pnp / pnp/sp-dev-fx-controls-react

Update vulnerable dependencies: swiper (8.4.7) and lodash (4.17.23)

Open Beginner friendly
#2,127 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
433
Forks
418
Avg merge
5d 6m
Merged PRs (30d)
19

Description

Category
[x] Enhancement

Version
Please specify what version of the library you are using: @pnp/spfx-controls-react@3.25.0

Expected / Desired Behavior / Question

The library currently references vulnerable versions of two dependencies, swiper and lodash, which flag as security vulnerabilities in dependency scans:
swiper — currently 8.4.7, fixed in 12.1.2
lodash — currently 4.17.23, fixed in 4.18.1

Requesting that both dependencies be updated to their latest non-vulnerable versions in package.json.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with package.json in the @pnp/spfx-controls-react@3.25.0 project and inspect the swiper and lodash dependency entries. Update both to the requested non-vulnerable versions, then verify that dependency scans no longer flag these vulnerabilities.

Written by the indexing model from the issue text.

Assessment

Tech stack
react, typescript
Domain
frontend, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.