DeadPackets / HackPi

A NodeJS server meant to turn a Raspberry Pi into an all out hacking device
MIT License
18 stars 5 forks source link

[Snyk] Security upgrade react-native-vector-icons from 4.6.0 to 6.4.1 #50

Open snyk-bot opened 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-Y18N-1021887
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-native-vector-icons The new version differs by 90 commits.
  • a8653c1 Release 6.4.1 (#963)
  • e0ad7b4 Font Awesome 5 multi style fix (#962)
  • 9cbeec5 Remove deprecated issue stats badge
  • 1154eeb Bump yargs
  • 58f72a1 Release 6.4.0
  • 7612a69 Bump Material Community Icons to 3.5.95
  • 9904449 Add list of all fonts to copy & paste in the info.plist file (#957)
  • 432cac9 Remove --save flag from installation instructions (#954)
  • a91749a Add flow type definitions for main classes (#931)
  • aa7f1aa FontAwesome 5.7.0 and multi-style support (#934)
  • 45ebd8d Release 6.3.0
  • 2811ddf Bump prettier and format all files
  • 546d373 Bump Octicons to 8.4.1
  • 552e655 Bump MaterialCommunityIcons to 3.4.93
  • 2568466 Remove unused class method in directory (#909)
  • 25a1b26 IconMoon Aliases (#946)
  • d101ad9 Update project to Xcode 10 recommended settings (#901)
  • 5f6fa93 Cleaned up the directory design. Cleaner header, cleaner searchbar, and section titles stand out more. (#935)
  • 391cb84 Release 6.2.0
  • e218fec Fix issues with #871 when using Android Gradle Plugin 3.1 (#923)
  • 5dbd964 Update FontAwesome5 to 5.6.3 (#916)
  • 91674f8 Update fa5-upgrade.sh script (#899)
  • 00b077f Release 6.1.0
  • 6bb69bc Updated SimpleLineIcons link in README to a github hosted link, as it is more reliable (#883)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic