forcedotcom / SalesforceMobileSDK-Templates

BSD 3-Clause "New" or "Revised" License
52 stars 56 forks source link

[Snyk] Security upgrade react-native-vector-icons from 4.6.0 to 6.4.1 #284

Closed snyk-bot closed 4 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
medium severity Prototype Pollution
SNYK-JS-YARGSPARSER-560381
Yes Proof of Concept
medium severity Denial of Service (DoS)
npm:mem:20180117
Yes No Known Exploit
Commit messages
Package name: react-native-vector-icons The new version differs by 90 commits.
  • a8653c1 Release 6.4.1 (#963)
  • e0ad7b4 Font Awesome 5 multi style fix (#962)
  • 9cbeec5 Remove deprecated issue stats badge
  • 1154eeb Bump yargs
  • 58f72a1 Release 6.4.0
  • 7612a69 Bump Material Community Icons to 3.5.95
  • 9904449 Add list of all fonts to copy & paste in the info.plist file (#957)
  • 432cac9 Remove --save flag from installation instructions (#954)
  • a91749a Add flow type definitions for main classes (#931)
  • aa7f1aa FontAwesome 5.7.0 and multi-style support (#934)
  • 45ebd8d Release 6.3.0
  • 2811ddf Bump prettier and format all files
  • 546d373 Bump Octicons to 8.4.1
  • 552e655 Bump MaterialCommunityIcons to 3.4.93
  • 2568466 Remove unused class method in directory (#909)
  • 25a1b26 IconMoon Aliases (#946)
  • d101ad9 Update project to Xcode 10 recommended settings (#901)
  • 5f6fa93 Cleaned up the directory design. Cleaner header, cleaner searchbar, and section titles stand out more. (#935)
  • 391cb84 Release 6.2.0
  • e218fec Fix issues with #871 when using Android Gradle Plugin 3.1 (#923)
  • 5dbd964 Update FontAwesome5 to 5.6.3 (#916)
  • 91674f8 Update fa5-upgrade.sh script (#899)
  • 00b077f Release 6.1.0
  • 6bb69bc Updated SimpleLineIcons link in README to a github hosted link, as it is more reliable (#883)
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

bhariharan commented 4 years ago

Will be updated on dev.