Darkhorse-Fraternity / RNPakageForNative

RNPakageForNative
MIT License
0 stars 0 forks source link

Bump xmldom, plist and react-native-code-push #20

Open dependabot[bot] opened 2 years ago

dependabot[bot] commented 2 years ago

Removes xmldom. It's no longer used after updating ancestor dependencies xmldom, plist and react-native-code-push. These dependencies need to be updated together.

Removes xmldom

Updates plist from 3.0.1 to 3.0.6

Changelog

Sourced from plist's changelog.

3.0.5 / 2022-03-23

  • [96e2303d05] Prototype Pollution using .parse() #114 (mario-canva)
  • update browserify from 16 to 17

3.0.4 / 2021-08-27

  • inline xmldom@0.6.0 to eliminate security warning false positive (Mike Reinstein)

3.0.3 / 2021-08-04

  • update xmldom to 0.6.0 to patch critical vulnerability (Mike Reinstein)
  • remove flaky saucelabs teseting badge (Mike Reinstein)

3.0.2 / 2021-03-25

  • update xmldom to 0.5.0 to patch critical vulnerability (Mike Reinstein)
  • update saucelab credentials to point at mreinstein's saucelabs account (Mike Reinstein)
  • remove a bunch of test versions from the matrix because they weren't working in zuul + sauce (Mike Reinstein)
Commits


Updates react-native-code-push from 5.7.0 to 7.0.5

Release notes

Sourced from react-native-code-push's releases.

v7.0.5

  • Fix partial path traversal vulnerability in Android

v7.0.4

  • Update dependencies
  • Fix issue with missed images after the second update

v7.0.3

  • Fix issue where foreign characters break the data integrity check
  • Update dependencies
  • Bump IPHONEOS_DEPLOYMENT_TARGET version

v7.0.2

  • Fix MitM vulnerability

v7.0.1

  • Update dependencies

v7.0.0

Add React Native Windows v0.63.5+ support

v6.4.1

  • Fix issue with the timer on ON_NEXT_SUSPEND mode

v6.4.0

  • Update dependencies
  • Fix Xcode 12 compatibility
  • Fixed problem with android versions <= 4.4
  • Small bug-fixing

v6.3.0

  • Move disallowRestart to the native side.
  • Add tests for ON_NEXT_SUSPEND install mode.
  • Update docs.

v6.2.1

  • Fix ON_NEXT_SUSPEND install mode

v6.2.0

  • Add compatibility with new react-native@0.62 version

v6.1.1

  • Fixed iOS rollback recording

v6.1.0

  • Make create app.js script supportable of react-native@0.60+ versions
  • Make tests supportable of react-native@0.60+ versions

v6.0.0

Added react-native@0.60 version and above support

... (truncated)

Commits
  • bd883b8 Add terminating separator to avoid path escaping (#2288)
  • 773f942 Bump url-parse from 1.5.3 to 1.5.7 in /Examples/CodePushDemoApp (#2224)
  • 45af5e0 Bump url-parse from 1.5.4 to 1.5.7 in /Examples/CodePushDemoAppCpp (#2223)
  • 41c39dc Bump url-parse from 1.5.3 to 1.5.7 (#2222)
  • 9768904 Bump vm2 from 3.9.5 to 3.9.7 in /Examples/CodePushDemoAppCpp (#2218)
  • 4290a41 Bump vm2 from 3.9.4 to 3.9.7 in /Examples/CodePushDemoApp (#2217)
  • 173d790 Bump vm2 from 3.9.5 to 3.9.7 (#2216)
  • 73cdaff Bump node-fetch to 2.6.7 in CodePushDemoAppCpp (#2212)
  • 8d8613f Bump node-fetch from 2.6.5 to 2.6.7 in /Examples/CodePushDemoApp (#2211)
  • 6875b11 Bump ansi-regex to 5.0.1 via resolutions (#2210)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by appcenter, a new releaser for react-native-code-push since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Darkhorse-Fraternity/RNPakageForNative/network/alerts).