ladjs / react-native-phone-verification

The best React Native example for phone verification (an alternative to Twitter Digits).
https://joinspontaneous.com
MIT License
371 stars 66 forks source link

[Snyk] Security upgrade react-native from 0.40.0 to 0.69.12 #32

Open titanism opened 3 months ago

titanism commented 3 months ago

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123) ### Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project. #### Snyk changed the following file(s): - `example/package.json` #### Note for [zero-installs](https://yarnpkg.com/features/zero-installs) users If you are using the Yarn feature [zero-installs](https://yarnpkg.com/features/zero-installs) that was introduced in Yarn V2, note that this PR does not update the `.yarn/cache/` directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run `yarn` to update the contents of the `./yarn/cache` directory. If you are not using zero-install you can ignore this as your flow should likely be unchanged.
⚠️ Warning ``` Failed to update the yarn.lock, please update manually before merging. ```
#### Vulnerabilities that will be fixed with an upgrade: | | Issue | Score | :-------------------------:|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-ASYNC-7414156](https://snyk.io/vuln/SNYK-JS-ASYNC-7414156) |   **631**   --- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - Max score is 1000. Note that the real score may have changed since the PR was raised. > - This PR was automatically created by Snyk using the credentials of a real user. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: 🧐 [View latest project report](https://app.snyk.io/org/titanism/project/0656cc33-cf22-4728-8255-0bdcd6fe0e2c?utm_source=github&utm_medium=referral&page=fix-pr) 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates) 🛠 [Adjust project settings](https://app.snyk.io/org/titanism/project/0656cc33-cf22-4728-8255-0bdcd6fe0e2c?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read about Snyk's upgrade logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr) [//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"react-native","from":"0.40.0","to":"0.69.12"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ASYNC-7414156","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-ASYNC-7414156","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Regular Expression Denial of Service (ReDoS)"}],"prId":"c4761fd8-b0d1-4351-967c-68e9a2db930a","prPublicId":"c4761fd8-b0d1-4351-967c-68e9a2db930a","packageManager":"yarn","priorityScoreList":[631],"projectPublicId":"0656cc33-cf22-4728-8255-0bdcd6fe0e2c","projectUrl":"https://app.snyk.io/org/titanism/project/0656cc33-cf22-4728-8255-0bdcd6fe0e2c?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","pr-warning-shown","priorityScore"],"type":"auto","upgrade":["SNYK-JS-ASYNC-7414156"],"vulns":["SNYK-JS-ASYNC-7414156"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'
socket-security[bot] commented 3 months ago

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/accepts@1.3.8 None 0 16.8 kB dougwilson
npm/babel-preset-fbjs@3.4.0 environment Transitive: filesystem, shell, unsafe +84 14.4 MB gweterings
npm/cli-cursor@3.1.0 None +2 17.1 kB sindresorhus
npm/commander@2.20.3 filesystem, shell 0 62.4 kB abetomo
npm/compressible@2.0.18 None 0 7.36 kB dougwilson
npm/compression@1.7.4 Transitive: environment, filesystem, network +3 117 kB dougwilson
npm/connect@3.7.0 environment, network +2 105 kB dougwilson
npm/cross-spawn@6.0.5 environment, filesystem, shell +4 94.2 kB satazor
npm/error-ex@1.3.2 None +1 13.1 kB qix
npm/errorhandler@1.5.1 environment, filesystem 0 15.2 kB dougwilson
npm/event-target-shim@5.0.1 None 0 189 kB mysticatea
npm/finalhandler@1.1.2 environment +3 43.5 kB dougwilson
npm/fs-extra@8.1.0 filesystem Transitive: environment +3 182 kB ryanzim
npm/image-size@0.6.3 filesystem 0 27.5 kB netroy
npm/joi@17.13.3 None +5 670 kB marsup
npm/mime-db@1.52.0 None 0 206 kB dougwilson
npm/mime-types@2.1.35 None 0 18.3 kB dougwilson
npm/mime@2.6.0 None 0 60.1 kB broofa
npm/negotiator@0.6.3 None 0 27.4 kB dougwilson
npm/on-headers@1.0.2 None 0 7.54 kB dougwilson
npm/parseurl@1.3.3 None 0 10.3 kB dougwilson
npm/plist@3.1.0 None +3 1.2 MB mreinstein
npm/react-native@0.69.12 environment, network Transitive: eval, filesystem, shell, unsafe +451 246 MB react-native-bot
npm/readable-stream@3.6.2 environment 0 124 kB matteo.collina
npm/serve-static@1.15.0 None +1 33.1 kB dougwilson
npm/shell-quote@1.8.1 None 0 45 kB ljharb
npm/statuses@1.5.0 None 0 11 kB dougwilson
npm/through2@2.0.5 None 0 9.65 kB rvagg
npm/vary@1.1.2 None 0 8.75 kB dougwilson
npm/walker@1.0.8 filesystem 0 5.8 kB daaku
npm/write-file-atomic@2.4.3 None +2 34.1 kB isaacs
npm/ws@6.2.3 network 0 102 kB lpinca

🚮 Removed packages: npm/accepts@1.2.13, npm/align-text@0.1.4, npm/ansi@0.3.1, npm/babel-plugin-transform-es2015-block-scoped-functions@6.22.0, npm/babel-plugin-transform-es2015-object-super@6.22.0, npm/babel-plugin-transform-es3-member-expression-literals@6.22.0, npm/babel-plugin-transform-es3-property-literals@6.22.0, npm/combined-stream@1.0.5, npm/mime-db@1.26.0, npm/mime-types@2.1.11, npm/mime@1.3.4, npm/on-headers@1.0.1, npm/parseurl@1.3.1, npm/plist@1.2.0, npm/react-native@0.40.0, npm/readable-stream@1.1.14, npm/string-width@1.0.2, npm/tweetnacl@0.14.5, npm/xtend@4.0.1

View full report↗︎