asset-system icon indicating copy to clipboard operation
asset-system copied to clipboard

[Snyk] Security upgrade react-native from 0.52.1 to 0.57.0

Open decompil3d opened this issue 2 years ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • examples/reactnative/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 713/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 6.4
Prototype Pollution
SNYK-JS-JSON5-3182856
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-native The new version differs by 250 commits.
  • 3008c3c [0.57.0] Bump version numbers
  • 7b57b8c Remove view configs from JS
  • 967d478 Require that JS defined Component Attributes match Native ones in dev
  • 499e207 Put View ViewConfig in JS
  • 7525f38 Correct RCTAnimation import (#18050)
  • b77d640 Add the new RCTWKWebView* files to build target on iOS (#21031)
  • 057d3ef Fix #18272 TextInput.setNativeProps({text: ''}) to work (#18278)
  • cf5f3e9 React: Upgrade to [email protected]
  • 0b30129 React sync for revisions bc1ea9c...ade5e69
  • 7b1186c Require all Android View Attributes are defined in flow prop types
  • 3ccc141 Put View ViewConfig in JS
  • cbad158 Adding a more complete type for ReactNativeBaseComponentViewConfig
  • 3c1ffd8 Fix Metro version
  • a88243a React: Upgrade to [email protected]
  • 8402c97 [0.57.0-rc.4] Bump version numbers
  • fd2db95 Remove test dep on publish
  • cb471c7 Revert "[0.57.0-rc.4] Bump version numbers"
  • 9dcc395 [0.57.0-rc.4] Bump version numbers
  • 5ffa4b3 Revert "[0.57.0-rc.4] Bump version numbers"
  • 0943c64 Sync Circle CI config from master
  • 9974d4f [0.57.0-rc.4] Bump version numbers
  • 4382413 Fix flow
  • f28a6bb Revert "[0.57.0-rc.4] Bump version numbers"
  • 6d4970f [0.57.0-rc.4] Bump version numbers

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution

decompil3d avatar Dec 26 '22 02:12 decompil3d