Skip to content

chore(deps): bump react-slick from 0.24.0 to 0.31.0 in /modules/gutenberg in the gutenberg-prod-minor group#90

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/modules/gutenberg/gutenberg-prod-minor-200da2a6af
Open

chore(deps): bump react-slick from 0.24.0 to 0.31.0 in /modules/gutenberg in the gutenberg-prod-minor group#90
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/modules/gutenberg/gutenberg-prod-minor-200da2a6af

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the gutenberg-prod-minor group in /modules/gutenberg with 1 update: react-slick.

Updates react-slick from 0.24.0 to 0.31.0

Release notes

Sourced from react-slick's releases.

0.31.0

  • Fixed extra clones issue
  • Extra height of slider in vertical mode when number of slides is less than or equal to slidesToShow issue

0.30.3

Merged #2408 and #2366 PRs

0.30.2

Fixed issues #2076 and #2344

0.30.1

Fixed issues #1874 and #2315

0.30.0

  • Fixed #1813
  • Migrated tests from enzyme to react-testing-library
  • Migrated examples from class components to function components

0.29.0

Upgraded dependencies to support React 18

0.28.0

Fixes for #1650

Merged PR's: #1967 #1971

0.27.14

Fixed #1830

0.27.10

No release notes provided.

0.27.9

No release notes provided.

0.27.8

No release notes provided.

0.27.7

No release notes provided.

0.27.6

No release notes provided.

0.27.5

No release notes provided.

0.27.4

Fixed an issue with uneven sets in focusOnSelect mode

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the gutenberg-prod-minor group in /modules/gutenberg with 1 update: [react-slick](https://github.com/akiran/react-slick).


Updates `react-slick` from 0.24.0 to 0.31.0
- [Release notes](https://github.com/akiran/react-slick/releases)
- [Changelog](https://github.com/akiran/react-slick/blob/master/CHANGELOG.md)
- [Commits](akiran/react-slick@0.24.0...0.31.0)

---
updated-dependencies:
- dependency-name: react-slick
  dependency-version: 0.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gutenberg-prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 2, 2026
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Prototype Pollution in npm lodash

CVE: GHSA-jf85-cpcp-j695 Prototype Pollution in lodash (CRITICAL)

Affected versions: < 4.17.12

Patched version: 4.17.12

From: modules/gutenberg/package-lock.jsonnpm/grunt-json2php@0.1.4npm/lodash@2.4.2

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/lodash@2.4.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@dependabot @github

dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot attempted to update this pull request, but because the branch dependabot/npm_and_yarn/modules/gutenberg/gutenberg-prod-minor-200da2a6af is protected it was unable to do so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants