titanscouting / red-alliance-mobile

Red Alliance App in React
2 stars 6 forks source link

[Snyk] Upgrade react-native-reanimated from 2.1.0 to 2.2.2 #157

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade react-native-reanimated from 2.1.0 to 2.2.2.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1023599
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TMPL-1583443
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Command Injection
SNYK-JS-LODASH-1040724
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1072471
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
482/1000
Why? Proof of Concept exploit, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: react-native-reanimated
  • 2.2.2 - 2021-09-15

    πŸ”‘ Key changes

    • Patch release to fix build issues people using Expo EAS

    ⚠️ JS part of 2.2.2 is fully compatible with 2.2.0

    πŸ™Œ Thank you for your contributions!

  • 2.2.1 - 2021-09-10

    πŸ”‘ Key changes

    • Added support for react-native@0.65
    • Simplified internal installation for jsExecutorFactoryForBridge on iOS #2223
    • Fix problem with libfbjni.so #2209
    • Adjustment for the new Hermes version
    • Fix for crash in UserStore

    ⚠️ JS part of 2.2.1 is fully compatible with 2.2.0

    πŸ™Œ Thank you for your contributions!

  • 2.2.0 - 2021-05-27

    πŸ”‘ Key changes

    πŸ› Bug fixes

    πŸ‘ Improvements

    • Speeded up building on Android (Example App) 7aebe68
    • Named exported animation functions 462e21e
    • Possibility to set custom globals in our babel plugin 11250a0
    • Made shared values more aware of multithreading c511a5d

    πŸ““ Docs improvements

    • Broken links fixes 85e5705, ee5e557
    • Docs appearance update 5b0e39f
    • Add information about JSC support to the docs 22bbc3a
    • Clarify iOS installation steps b8b7da8
    • Update testing related doc ab6afd1
    • Added info about Webpack configuration to docs ee11c63

    πŸ™Œ Thank you for your contributions!

    πŸ“’ Keep watching! We will back with new features soon! πŸ€—

  • 2.1.0 - 2021-04-01

    πŸ”‘ Key changes

    πŸ› Bug fixes

    • Fixed problem with full reload on Android. #1839
    • Fixed wrapped worklet. #1844
    • Fixed bug in react-native-web affected on the web version of reanimated. RNW Issue
    • Added missing viewRef for animatedProps #1819
    • Fixed problem with hidden headers for Swift applications. #1810

    πŸ‘ Improvements

    • Added possibility to use Reanimated 2 without configuration if you use only API v1. #1845
    • Add more descriptive error messages. #1845 #1832
    • Reorganized structure of files in the project: #1789
    • Migration codebase to TypeScript. #1807 #1872

    πŸ““ Docs improvements

    • Updated information about debugging. #1876

    πŸ™Œ Thank you for your contributions!

    πŸ“’ Keep watching! We will back with new features soon! πŸ€—

from react-native-reanimated GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

πŸ›  Adjust upgrade PR settings

πŸ”• Ignore this dependency or unsubscribe from future upgrade PRs