rumax / react-native-PDFView

๐Ÿ“š PDF viewer for React Native
MIT License
300 stars 92 forks source link

[Snyk] Security upgrade react-native from 0.63.3 to 0.64.0 #215

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Information Exposure
SNYK-JS-NODEFETCH-2342118
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: react-native The new version differs by 250 commits.
  • ace025d [0.64.0] Bump version numbers
  • 728d55a Fixing the git attrs for all the people and all the files and all future ๐Ÿ™Œ
  • 8a6ac1f chore: Update React.podspec to require cocoapods >= 1.10.1
  • 138fdbc fix: restore refresh control fix
  • 7f3f80f Fix RefreshControl layout when removed from window (#31024)
  • 1aa4f47 [0.64.0-rc.4] Bump version numbers
  • 48a97d7 chore: fix conflict in Podfile.lock
  • e7e4b00 fix: disable fabric
  • 14db556 fix: React Native CodeGen integration for 0.64-stable (#31027)
  • 4b68734 Generalize node search logic
  • 7159bcb Update flipper in RNTester and template (#31010)
  • e846740 [0.64.0-rc.3] Bump version numbers
  • c023a40 chore: bump codegen script
  • 7004cac Invoke `node` directly in generate-specs.sh (#30781)
  • 5ada078 Make codegen more reliable on iOS (#30792)
  • 937ced3 Optionally override codegen script defaults via envvars
  • e5888de Add use_react_native_codegen!
  • 0636c45 Use Fabric builds in iOS tests (#30639)
  • 224c85a Update iOS Fabric-related files to compile on OSS (#29810)
  • 7ec38b9 Avoid eating clicks/taps into ScrollView when using physical keyboard (#30374)
  • 052447c Remove dependency on Folly in TurboModuleUtils.h (#30672)
  • 70ba9ac Expose the testID to black-box testing frameworks on Android (#29610)
  • 1eb7d4a [0.64.0-rc.2] Bump version numbers
  • 4481d09 Fix infinite loop in KeyboardAvoidingView
See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: ๐Ÿง View latest project report

๐Ÿ›  Adjust project settings

๐Ÿ“š Read more about Snyk's upgrade and patch logic

codecov-commenter commented 2 years ago

Codecov Report

Merging #215 (d84f100) into master (78e1711) will not change coverage. The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #215   +/-   ##
=======================================
  Coverage   67.56%   67.56%           
=======================================
  Files           2        2           
  Lines          37       37           
  Branches       12       12           
=======================================
  Hits           25       25           
  Misses          9        9           
  Partials        3        3           

Continue to review full report at Codecov.

Legend - Click here to learn more ฮ” = absolute <relative> (impact), รธ = not affected, ? = missing data Powered by Codecov. Last update 78e1711...d84f100. Read the comment docs.

stale[bot] commented 2 years ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.