DylanVann / react-native-fast-image

🚩 FastImage, performant React Native image component.
MIT License
8.09k stars 1.47k forks source link

bump SDWebImageWebPCoder to 0.11.0 to resolve Double Free VULNERABILITY #988

Open TheSolly opened 1 year ago

TheSolly commented 1 year ago

Hi! πŸ‘‹

Firstly, thanks for your work on this project! πŸ™‚

Today I used patch-package to patch react-native-fast-image@8.6.3 for the project I'm working on.

Here is the diff that solved my problem:

diff --git a/node_modules/react-native-fast-image/RNFastImage.podspec b/node_modules/react-native-fast-image/RNFastImage.podspec
index db0fada..d47bb82 100644
--- a/node_modules/react-native-fast-image/RNFastImage.podspec
+++ b/node_modules/react-native-fast-image/RNFastImage.podspec
@@ -17,5 +17,5 @@ Pod::Spec.new do |s|

   s.dependency 'React-Core'
   s.dependency 'SDWebImage', '~> 5.11.1'
-  s.dependency 'SDWebImageWebPCoder', '~> 0.8.4'
+  s.dependency 'SDWebImageWebPCoder', '~> 0.11.0'
 end

This issue body was partially generated by patch-package.