react-native-PDFView icon indicating copy to clipboard operation
react-native-PDFView copied to clipboard

[Snyk] Security upgrade react-native from 0.69.4 to 0.72.0

Open rumax opened this issue 1 year ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • demo/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
No No Known Exploit
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-native The new version differs by 250 commits.
  • 7a893e4 [0.72.0] Bump version numbers
  • 3863877 [LOCAL] update podfile.lock
  • ec4771b [0.72.0-rc.6] Bump version numbers
  • a2df07e [LOCAL] bump CLI to 11.3.2
  • b2f2737 bumped packages versions
  • 0817eaa Revert "fix: border width top/bottom not matching the border radius" (#37840)
  • 0da7e06 Remove CallInvoker parameter from toJs method in Codegen (#37832)
  • 2d15f50 Fix Android border clip check (#37828)
  • 2760042 Fix loading NODE_BINARY inside Generate Legacy Components Interop (#37802)
  • 8ed2cfd Add support for building with Xcode 15 (#37758)
  • 73f4a78 Fixed random styling for text nodes with many children (#36656)
  • dfc64d5 Fix copy / paste menu and simplify controlled text selection on Android (#37424)
  • bab5bab [LOCAL] bump hermes podlock
  • a98c7c6 [0.72.0-rc.5] Bump version numbers
  • 7dc11bc bumped packages versions
  • e11396e [0.72.0-rc.4] Bump version numbers
  • 60a452b [LOCAL] Fix performance issues in Hermes when Debug
  • 32327cc [LOCAL] Fix hermesc for linux (#37591)
  • 52d2065 [LOCAL] Make sure Java Toolchain and source/target level is applied to all projects (#37576)
  • e0c88fe [LOCAL] Fix Ruby tests
  • a4aaee0 [LOCAL] Remove double definition of task wrapper after merge conflict
  • 74e3803 bumped packages versions
  • 7c5dc1d [LOCAL] bump metro to 0.76.5 and CLI to 11.3.1
  • c43bd7a Do not use setNativeState in RuntimeScheduler::Task

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled resource consumption

rumax avatar May 13 '24 21:05 rumax