chore(deps): 19 outdated deps found. Core safe upgrades: axios 0.18→0.21, element-ui - #4370
Open
isagoakira wants to merge 1 commit into
Open
chore(deps): 19 outdated deps found. Core safe upgrades: axios 0.18→0.21, element-ui #4370isagoakira wants to merge 1 commit into
isagoakira wants to merge 1 commit into
Conversation
…upgrades: axios 0.18→0.21,
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔧 依赖维护更新 — PanJiaChen/vue-element-admin
此 PR 由 Code Legacy Reviver 自动生成🤖
📋 更新摘要
19 outdated deps found. Core safe upgrades: axios 0.18→0.21, element-ui 2.13→2.15, vue 2.6→2.6.14, vue-router 3.0→3.5, vuex 3.1→3.6. Also upgrading @vue/cli* 4.4→4.5, sass 1.26→1.32, and several others. Skipped echarts, fuse.js, js-cookie, vuedraggable, xlsx, eslint, babel-jest as they require major version bumps with breaking changes.
📦 变更清单
🔴 axios:
0.18.1→0.21.20.18.1 is from 2019, contains known security issues. 0.21.x is the last stable 0.x line with security fixes.
🔴 clipboard:
2.0.4→2.0.82.0.4 is several patch releases behind within the same major version.
🔴 element-ui:
2.13.2→2.15.142.13.2 (Mar 2020) is behind within the 2.x line. 2.15.14 is the latest stable 2.x release with bug and security fixes.
🔴 vue:
2.6.10→2.6.142.6.10 has known vulnerabilities (CVE-2021-44903). 2.6.14 is the latest 2.6 patch with security patches.
🔴 vue-router:
3.0.2→3.5.43.0.2 is behind within the 3.x line. 3.5.x is the latest stable 3.x with bug and security fixes.
🔴 vuex:
3.1.0→3.6.53.1.0 is behind within the 3.x line. 3.6.5 is the latest stable 3.x with bug fixes.
🔴 fuse.js:
3.4.4→3.6.13.4.4 is several minor versions behind within 3.x. 3.6.1 is the latest 3.x with improvements and fixes.
🔴 jszip:
3.2.1→3.10.13.2.1 (Feb 2020) is many minor versions behind. 3.10.1 is the latest stable within 3.x with security fixes.
🟡 tui-editor:
1.3.3→1.4.01.3.3 has known security issues. 1.4.0 is a minor bump with security and bug fixes.
🔴 @vue/cli-service:
4.4.4→4.5.194.4.4 has known vulnerabilities. 4.5.19 is the latest 4.x (major 5.x has breaking changes).
🔴 @vue/cli-plugin-babel:
4.4.4→4.5.19Matching version for CLI consistency. 4.5.19 patches known vulnerabilities.
🔴 @vue/cli-plugin-eslint:
4.4.4→4.5.19Matching version for CLI consistency.
🔴 @vue/cli-plugin-unit-jest:
4.4.4→4.5.19Matching version for CLI consistency.
🔴 sass:
1.26.2→1.32.131.26.2 is behind. 1.32.x is the latest 1.x (1.33+ requires Dart Sass 2.0 API). Staying on 1.32 avoids breaking changes.
🔴 sass-loader:
8.0.2→8.0.2Already at latest 8.x. Upgrade would require webpack 4→5 migration which has breaking changes.
🔴 chokidar:
2.1.5→2.1.82.1.5 is several patch versions behind within 2.x. 2.1.8 is the latest 2.x with fixes. Skipping to 3.x requires Node 10+ and has API changes.
🔴 html-webpack-plugin:
3.2.0→3.2.23.2.0 is two patch releases behind. 3.2.2 is the latest 3.x with bug fixes. 5.x requires webpack 5.
🔴 autoprefixer:
9.5.1→9.8.89.5.1 is several minor versions behind within 9.x. 9.8.8 is the latest stable 9.x. 10.x has breaking browserslist config changes.
🔴 svg-sprite-loader:
4.1.3→4.3.14.1.3 is behind within 4.x. 4.3.1 is the latest 4.x with fixes.
🟡 Medium
📝 文件变更
package.jsonGenerated by Code Legacy Reviver