xhorizontally for both left and right*yvertically for both top and bottomYou need to combine a margin/padding prefix with a direciton suffix. For example:
margin-top, usemt-*padding-bottom, usepb-*margin-leftandmargin-right, usemx-*Each of these
property-directioncombinations needs to be appended with one of 6 value suffixesThis release also includes the following helpers:
Improvements
is-vcenteredBug fixes
is-toggletagThis is a minor release. See 0.8.1 release notes for additional information.
Bug fixes
$input-color: $text-strongImprovements
notificationelementherobulmaRgba()function to supportinheritvalue$button-text-decorationvariableBug fixes
$panel-colorsvariableRead more
Read more
Commit messages
Package name: bulma
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs