SudoPlz / sp-react-native-in-app-updates

An in-app updater for the native version of your react-native app.
MIT License
491 stars 66 forks source link

Vulnerability in axios #42

Closed nirajniroula closed 3 years ago

nirajniroula commented 3 years ago

A vulnerability CVE-2020-28168 detected in package axios<0.21.1 is referenced by sp-react-native-in-app-updates via react-native-siren@0.0.3. It has been fixed in the latest release.

Can we please use the latest version of react-native-siren in the next release?

SudoPlz commented 3 years ago

Fixed in 1.1.3