titanscouting / red-alliance-mobile

Red Alliance App in React
2 stars 6 forks source link

[Snyk] Upgrade @react-native-async-storage/async-storage from 1.15.9 to 1.15.11 #172

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade @react-native-async-storage/async-storage from 1.15.9 to 1.15.11.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1023599
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Command Injection
SNYK-JS-LODASH-1040724
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1072471
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
482/1000
Why? Proof of Concept exploit, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @react-native-async-storage/async-storage
  • 1.15.11 - 2021-11-05

    1.15.11 (2021-11-05)

    Bug Fixes

    • Error handling improvements and docs update (#698) (fc34bfa)

    AsyncStorage will no longer swallow errors from multiGet. In addition, multiple batched multiGet calls (not awaited) will be rejected with the same error, if one of the keys retrieval would fail. This is to keep the consistency across the platforms.

  • 1.15.10 - 2021-11-04
    • multiGet to propagate errors

    • bump Android next versions

    • docs: next storage + room

    • docs: android limits

  • 1.15.9 - 2021-10-05

    1.15.9 (2021-10-05)

    Bug Fixes

    • declare support for react-native 0.66 (#683) (e547e8d)
from @react-native-async-storage/async-storage GitHub release notes
Commit messages
Package name: @react-native-async-storage/async-storage
  • 2821da5 fix: gradle build (#706)
  • a9ed140 chore(deps): bump tar from 6.1.6 to 6.1.11 (#703)
  • 162e35b chore(deps): bump semver-regex from 3.1.2 to 3.1.3 (#702)
  • 006700f docs: Change API URL (#704)
  • fc34bfa fix: Error handling improvements and docs update (#698)
  • 8dfd16d chore: bump actions/stale to v4 (#691)
  • 609b19d chore: use GitHub's form schema for filing issues (#690)
  • 71c5c52 chore(windows): fix windows build (#686)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs