Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #49

Open
wants to merge 1 commit into
base: dev
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-NODEFETCH-2342118
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-native The new version differs by 250 commits.
  • ace025d [0.64.0] Bump version numbers
  • 728d55a Fixing the git attrs for all the people and all the files and all future 馃檶
  • 8a6ac1f chore: Update React.podspec to require cocoapods >= 1.10.1
  • 138fdbc fix: restore refresh control fix
  • 7f3f80f Fix RefreshControl layout when removed from window (#31024)
  • 1aa4f47 [0.64.0-rc.4] Bump version numbers
  • 48a97d7 chore: fix conflict in Podfile.lock
  • e7e4b00 fix: disable fabric
  • 14db556 fix: React Native CodeGen integration for 0.64-stable (#31027)
  • 4b68734 Generalize node search logic
  • 7159bcb Update flipper in RNTester and template (#31010)
  • e846740 [0.64.0-rc.3] Bump version numbers
  • c023a40 chore: bump codegen script
  • 7004cac Invoke `node` directly in generate-specs.sh (#30781)
  • 5ada078 Make codegen more reliable on iOS (#30792)
  • 937ced3 Optionally override codegen script defaults via envvars
  • e5888de Add use_react_native_codegen!
  • 0636c45 Use Fabric builds in iOS tests (#30639)
  • 224c85a Update iOS Fabric-related files to compile on OSS (#29810)
  • 7ec38b9 Avoid eating clicks/taps into ScrollView when using physical keyboard (#30374)
  • 052447c Remove dependency on Folly in TurboModuleUtils.h (#30672)
  • 70ba9ac Expose the testID to black-box testing frameworks on Android (#29610)
  • 1eb7d4a [0.64.0-rc.2] Bump version numbers
  • 4481d09 Fix infinite loop in KeyboardAvoidingView

See the full diff

Package name: react-navigation The new version differs by 113 commits.
  • 8bd25cf Bump to 1.0.0
  • 20af8c6 Prevent push from bubbling up (#3454)
  • b0dccd7 Prevent pop and popToTop from bubbling up to parent stack (#3453)
  • c69a22f Bump version
  • 43a1c5d Fix issue with StackRouter popToTop (#3451)
  • e97d41c Bump version and update description
  • 3e4ddc6 Remove Header.HEIGHT deprecation warning, no good alternative solution available yet
  • f62c728 Bump version
  • 616f9a5 Fix StackRouter Replace Key Behavior (#3450)
  • 3b93faa Bump version
  • 333b2e4 StackNavigator Replace Action (#3440)
  • 7f50173 Bump version
  • 8432f67 Add adaptive to TabBarBottom flow interface
  • c72b44c Fix focus event for initial screen (#3448)
  • 149f5f5 Fix #2795 - Not reducing header height in landscape on iPad (#3251)
  • 85f77fe Issue #2794 - Tab bar fix - Continued from #3041 (#3267)
  • d4b7596 remove $FlowFixMe comments left over, as flow is no longer used (#3439)
  • 4d2609f Use a stack inside of drawer
  • 0766ec9 Bump version
  • 0759e8c Fix tests
  • fae1f71 Key for completion action, to prevent eager didFocus (#3435)
  • 03fbd98 Fix Transitioner race condition (#3434)
  • 63a6565 Fix incorrect easing functions for CardStack (#3381)
  • 154aa85 remove unuseful SafeAreaView component (#3428)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
馃 View latest project report

馃洜 Adjust project settings

馃摎 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-NODEFETCH-2342118
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant