Bump jspdf from 3.0.1 to 3.0.3 in /jbrowse
Closed
Number: #354
Type: Pull Request
State: Closed
Type: Pull Request
State: Closed
Author:
dependabot[bot]
Association: Contributor
Comments: 1
Association: Contributor
Comments: 1
Created:
October 04, 2025 at 02:45 PM UTC
(9 months ago)
(9 months ago)
Updated:
October 07, 2025 at 10:36 PM UTC
(9 months ago)
(9 months ago)
Closed:
October 07, 2025 at 10:36 PM UTC
(9 months ago)
(9 months ago)
Time to Close:
3 days
Labels:
dependencies javascript
dependencies javascript
Description:
Bumps jspdf from 3.0.1 to 3.0.3.
Release notes
Sourced from jspdf's releases.
v3.0.3
This release fixes regressions with PNG encoding that were introduced in v3.0.2.
What's Changed
- Fix division by zero when calculating word spacing by
@alxndr-pggmin parallax/jsPDF#3879- fix scaling of form object bounding boxes by
@HackbrettXXXin parallax/jsPDF#3888- fix regressions in PNG encoding that were introduced in 3.0.2 by
@HackbrettXXXin parallax/jsPDF#3887New Contributors
@alxndr-pggmmade their first contribution in parallax/jsPDF#3879Full Changelog: https://github.com/parallax/jsPDF/compare/v3.0.2...v3.0.3
v3.0.2
This release fixes a security issue where parsing of corrupt PNG images could lead to long running loops and denial of service.
What's Changed
- [Snyk] Upgrade
@babel/runtimefrom 7.26.7 to 7.26.9 by@MrRioin parallax/jsPDF#3847- Fix parsing corrupt PNG images in addImage method by
@HackbrettXXXin parallax/jsPDF#3880. The atob and btoa dependencies have been removed and the fast-png dependency has been added.New Contributors
@WardenDrewmade their first contribution in parallax/jsPDF#3872Full Changelog: https://github.com/parallax/jsPDF/compare/v3.0.1...v3.0.2
Commits
574a9413.0.39ea590cfix regressions in PNG encoding that were introduced in 3.0.2 (#3887)394d1e7fix scaling of form object bounding boxes (#3888)064194fFix division by zero when calculating word spacing (#3879)543b3563.0.24cf3ab6Fix parsing corrupt PNG images in the addImage method (#3880)7c51caaCorrect the millimeter unit conversion constant in docs (#3872)d8bfc9ffix: upgrade@babel/runtimefrom 7.26.7 to 7.26.9 (#3847)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
Commits:
0
0
Files Changed:
0
0
Additions:
+0
+0
Deletions:
-0
-0
Package Dependencies
Technical Details
| ID: | 9816554 |
| UUID: | 3483816825 |
| Node ID: | PR_kwDOCkp7bM6sGLPE |
| Host: | GitHub |
| Repository: | BimberLab/DiscvrLabKeyModules |