Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade redux-thunk from 2.3.0 to 2.4.2 #3

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mun1013
Copy link
Owner

@mun1013 mun1013 commented Aug 2, 2024

snyk-top-banner

Snyk has created this PR to upgrade redux-thunk from 2.3.0 to 2.4.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 3 versions ahead of your current version.

  • The recommended version was released on 2 years ago.

Release notes
Package name: redux-thunk
  • 2.4.2 - 2022-11-04

    This release removes an unused TS type that caused errors when users were type-checking libraries in node_modules.

    What's Changed

    Full Changelog: v2.4.1...v2.4.2

  • 2.4.1 - 2021-11-26

    This release adds an explicit plain action overload to the ThunkDispatch TS type to better handle inference of the return value in some cases.

    What's Changed

    Full Changelog: v2.4.0...v2.4.1

  • 2.4.0 - 2021-10-26

    This very overdue release makes several major improvements to the TypeScript types, and converts the actual source to TypeScript. Sorry for the delay!

    Changelog

    TypeScript Improvements

    This release fixes several outstanding issues that had been reported with the types. An extra overload has been added to let TS correctly understand some generically-typed values being passed to dispatch, and the overloads have been reworked for additional compatibility.

    There's also a new ThunkActionDispatch type that can be used to represent how bindActionCreators turns bound thunks into (arg) => thunkReturnValue.

    Additionally, all of the generic args have been giving meaningful names instead of one-letter abbreviations (S -> State, E -> ExtraArgument, etc), and we've added descriptive comments in the type definitions for clarity.

    Optional Global Dispatch Type Extension

    Most Redux apps have the thunk middleware enabled, but the default Dispatch and bindActionCreator types only know about the standard behavior of a basic Redux store without any middleware. The thunk middleware types add to that type behavior, so that Dispatch knows dispatching a thunk can actually return a value such as a Promise.

    We generally recommend inferring the type of dispatch and using that to create reusable types, including creating pre-typed hooks. However, some users may prefer to globally augment the Dispatch type to always use the additional thunk behavior.

    You can now import 'redux-thunk/extend-redux' to globally augment the Dispatch type as an opt-in change in behavior.

    Codebase Converted to TypeScript

    We've gone ahead and converted the actual source to TS. Since the source was only 15-ish lines to begin with, most of the "conversion" time was just trying to convince TS that assigning thunk.extraArgument = createThunkMiddleware was a legal operation :)

    We also updated the build tooling:

    • Babel updates
    • Rollup for the UMDs instead of Webpack
    • Github Actions for CI instead of Travis

    Finally, the README has been updated with newer instructions and usage information.

    What's Changed

    New Contributors

    Full Changelog: v2.3.0...v2.4.0

  • 2.3.0 - 2018-05-28

    Hello! There's a new sheriff in town...

    This is only an update to the TypeScript typings for Redux 4.0 compatibility. After some discussion on the issues/PRs, we're going to be removing the typings completely in a 3.0 release soon. They will instead live in DefinitelyTyped, where they can be updated to match newer version of TypeScript and Redux at whatever pace they want to take. Farewell, typings! 🖖

from redux-thunk GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade redux-thunk from 2.3.0 to 2.4.2.

See this package in npm:
redux-thunk

See this project in Snyk:
https://app.snyk.io/org/mun1013/project/c91eacc6-9bfb-4a42-a066-16a1ef33d838?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants