titanscouting / red-alliance-mobile

Red Alliance App in React
2 stars 6 forks source link

[Snyk] Upgrade @react-native-community/toolbar-android from 0.1.0-rc.2 to 0.2.1 #158

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade @react-native-community/toolbar-android from 0.1.0-rc.2 to 0.2.1.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1023599
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-TMPL-1583443
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Command Injection
SNYK-JS-LODASH-1040724
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1072471
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
482/1000
Why? Proof of Concept exploit, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-COLORSTRING-1082939
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @react-native-community/toolbar-android
  • 0.2.1 - 2021-09-03

    Summary

    • update ReactToolbar.java to be backward compatible (Rn < 0.65) (#55)
    • fix ci

    Change History:

    v0.2.0 => v0.2.1

    Happy coding 😄

  • 0.2.0 - 2021-09-03

    Summary

    • update ReactToolbar.java to be react-native @ 0.65 compatible (#54)
    • added example app for react-native @ 0.65
    • various security vulnerability patches

    Change History:

    v0.1.0-rc.2 => v0.2.0

    Happy coding 😄

  • 0.1.0-rc.2 - 2020-03-08

    Summary

    • enhance web support by making UnimplementedView an optional dependency so it won't trigger build error.
    • internal enhancement for testing with the examples

    Contributors 🙏

    @ connectdotz

    Change History:

    v0.1.0-rc.1 => v0.1.0-rc.2

    Happy coding 😄

from @react-native-community/toolbar-android GitHub release notes
Commit messages
Package name: @react-native-community/toolbar-android
  • cbcce4d bump up version
  • e5906f5 make ReactToolbar backward compatible with RN < 0.65
  • 66969ab Update config.yml
  • 2ec9aa8 fix java option due to JDK upgrade
  • 00a3fe1 upgrade node and android api version
  • 178fb25 more debug
  • 5b814b9 adding some debugging flag
  • 15c81fb update ci and readme
  • c3e12ec use new style circleci badge
  • 1060483 update circle badge URL
  • b4d40ce Merge remote-tracking branch 'upstream/master' into rn-0.65
  • 571224f adding react-native 0.65 example and fix compatibility issue
  • b4ebbb2 Merge pull request #46 from react-native-toolbar-android/dependabot/npm_and_yarn/example/ToolbarAndroidExample-061/path-parse-1.0.7
  • 9af74e3 Bump path-parse in /example/ToolbarAndroidExample-061
  • 8f1a391 Merge pull request #47 from react-native-toolbar-android/dependabot/npm_and_yarn/path-parse-1.0.7
  • 04b8cec Bump path-parse from 1.0.6 to 1.0.7
  • 039895a Merge pull request #52 from react-native-toolbar-android/dependabot/npm_and_yarn/example/ToolbarAndroidExample-expo-063/url-parse-1.5.3
  • 26d7498 Merge pull request #53 from react-native-toolbar-android/dependabot/npm_and_yarn/example/ToolbarAndroidExample-expo-063/color-string-1.6.0
  • 9d34003 Bump color-string in /example/ToolbarAndroidExample-expo-063
  • 1816737 Bump url-parse in /example/ToolbarAndroidExample-expo-063
  • c48d694 Merge pull request #48 from react-native-toolbar-android/dependabot/npm_and_yarn/example/ToolbarAndroidExample-060/path-parse-1.0.7
  • f41430a Merge pull request #49 from react-native-toolbar-android/dependabot/npm_and_yarn/example/ToolbarAndroidExample-expo-063/path-parse-1.0.7
  • 7899885 Merge pull request #50 from react-native-toolbar-android/dependabot/npm_and_yarn/tar-4.4.19
  • 5fb23f1 Bump tar from 4.4.8 to 4.4.19
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs