[Snyk] Upgrade react-native from 0.60.5 to 0.75.3 #1443
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade react-native from 0.60.5 to 0.75.3.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-WS-7266574
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-DECODEURICOMPONENT-3149970
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-UNSETVALUE-2400660
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-ASYNC-2441827
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-BRACES-6838727
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1536531
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1579147
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1579152
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1579155
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-PLIST-2405644
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-REACTNATIVE-1298632
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-UAPARSERJS-1023599
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-UAPARSERJS-610226
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SHELLQUOTE-1766506
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1536528
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-XMLDOM-3042242
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-INI-1048974
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-LOGKITTY-568763
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-MICROMATCH-6838728
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-WS-1296835
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-HAPIHOEK-548452
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-HOSTEDGITINFO-1088355
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-YARGSPARSER-560381
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-YARGSPARSER-560381
Why? Proof of Concept exploit, CVSS 7.5
npm:mem:20180117
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFETCH-2342118
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-UAPARSERJS-1072471
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFETCH-674311
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFETCH-674311
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODENOTIFIER-1035794
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-XMLDOM-1084960
Why? Proof of Concept exploit, CVSS 7.5
npm:debug:20170905
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-BABELTRAVERSE-5962462
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-6476909
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-REACTDEVTOOLSCORE-6023999
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-NODEFETCH-2342118
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-XMLDOM-1534562
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-WS-1296835
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-JSON5-3182856
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-TAR-1536758
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SEND-7926862
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-SERVESTATIC-7926865
Why? Proof of Concept exploit, CVSS 7.5
SNYK-JS-XMLDOM-3092935
Why? Proof of Concept exploit, CVSS 7.5
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: react-native
Changed
Fixed
Android specific
gradle-tooling-api-builders
- serviceOf failure (1067798a7e by @ cortinico)iOS specific
(05dec917f2 by @ okwasniewski)
Hermes dSYMS:
You can file issues or pick requests against this release here.
To help you upgrade to this version, you can use the Upgrade Helper ⚛️.
View the whole changelog in the CHANGELOG.md file.
Added
Android specific
com.facebook.react.bridge.Dynamic
as parameter for TurboModules (a9588f3718 by @ cortinico)Changed
Fixed
Hermes dSYMS:
You can file issues or pick requests against this release here.
To help you upgrade to this version, you can use the Upgrade Helper ⚛️.
View the whole changelog in the CHANGELOG.md file.
Removed
Android specific
Fixed
Android specific
iOS specific
<KeyboardAvoidingView>
with floating keyboard on iPadOS (3c54e1ee45 by @ renchap)Hermes dSYMS:
You can file issues or pick requests against this release here
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.