Skip to content
This repository has been archived by the owner on Jan 20, 2024. It is now read-only.

[Snyk] Security upgrade react-native from 0.64.3 to 0.65.0 #473

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

filiptronicek
Copy link
Member

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • yarn.lock

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
critical severity 786/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service (DoS)

Copy link

yarn.lock changes

Summary

Status Count
ADDED 7
UPDATED 69
DOWNGRADED 4
REMOVED 19
Click to toggle table visibility
Name Status Previous Current
@ampproject/remapping UPDATED 2.1.2 2.2.1
@babel/code-frame UPDATED 7.16.7 7.23.5
@babel/compat-data UPDATED 7.17.0 7.23.5
@babel/generator UPDATED 7.17.3 7.23.6
@babel/helper-annotate-as-pure UPDATED 7.16.7 7.22.5
@babel/helper-compilation-targets UPDATED 7.16.7 7.23.6
@babel/helper-environment-visitor UPDATED 7.16.7 7.22.20
@babel/helper-function-name UPDATED 7.16.7 7.23.0
@babel/helper-hoist-variables UPDATED 7.16.7 7.22.5
@babel/helper-module-imports UPDATED 7.16.7 7.22.15
@babel/helper-module-transforms UPDATED 7.16.7 7.23.3
@babel/helper-plugin-utils UPDATED 7.16.7 7.22.5
@babel/helper-remap-async-to-generator UPDATED 7.15.4 7.22.20
@babel/helper-simple-access UPDATED 7.16.7 7.22.5
@babel/helper-skip-transparent-expression-wrappers DOWNGRADED 7.16.0 7.15.4
@babel/helper-split-export-declaration UPDATED 7.16.7 7.22.6
@babel/helper-string-parser ADDED - 7.23.4
@babel/helper-validator-identifier UPDATED 7.16.7 7.22.20
@babel/helper-validator-option UPDATED 7.16.7 7.23.5
@babel/helper-wrap-function UPDATED 7.15.4 7.22.20
@babel/helpers UPDATED 7.17.2 7.23.6
@babel/highlight UPDATED 7.16.10 7.23.4
@babel/parser UPDATED 7.17.3 7.23.6
@babel/plugin-syntax-flow DOWNGRADED 7.16.0 7.12.13
@babel/plugin-transform-flow-strip-types DOWNGRADED 7.16.0 7.13.0
@babel/preset-flow REMOVED 7.16.0 -
@babel/template UPDATED 7.16.7 7.22.15
@babel/traverse UPDATED 7.17.3 7.23.6
@babel/types UPDATED 7.17.0 7.23.6
@jest/create-cache-key-function UPDATED 26.6.2 27.5.1
@jridgewell/gen-mapping ADDED - 0.3.3
@jridgewell/resolve-uri UPDATED 3.0.5 3.1.1
@jridgewell/set-array ADDED - 1.1.2
@jridgewell/sourcemap-codec UPDATED 1.4.11 1.4.15
@jridgewell/trace-mapping UPDATED 0.3.4 0.3.20
@react-native-community/cli UPDATED 5.0.1 6.4.0
@react-native-community/cli-debugger-ui UPDATED 5.0.1 6.0.0
@react-native-community/cli-hermes UPDATED 5.0.1 6.3.1
@react-native-community/cli-platform-android UPDATED 5.0.1 6.3.1
@react-native-community/cli-platform-ios UPDATED 5.0.2 6.2.1
@react-native-community/cli-plugin-metro ADDED - 6.4.0
@react-native-community/cli-server-api UPDATED 5.0.1 6.4.3
@react-native-community/cli-tools UPDATED 5.0.1 6.2.1
@react-native-community/cli-types UPDATED 5.0.1 6.0.0
@xmldom/xmldom UPDATED 0.7.5 0.8.10
array-filter REMOVED 0.0.1 -
array-map REMOVED 0.0.0 -
array-reduce REMOVED 0.0.0 -
ast-types REMOVED 0.14.2 -
babel-core REMOVED 7.0.0-bridge.0 -
babel-preset-fbjs UPDATED 3.3.0 3.4.0
browserslist UPDATED 4.18.1 4.22.2
caniuse-lite UPDATED 1.0.30001282 1.0.30001570
colors REMOVED 1.4.0 -
convert-source-map UPDATED 1.7.0 2.0.0
electron-to-chromium UPDATED 1.3.904 1.4.615
flow-parser REMOVED 0.121.0 -
hermes-engine UPDATED 0.7.2 0.8.1
hermes-parser ADDED - 0.4.7
interpret REMOVED 1.4.0 -
is-core-module DOWNGRADED 2.8.1 2.3.0
jsc-android UPDATED 245459.0.0 250230.2.1
jscodeshift REMOVED 0.11.0 -
json5 UPDATED 2.2.0 2.2.3
jsonify REMOVED 0.0.0 -
metro UPDATED 0.64.0 0.66.2
metro-babel-register UPDATED 0.64.0 0.66.2
metro-babel-transformer UPDATED 0.64.0 0.66.2
metro-cache UPDATED 0.64.0 0.66.2
metro-cache-key UPDATED 0.64.0 0.66.2
metro-config UPDATED 0.64.0 0.66.2
metro-core UPDATED 0.64.0 0.66.2
metro-hermes-compiler UPDATED 0.64.0 0.66.2
metro-inspector-proxy UPDATED 0.64.0 0.66.2
metro-minify-uglify UPDATED 0.64.0 0.66.2
metro-react-native-babel-preset UPDATED 0.64.0 0.66.2
metro-react-native-babel-transformer UPDATED 0.64.0 0.66.2
metro-resolver UPDATED 0.64.0 0.66.2
metro-runtime UPDATED 0.64.0 0.66.2
metro-source-map UPDATED 0.64.0 0.66.2
metro-symbolicate UPDATED 0.64.0 0.66.2
metro-transform-plugins UPDATED 0.64.0 0.66.2
metro-transform-worker UPDATED 0.64.0 0.66.2
neo-async REMOVED 2.6.2 -
node-dir REMOVED 0.1.17 -
node-releases UPDATED 2.0.1 2.0.14
ob1 UPDATED 0.64.0 0.66.2
plist UPDATED 3.0.4 3.1.0
react-native UPDATED 0.64.3 0.65.0
react-native-codegen REMOVED 0.0.6 -
readline ADDED - 1.3.0
recast REMOVED 0.20.5 -
rechoir REMOVED 0.6.2 -
shell-quote UPDATED 1.7.2 1.8.1
shelljs REMOVED 0.8.5 -
supports-preserve-symlinks-flag REMOVED 1.0.0 -
tslib REMOVED 2.3.1 -
update-browserslist-db ADDED - 1.0.13
xmlbuilder UPDATED 14.0.0 15.1.1

Copy link

App is ready for review, you can see it here.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants