Skip to content
This repository has been archived by the owner on Jan 20, 2024. It is now read-only.

[Snyk] Security upgrade react-native from 0.64.3 to 0.71.0 #474

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

filiptronicek
Copy link
Member

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • yarn.lock

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-ASYNC-2441827
No Proof of Concept
critical severity 786/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
No Proof of Concept
medium severity 641/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.4
Prototype Pollution
SNYK-JS-JSON5-3182856
No Proof of Concept
low severity 506/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 3.7
Prototype Pollution
SNYK-JS-MINIMIST-2429795
No Proof of Concept
medium severity 539/1000
Why? Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-NODEFETCH-2342118
No No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Improper Authorization
SNYK-JS-REACTDEVTOOLSCORE-6023999
No Proof of Concept
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
No Proof of Concept
high severity 619/1000
Why? Has a fix available, CVSS 8.1
Remote Code Execution (RCE)
SNYK-JS-SHELLQUOTE-1766506
No No Known Exploit
medium severity 489/1000
Why? Has a fix available, CVSS 5.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-SIDEWAYFORMULA-3317169
No No Known Exploit
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WS-1296835
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Prototype Pollution
🦉 Remote Code Execution (RCE)

Copy link

yarn.lock changes

Summary

Status Count
ADDED 31
UPDATED 129
DOWNGRADED 1
REMOVED 79
Click to toggle table visibility
Name Status Previous Current
@ampproject/remapping UPDATED 2.1.2 2.2.1
@babel/code-frame UPDATED 7.16.7 7.23.5
@babel/compat-data UPDATED 7.17.0 7.23.5
@babel/core UPDATED 7.17.4 7.23.6
@babel/generator UPDATED 7.17.3 7.23.6
@babel/helper-annotate-as-pure UPDATED 7.16.7 7.22.5
@babel/helper-compilation-targets UPDATED 7.16.7 7.23.6
@babel/helper-create-class-features-plugin UPDATED 7.17.1 7.23.6
@babel/helper-create-regexp-features-plugin UPDATED 7.14.5 7.22.15
@babel/helper-environment-visitor UPDATED 7.16.7 7.22.20
@babel/helper-function-name UPDATED 7.16.7 7.23.0
@babel/helper-hoist-variables UPDATED 7.16.7 7.22.5
@babel/helper-member-expression-to-functions UPDATED 7.16.7 7.23.0
@babel/helper-module-imports UPDATED 7.16.7 7.22.15
@babel/helper-module-transforms UPDATED 7.16.7 7.23.3
@babel/helper-optimise-call-expression UPDATED 7.16.7 7.22.5
@babel/helper-plugin-utils UPDATED 7.16.7 7.22.5
@babel/helper-remap-async-to-generator UPDATED 7.15.4 7.22.20
@babel/helper-replace-supers UPDATED 7.16.7 7.22.20
@babel/helper-simple-access UPDATED 7.16.7 7.22.5
@babel/helper-skip-transparent-expression-wrappers UPDATED 7.16.0 7.22.5
@babel/helper-split-export-declaration UPDATED 7.16.7 7.22.6
@babel/helper-string-parser ADDED - 7.23.4
@babel/helper-validator-identifier UPDATED 7.16.7 7.22.20
@babel/helper-validator-option UPDATED 7.16.7 7.23.5
@babel/helper-wrap-function UPDATED 7.15.4 7.22.20
@babel/helpers UPDATED 7.17.2 7.23.6
@babel/highlight UPDATED 7.16.10 7.23.4
@babel/parser UPDATED 7.17.3 7.23.6
@babel/plugin-syntax-flow UPDATED 7.16.0 7.23.3
@babel/plugin-syntax-jsx UPDATED 7.14.5 7.23.3
@babel/plugin-syntax-typescript UPDATED 7.16.7 7.23.3
@babel/plugin-transform-flow-strip-types UPDATED 7.16.0 7.23.3
@babel/plugin-transform-modules-commonjs UPDATED 7.15.4 7.23.3
@babel/plugin-transform-typescript UPDATED 7.16.8 7.23.6
@babel/preset-flow UPDATED 7.16.0 7.23.3
@babel/register UPDATED 7.13.16 7.22.15
@babel/regjsgen ADDED - 0.8.0
@babel/template UPDATED 7.16.7 7.22.15
@babel/traverse UPDATED 7.17.3 7.23.6
@babel/types UPDATED 7.17.0 7.23.6
@cnakazawa/watch REMOVED 1.0.4 -
@jest/create-cache-key-function UPDATED 26.6.2 29.7.0
@jest/environment UPDATED 27.5.1 29.7.0
@jest/fake-timers UPDATED 27.5.1 29.7.0
@jest/schemas ADDED - 29.6.3
@jest/types UPDATED 27.5.1 29.6.3
@jridgewell/gen-mapping ADDED - 0.3.3
@jridgewell/resolve-uri UPDATED 3.0.5 3.1.1
@jridgewell/set-array ADDED - 1.1.2
@jridgewell/source-map ADDED - 0.3.5
@jridgewell/sourcemap-codec UPDATED 1.4.11 1.4.15
@jridgewell/trace-mapping UPDATED 0.3.4 0.3.20
@react-native-community/cli UPDATED 5.0.1 10.0.0
@react-native-community/cli-clean ADDED - 10.1.1
@react-native-community/cli-config ADDED - 10.1.1
@react-native-community/cli-debugger-ui UPDATED 5.0.1 10.0.0
@react-native-community/cli-doctor ADDED - 10.2.5
@react-native-community/cli-hermes UPDATED 5.0.1 10.2.0
@react-native-community/cli-platform-android UPDATED 5.0.1 10.2.0
@react-native-community/cli-platform-ios UPDATED 5.0.2 10.2.5
@react-native-community/cli-plugin-metro ADDED - 10.2.3
@react-native-community/cli-server-api UPDATED 5.0.1 10.1.1
@react-native-community/cli-tools UPDATED 5.0.1 10.1.1
@react-native-community/cli-types UPDATED 5.0.1 10.0.0
@react-native/normalize-color UPDATED 2.0.0 2.1.0
@react-native/polyfills UPDATED 1.0.0 2.0.0
@sinclair/typebox ADDED - 0.27.8
@sinonjs/commons UPDATED 1.8.3 3.0.0
@sinonjs/fake-timers UPDATED 8.0.1 10.3.0
@types/yargs UPDATED 16.0.3 17.0.32
acorn UPDATED 8.7.0 8.11.2
arr-diff REMOVED 4.0.0 -
arr-flatten REMOVED 1.1.0 -
arr-union REMOVED 3.1.0 -
array-filter REMOVED 0.0.1 -
array-map REMOVED 0.0.0 -
array-reduce REMOVED 0.0.0 -
array-unique REMOVED 0.3.2 -
assign-symbols REMOVED 1.0.0 -
ast-types UPDATED 0.14.2 0.15.2
async UPDATED 2.6.3 3.2.5
atob REMOVED 2.1.2 -
babel-preset-fbjs UPDATED 3.3.0 3.4.0
base REMOVED 0.11.2 -
bl ADDED - 4.1.0
browserslist UPDATED 4.18.1 4.22.2
buffer ADDED - 5.7.1
cache-base REMOVED 1.0.1 -
caniuse-lite UPDATED 1.0.30001282 1.0.30001570
capture-exit REMOVED 2.0.0 -
class-utils REMOVED 0.3.6 -
cli-cursor UPDATED 2.1.0 3.1.0
cli-spinners UPDATED 2.6.0 2.9.2
cliui UPDATED 7.0.4 8.0.1
collection-visit REMOVED 1.0.0 -
colors REMOVED 1.4.0 -
commander UPDATED 7.2.0 9.5.0
component-emitter REMOVED 1.3.0 -
convert-source-map UPDATED 1.7.0 2.0.0
copy-descriptor REMOVED 0.1.1 -
define-property REMOVED 2.0.2 -
deprecated-react-native-prop-types ADDED - 3.0.2
electron-to-chromium UPDATED 1.3.904 1.4.615
exec-sh REMOVED 0.3.6 -
expand-brackets REMOVED 2.1.4 -
extend-shallow REMOVED 3.0.2 -
extglob REMOVED 2.0.4 -
fast-xml-parser ADDED - 4.3.2
flow-parser UPDATED 0.121.0 0.185.2
for-in REMOVED 1.0.2 -
fragment-cache REMOVED 0.2.1 -
get-value REMOVED 2.0.6 -
has-value REMOVED 1.0.0 -
has-values REMOVED 1.0.0 -
hermes-engine REMOVED 0.7.2 -
hermes-estree ADDED - 0.8.0
hermes-parser ADDED - 0.8.0
ieee754 ADDED - 1.2.1
interpret REMOVED 1.4.0 -
is-accessor-descriptor REMOVED 1.0.0 -
is-buffer REMOVED 1.1.6 -
is-ci REMOVED 2.0.0 -
is-core-module DOWNGRADED 2.8.1 2.3.0
is-data-descriptor REMOVED 1.0.0 -
is-descriptor REMOVED 1.0.2 -
is-extendable REMOVED 1.0.1 -
is-interactive ADDED - 1.0.0
is-unicode-supported ADDED - 0.1.0
is-windows REMOVED 1.0.2 -
jest-environment-node UPDATED 27.5.1 29.7.0
jest-message-util UPDATED 27.5.1 29.7.0
jest-mock UPDATED 27.5.1 29.7.0
jest-util UPDATED 27.5.1 29.7.0
jetifier REMOVED 1.6.8 -
jsc-android UPDATED 245459.0.0 250230.2.1
jsc-safe-url ADDED - 0.2.4
jscodeshift UPDATED 0.11.0 0.14.0
json5 UPDATED 2.2.0 2.2.3
jsonify REMOVED 0.0.0 -
klaw REMOVED 1.3.1 -
log-symbols UPDATED 2.2.0 4.1.0
map-cache REMOVED 0.2.2 -
map-visit REMOVED 1.0.0 -
memoize-one ADDED - 5.2.1
metro UPDATED 0.64.0 0.73.10
metro-babel-register REMOVED 0.64.0 -
metro-babel-transformer UPDATED 0.64.0 0.73.10
metro-cache UPDATED 0.64.0 0.73.10
metro-cache-key UPDATED 0.64.0 0.73.10
metro-config UPDATED 0.64.0 0.73.10
metro-core UPDATED 0.64.0 0.73.10
metro-file-map ADDED - 0.73.10
metro-hermes-compiler UPDATED 0.64.0 0.73.10
metro-inspector-proxy UPDATED 0.64.0 0.73.10
metro-minify-terser ADDED - 0.73.10
metro-minify-uglify UPDATED 0.64.0 0.73.10
metro-react-native-babel-preset UPDATED 0.64.0 0.73.10
metro-react-native-babel-transformer UPDATED 0.64.0 0.73.10
metro-resolver UPDATED 0.64.0 0.73.10
metro-runtime UPDATED 0.64.0 0.73.10
metro-source-map UPDATED 0.64.0 0.73.10
metro-symbolicate UPDATED 0.64.0 0.73.10
metro-transform-plugins UPDATED 0.64.0 0.73.10
metro-transform-worker UPDATED 0.64.0 0.73.10
mixin-deep REMOVED 1.3.2 -
nanomatch REMOVED 1.2.13 -
nocache UPDATED 2.1.0 3.0.4
node-releases UPDATED 2.0.1 2.0.14
ob1 UPDATED 0.64.0 0.73.10
object-copy REMOVED 0.1.0 -
object-visit REMOVED 1.0.1 -
object.pick REMOVED 1.3.0 -
options REMOVED 0.0.6 -
ora UPDATED 3.4.0 5.4.1
pascalcase REMOVED 0.1.1 -
pirates UPDATED 4.0.5 4.0.6
posix-character-classes REMOVED 0.1.1 -
pretty-format UPDATED 27.5.1 29.7.0
promise UPDATED 8.1.0 8.3.0
prop-types UPDATED 15.7.2 15.8.1
react-devtools-core UPDATED 4.13.2 4.28.5
react-is UPDATED 17.0.2 18.2.0
react-native UPDATED 0.64.3 0.71.0
react-native-codegen UPDATED 0.0.6 0.71.6
react-native-gradle-plugin ADDED - 0.71.19
react-shallow-renderer ADDED - 16.15.0
readable-stream UPDATED 2.3.7 3.6.2
readline ADDED - 1.3.0
recast UPDATED 0.20.5 0.21.5
rechoir REMOVED 0.6.2 -
regenerate-unicode-properties UPDATED 8.2.0 10.1.1
regenerator-runtime UPDATED 0.13.7 0.14.1
regex-not REMOVED 1.0.2 -
regexpu-core UPDATED 4.7.1 5.3.2
regjsparser UPDATED 0.6.9 0.9.1
remove-trailing-separator REMOVED 1.1.0 -
repeat-element REMOVED 1.1.4 -
repeat-string REMOVED 1.6.1 -
resolve-url REMOVED 0.2.1 -
restore-cursor UPDATED 2.0.0 3.1.0
ret REMOVED 0.1.15 -
rsvp REMOVED 4.8.5 -
safe-buffer UPDATED 5.1.2 5.2.1
safe-regex REMOVED 1.1.0 -
sane REMOVED 4.1.0 -
scheduler UPDATED 0.20.2 0.23.0
set-value REMOVED 2.0.1 -
shell-quote UPDATED 1.7.2 1.8.1
shelljs REMOVED 0.8.5 -
snapdragon REMOVED 0.8.2 -
snapdragon-node REMOVED 2.1.1 -
snapdragon-util REMOVED 3.0.1 -
source-map-resolve REMOVED 0.5.3 -
source-map-support UPDATED 0.5.19 0.5.21
source-map-url REMOVED 0.4.1 -
split-string REMOVED 3.1.0 -
static-extend REMOVED 0.1.2 -
string-width UPDATED 4.2.2 4.2.3
strnum ADDED - 1.0.5
supports-preserve-symlinks-flag REMOVED 1.0.0 -
temp UPDATED 0.8.3 0.8.4
terser ADDED - 5.26.0
to-object-path REMOVED 0.3.0 -
to-regex REMOVED 3.0.2 -
ultron REMOVED 1.0.2 -
unicode-canonical-property-names-ecmascript UPDATED 1.0.4 2.0.0
unicode-match-property-ecmascript UPDATED 1.0.4 2.0.0
unicode-match-property-value-ecmascript UPDATED 1.2.0 2.1.0
unicode-property-aliases-ecmascript UPDATED 1.1.0 2.1.0
union-value REMOVED 1.0.1 -
unset-value REMOVED 1.0.0 -
update-browserslist-db ADDED - 1.0.13
urix REMOVED 0.1.0 -
use REMOVED 3.1.1 -
use-sync-external-store ADDED - 1.2.0
ws UPDATED 7.4.6 7.5.9
xmldoc REMOVED 1.1.2 -
yargs UPDATED 16.2.0 17.7.2
yargs-parser UPDATED 20.2.7 21.1.1

Copy link

App is ready for review, you can see it here.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants