Skip to content

[Snyk] Upgrade @fontsource/lato from 5.2.7 to 5.3.0 - #2681

Closed
zachsis wants to merge 1 commit into
masterfrom
snyk-upgrade-dafea5c9b69ca5d8b25dd33fc1379c2c
Closed

[Snyk] Upgrade @fontsource/lato from 5.2.7 to 5.3.0#2681
zachsis wants to merge 1 commit into
masterfrom
snyk-upgrade-dafea5c9b69ca5d8b25dd33fc1379c2c

Conversation

@zachsis

@zachsis zachsis commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to upgrade @fontsource/lato from 5.2.7 to 5.3.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.

  • The recommended version was released 22 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Integer Overflow
SNYK-JS-SHARP-18184259
300 No Known Exploit
high severity Heap-based Buffer Overflow
SNYK-JS-SHARP-18184418
300 No Known Exploit
high severity Infinite loop
SNYK-JS-NANOID-18506897
300 No Known Exploit
high severity Infinite loop
SNYK-JS-NANOID-18506894
300 No Known Exploit
medium severity Integer Overflow
SNYK-JS-SHARP-18184262
300 No Known Exploit
medium severity Out-of-bounds Read
SNYK-JS-SHARP-18184416
300 No Known Exploit

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.

Release notes
Package name: @fontsource/lato
  • 5.3.0 - 2026-07-19
  • 5.2.7 - 2025-09-17
from @fontsource/lato GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade @fontsource/lato from 5.2.7 to 5.3.0.

See this package in npm:
@fontsource/lato

See this project in Snyk:
https://app.snyk.io/org/instructure/project/0b0d106a-e39a-450e-b2b1-7f66819e4808?utm_source=github&utm_medium=referral&page=upgrade-pr
@zachsis

zachsis commented Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

Merge Risk: Low

This is a minor version upgrade for the @fontsource/lato package. Updates in this range for Fontsource packages typically include routine updates to the underlying font files from the upstream provider or minor package improvements. No breaking changes, such as removed weights or renamed files, are documented for this version change.

Source: Package documentation

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1
Preview removed because the pull request was closed.
2026-08-18 09:14 UTC

@balzss

balzss commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

closing in favor of #2691

@balzss balzss closed this Aug 18, 2026
balzss added a commit that referenced this pull request Aug 19, 2026
…lato

Applies the four dependency bumps Snyk opened as #2681, #2684, #2685 and #2686:

  next             16.2.10 -> 16.2.11
  react            19.2.7  -> 19.2.8
  react-dom        19.2.7  -> 19.2.8
  @fontsource/lato ^5.2.7  -> ^5.3.0

The Snyk PRs bumped regression-test/package.json without regenerating the lockfile. This app
is outside the pnpm workspace and uses npm, so the visual-regression workflow installs it with
`npm ci`, which hard-fails when package.json and package-lock.json disagree. Every one of those
PRs therefore died on the "Install regression-test dependencies" step.

Regenerated regression-test/package-lock.json alongside the manifest so `npm ci` resolves again.
The remaining lockfile churn is npm re-nesting @tailwindcss/oxide-wasm32-wasi's bundled deps
rather than hoisting them; no packages were added or dropped.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants