Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Security upgrade react-native from 0.57.3 to 0.69.12 #140

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

titanism
Copy link
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • example/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BABELHELPERS-9397697
  738  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

Copy link

New, updated, and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/arr-diff@1.1.02.0.0 None 0 5.32 kB jonschlinkert
npm/arr-union@2.1.03.1.0 None 0 6.66 kB jonschlinkert
npm/asn1@0.2.4 None 0 18 kB melloc
npm/assert-plus@1.0.0 environment 0 11.4 kB pfmooney
npm/asynckit@0.4.0 None 0 27.4 kB alexindigo
npm/bcrypt-pbkdf@1.0.2 None +1 203 kB arekinath
npm/browser-process-hrtime@0.1.3 None 0 3.26 kB kumavis
npm/commander@2.19.02.13.0 None 0 56.1 kB abetomo
npm/dashdash@1.14.1 environment, filesystem 0 80.6 kB trentm
npm/deep-is@0.1.3 None 0 8.22 kB thlorenz
npm/delayed-stream@1.0.0 None 0 8.02 kB apechimp
npm/ecc-jsbn@0.1.2 None 0 27.8 kB aduh95
npm/extend-shallow@1.1.43.0.2 None +1 15.6 kB phated
npm/extsprintf@1.3.0 None 0 22.8 kB dap
npm/fbjs@1.0.00.8.17 Transitive: eval +1 1.61 MB fb
npm/finalhandler@1.1.01.1.1 None 0 16.9 kB dougwilson
npm/gauge@1.2.72.7.4 None 0 48.3 kB iarna
npm/getpass@0.1.7 filesystem 0 5.67 kB arekinath
npm/globals@9.18.0 None 0 33.7 kB sindresorhus
npm/har-schema@2.0.0 None 0 15.1 kB ahmadnassri
npm/iconv-lite@0.4.23 None 0 336 kB ashtuchkin
npm/image-size@0.5.5 filesystem 0 19.2 kB netroy
npm/react-native@0.57.30.69.12 environment, network Transitive: eval, filesystem, shell, unsafe +468 254 MB react-native-bot

🚮 Removed packages: npm/@babel/plugin-check-constants@7.0.0-beta.38, npm/@babel/plugin-external-helpers@7.0.0, npm/ansi-colors@1.1.0, npm/ansi-cyan@0.1.1, npm/ansi-gray@0.1.1, npm/ansi-red@0.1.1, npm/ansi-wrap@0.1.0, npm/ansi@0.3.1, npm/array-filter@0.0.1, npm/array-map@0.0.0, npm/array-reduce@0.0.0, npm/array-slice@0.2.3, npm/art@0.10.3, npm/babel-helper-builder-react-jsx@6.26.0, npm/babel-helper-call-delegate@6.24.1, npm/babel-helper-define-map@6.26.0, npm/babel-helper-function-name@6.24.1, npm/babel-helper-get-function-arity@6.24.1, npm/babel-helper-hoist-variables@6.24.1, npm/babel-helper-optimise-call-expression@6.24.1, npm/babel-helper-replace-supers@6.24.1, npm/babel-plugin-check-es2015-constants@6.22.0, npm/babel-plugin-syntax-class-properties@6.13.0, npm/babel-plugin-syntax-flow@6.18.0, npm/babel-plugin-syntax-jsx@6.18.0, npm/babel-plugin-transform-class-properties@6.24.1, npm/babel-plugin-transform-es2015-arrow-functions@6.22.0, npm/babel-plugin-transform-es2015-block-scoped-functions@6.22.0, npm/babel-plugin-transform-es2015-block-scoping@6.26.0, npm/babel-plugin-transform-es2015-classes@6.24.1, npm/babel-plugin-transform-es2015-computed-properties@6.24.1, npm/babel-plugin-transform-es2015-destructuring@6.23.0, npm/babel-plugin-transform-es2015-for-of@6.23.0, npm/babel-plugin-transform-es2015-function-name@6.24.1, npm/babel-plugin-transform-es2015-literals@6.22.0, npm/babel-plugin-transform-es2015-modules-commonjs@6.26.2, npm/babel-plugin-transform-es2015-object-super@6.24.1, npm/babel-plugin-transform-es2015-parameters@6.24.1, npm/babel-plugin-transform-es2015-shorthand-properties@6.24.1, npm/babel-plugin-transform-es2015-spread@6.22.0, npm/babel-plugin-transform-es2015-template-literals@6.22.0, npm/babel-plugin-transform-es3-member-expression-literals@6.22.0, npm/babel-plugin-transform-es3-property-literals@6.22.0, npm/babel-plugin-transform-flow-strip-types@6.22.0, npm/babel-plugin-transform-object-rest-spread@6.26.0, npm/babel-plugin-transform-react-display-name@6.25.0, npm/babel-plugin-transform-react-jsx@6.24.1, npm/babel-plugin-transform-strict-mode@6.24.1, npm/big-integer@1.6.36, npm/bplist-creator@0.0.7, npm/bplist-parser@0.1.1, npm/color-support@1.1.3, npm/create-react-class@15.6.3, npm/eventemitter3@3.1.0, npm/fancy-log@1.3.2, npm/fbjs-css-vars@1.0.1, npm/fbjs-scripts@0.8.3, npm/is-dotfile@1.0.3, npm/is-equal-shallow@0.1.3, npm/is-extendable@0.1.1, npm/is-extglob@1.0.0, npm/is-finite@1.0.2, npm/is-generator-fn@1.0.0, npm/is-plain-object@2.0.4, npm/is-posix-bracket@0.1.1, npm/is-primitive@2.0.0, npm/is-promise@2.1.0, npm/is-regex@1.0.4, npm/is-symbol@1.0.2, npm/is-typedarray@1.0.0, npm/is-utf8@0.2.1, npm/is-windows@1.0.2, npm/is-wsl@1.1.0, npm/isarray@1.0.0, npm/isexe@2.0.0, npm/isomorphic-fetch@2.2.1, npm/isstream@0.1.2, npm/istanbul-api@1.3.7, npm/istanbul-lib-coverage@1.2.1, npm/istanbul-lib-hook@1.2.2, npm/istanbul-lib-instrument@1.10.2, npm/istanbul-lib-report@1.1.5, npm/istanbul-lib-source-maps@1.2.6, npm/istanbul-reports@1.5.1, npm/jest-changed-files@23.4.2, npm/jest-cli@23.6.0, npm/jest-config@23.6.0, npm/jest-diff@23.6.0, npm/jest-docblock@23.2.0, npm/jest-each@23.6.0, npm/jest-environment-jsdom@23.4.0, npm/jest-environment-node@23.4.0, npm/jest-haste-map@23.5.0, npm/jest-jasmine2@23.6.0, npm/jest-leak-detector@23.6.0, npm/jest-matcher-utils@23.6.0, npm/jest-message-util@23.4.0, npm/jest-mock@23.2.0, npm/jest-resolve-dependencies@23.6.0, npm/jest-resolve@23.6.0, npm/jest-runner@23.6.0, npm/jest-runtime@23.6.0, npm/jest-snapshot@23.6.0, npm/jest-watcher@23.4.0, npm/jest@23.6.0, npm/js-levenshtein@1.1.4, npm/jsdom@11.12.0, npm/json-parse-better-errors@1.0.2, npm/json-stable-stringify@1.0.1, npm/json-stringify-safe@5.0.1, npm/jsonify@0.0.0, npm/lcid@1.0.0, npm/left-pad@1.3.0, npm/load-json-file@2.0.0, npm/loader-runner@2.3.1, npm/lodash.debounce@4.0.8, npm/lodash.pad@4.5.1, npm/lodash.padend@4.6.1, npm/lodash.padstart@4.6.1, npm/lodash.toarray@4.4.0, npm/log-update@2.3.0, npm/loose-envify@1.4.0, npm/makeerror@1.0.11, npm/map-cache@0.2.2, npm/map-obj@2.0.0, npm/map-visit@1.0.0, npm/math-random@1.0.1, npm/md5.js@1.3.5, npm/media-typer@0.3.0, npm/mem@1.1.0, npm/memory-fs@0.4.1, npm/merge-descriptors@1.0.1, npm/merge@1.2.0, npm/methods@1.1.2, npm/metro-babel-register@0.48.1, npm/metro-babel7-plugin-react-transform@0.48.1, npm/metro-memory-fs@0.48.1, npm/miller-rabin@4.0.1, npm/min-document@2.19.0, npm/minimatch@3.0.4, npm/minimist@1.2.0, npm/minizlib@1.1.1, npm/mississippi@2.0.0, npm/mixin-deep@1.3.1, npm/mkdirp@0.5.1, npm/morgan@1.9.1, npm/move-concurrently@1.0.1, npm/multi-progress@2.0.0, npm/mute-stream@0.0.7, npm/nan@2.11.1, npm/nanomatch@1.2.13, npm/natural-compare@1.4.0, npm/needle@2.2.4, npm/neo-async@2.5.2, npm/node-emoji@1.8.1, npm/node-int64@0.4.0, npm/node-libs-browser@2.1.0, npm/node-modules-regexp@1.0.0, npm/node-notifier@5.2.1, npm/node-pre-gyp@0.10.3, npm/nopt@4.0.1, npm/normalize-package-data@2.4.0, npm/npm-bundled@1.0.5, npm/npm-packlist@1.1.12, npm/npmlog@2.0.4, npm/number-is-nan@1.0.1, npm/nwsapi@2.0.9, npm/oauth-sign@0.9.0, npm/object-assign@4.1.1, npm/object-copy@0.1.0, npm/object-keys@1.0.12, npm/object-visit@1.0.1, npm/object.getownpropertydescriptors@2.0.3, npm/object.omit@2.0.1, npm/object.pick@1.3.0, npm/on-finished@2.3.0, npm/once@1.4.0, npm/open-in-editor@2.2.0, npm/opn@3.0.3, npm/optimist@0.6.1, npm/optionator@0.8.2, npm/options@0.0.6, npm/os-browserify@0.3.0, npm/os-homedir@1.0.2, npm/os-locale@2.1.0, npm/osenv@0.1.5, npm/pako@1.0.6, npm/parallel-transform@1.1.0, npm/parse-asn1@5.1.1, npm/parse-glob@3.0.4, npm/parse5@4.0.0, npm/pascalcase@0.1.1, npm/path-browserify@0.0.0, npm/path-dirname@1.0.2, npm/path-to-regexp@0.1.7, npm/path-type@2.0.0, npm/pbkdf2@3.0.17, npm/pegjs@0.10.0, npm/performance-now@2.1.0, npm/pify@3.0.0, npm/pinkie-promise@2.0.1, npm/pinkie@2.0.4, npm/platform-select@1.1.2, npm/plist@3.0.1, npm/plugin-error@0.1.2, npm/pn@1.1.0, npm/posix-character-classes@0.1.1, npm/preserve@0.2.0, npm/private@0.1.8, npm/process-nextick-args@2.0.0, npm/process@0.5.2, npm/progress@1.1.8, npm/promise-inflight@1.0.1, npm/prop-types@15.6.2, npm/proxy-addr@2.0.4, npm/prr@1.0.1, npm/pseudomap@1.0.2, npm/psl@1.1.29, npm/public-encrypt@4.0.3, npm/pumpify@1.5.1, npm/punycode@1.4.1, npm/qs@6.5.2, npm/querystring-es3@0.2.1, npm/querystring@0.2.0, npm/quick-lru@1.1.0, npm/randomatic@3.1.0, npm/randomfill@1.0.4, npm/range-parser@1.2.0, npm/raw-body@2.3.3, npm/rc@1.2.8, npm/react-clone-referenced-element@1.1.0, npm/react-deep-force-update@1.1.2, npm/react-hot-loader@4.3.11, npm/react-lifecycles-compat@3.0.4, npm/react-proxy@1.1.8, npm/react-reconciler@0.3.0-beta.1, npm/react-timer-mixin@0.13.4, npm/react-transform-hmr@1.0.4, npm/read-pkg-up@2.0.0, npm/read-pkg@2.0.0, npm/readdirp@2.2.1, npm/realpath-native@1.0.2, npm/regex-cache@0.4.4, npm/regex-not@1.0.2, npm/remove-trailing-separator@1.1.0, npm/repeat-element@1.1.3, npm/repeating@2.0.1, npm/request-promise-core@1.1.1, npm/request-promise-native@1.0.5, npm/request@2.88.0, npm/require-directory@2.1.1, npm/require-main-filename@1.0.1, npm/resolve-cwd@2.0.0, npm/resolve-url@0.2.1, npm/ret@0.1.15, npm/rsvp@3.6.2, npm/run-async@2.3.0, npm/rx-lite-aggregates@4.0.8, npm/rx-lite@4.0.8, npm/rxjs@5.5.12, npm/safe-regex@1.1.0, npm/safer-buffer@2.1.2, npm/sane@2.5.2, npm/sax@1.1.6, npm/schedule@0.3.0, npm/send@0.16.2, npm/serialize-javascript@1.5.0, npm/serve-static@1.13.2, npm/set-blocking@2.0.0, npm/set-value@2.0.0, npm/setimmediate@1.0.5, npm/setprototypeof@1.1.0, npm/shallowequal@1.1.0, npm/shebang-command@1.2.0, npm/shebang-regex@1.0.0, npm/shellwords@0.1.1, npm/simple-plist@0.2.1, npm/simple-progress-webpack-plugin@1.1.2, npm/slide@1.1.6, npm/snapdragon-node@2.1.1, npm/snapdragon-util@3.0.1, npm/snapdragon@0.8.2, npm/source-list-map@2.0.1, npm/source-map-resolve@0.5.2, npm/source-map-url@0.4.0, npm/spdx-correct@3.0.2, npm/spdx-exceptions@2.2.0, npm/spdx-expression-parse@3.0.0, npm/spdx-license-ids@3.0.1, npm/split-string@3.1.0, npm/sprintf-js@1.0.3, npm/ssri@5.3.0, npm/stack-utils@1.0.1, npm/static-extend@0.1.2, npm/stealthy-require@1.1.1, npm/stream-browserify@2.0.1, npm/stream-buffers@2.2.0, npm/stream-each@1.2.3, npm/stream-http@2.8.3, npm/stream-shift@1.0.0, npm/string-length@2.0.0, npm/string_decoder@1.1.1, npm/strip-bom@3.0.0, npm/strip-eof@1.0.0, npm/strip-json-comments@2.0.1, npm/symbol-observable@1.0.1, npm/symbol-tree@3.2.2, npm/tar@4.4.6, npm/test-exclude@4.2.3, npm/thread-loader@1.2.0, npm/through2@2.0.3, npm/through@2.3.8, npm/time-stamp@1.1.0, npm/timers-browserify@2.0.10, npm/tmp@0.0.33, npm/tmpl@1.0.4, npm/to-arraybuffer@1.0.1, npm/to-object-path@0.3.0, npm/to-regex@3.0.2, npm/trim-right@1.0.1, npm/tty-browserify@0.0.0, npm/tunnel-agent@0.6.0, npm/type-is@1.6.16, npm/typedarray@0.0.6, npm/ua-parser-js@0.7.18, npm/uglify-es@3.3.9, npm/uglify-js@3.4.9, npm/uglifyjs-webpack-plugin@1.3.0, npm/ultron@1.0.2, npm/union-value@1.0.0, npm/unique-filename@1.1.1, npm/unique-slug@2.0.1, npm/unpipe@1.0.0, npm/unset-value@1.0.0, npm/upath@1.1.0, npm/uri-js@4.2.2, npm/urix@0.1.0, npm/url@0.11.0, npm/use@3.1.1, npm/util-deprecate@1.0.2, npm/util.promisify@1.0.0, npm/utils-merge@1.0.1, npm/uuid@3.0.1, npm/validate-npm-package-license@3.0.4, npm/vary@1.1.2, npm/vm-browserify@0.0.4, npm/w3c-hr-time@1.0.1, npm/walker@1.0.7, npm/watch@0.18.0, npm/watchpack@1.6.0, npm/webidl-conversions@4.0.2, npm/webpack-hot-middleware@2.24.3, npm/webpack-sources@1.3.0, npm/webpack@4.20.2, npm/whatwg-fetch@3.0.0, npm/whatwg-mimetype@2.2.0, npm/which-module@2.0.0, npm/wide-align@1.1.3, npm/wordwrap@1.0.0, npm/worker-farm@1.6.0, npm/wrappy@1.0.2, npm/write-file-atomic@1.3.4, npm/xcode@0.9.3, npm/xml-name-validator@3.0.0, npm/xmlbuilder@9.0.7, npm/xmldoc@0.4.0, npm/xmldom@0.1.27, npm/xpipe@1.0.5, npm/xtend@4.0.1, npm/yallist@2.1.2

View full report↗︎

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants