titanscouting / red-alliance-mobile

Red Alliance App in React
2 stars 6 forks source link

[Snyk] Upgrade react-native from 0.64.1 to 0.66.4 #174

Closed snyk-bot closed 2 years ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade react-native from 0.64.1 to 0.66.4.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Out-of-Bounds
SNYK-JS-HERMESENGINE-1727253
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Command Injection
SNYK-JS-LODASH-1040724
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1023599
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PROMPTS-1729737
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UAPARSERJS-1072471
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: react-native
  • 0.66.4 - 2021-12-09

    Fixes for iOS:

    • Revert "Fix Deadlock in RCTi18nUtil (iOS) (#31032)" 70ddf46
    • Pick Fix post_install_workaround downgrading development targets: a4a3e67

    You can participate in the conversation on the status of this release at this discussion


    To help you upgrade to this version, you can use the upgrade helper ⚛️


    You can find the whole changelog history in the changelog.md file.

  • 0.66.3 - 2021-11-10

    This release contains a set of improvements to the script we use for npm releases; aside from it:


    You can participate in the conversation on the status of this release at this discussion.


    To help you upgrade to this version, you can use the upgrade helper ⚛️


    You can find the whole changelog history in the changelog.md file.

  • 0.66.2 - 2021-11-04

    0.66.2 is out with some fixes:

    Fixed

    • Compare the LogBoxData ignorePatterns with the right code (a950634 by @ wiseqingyang)
    • [iOS] Fix logbox window capturing touch events (72ea0e1 by @ paddlefish)
    • Commit generated codegen files as a temporary workaround for devX issue with yarn install removing codegen assets. Proper fix coming in later. (5f7deb5 by @ kelset)

    You can participate in the conversation on the status of this release at this discussion.


    To help you upgrade to this version, you can use the upgrade helper ⚛️


    You can find the whole changelog history in the changelog.md file.

  • 0.66.1 - 2021-10-15
  • 0.66.0 - 2021-10-01
  • 0.66.0-rc.4 - 2021-09-24
  • 0.66.0-rc.3 - 2021-09-17
  • 0.66.0-rc.2 - 2021-09-10
  • 0.66.0-rc.1 - 2021-09-01
  • 0.66.0-rc.0 - 2021-08-27
  • 0.65.2 - 2021-11-04

    [0.65.2] Bump version numbers

  • 0.65.1 - 2021-08-19
  • 0.65.0 - 2021-08-17
  • 0.65.0-rc.4 - 2021-08-11
  • 0.65.0-rc.3 - 2021-07-23
  • 0.65.0-rc.2 - 2021-06-18
  • 0.65.0-rc.1 - 2021-06-17
  • 0.65.0-rc.0 - 2021-06-09
  • 0.64.3 - 2021-11-04

    0.64.3 is out with a pick of Android Appearance API support (e94f9fa7 by @ mrbrentkelly)


    If you have concerns or follow-up, please start or contribute to a relevant 0.64.3 discussion here


    To help you upgrade to this version, you can use the upgrade helper ⚛️


    You can find the whole changelog history in the changelog.md file.

  • 0.64.2 - 2021-06-03
  • 0.64.1 - 2021-05-05
from react-native GitHub release notes
Commit messages
Package name: react-native
  • 1b31d6b [0.66.4] Bump version numbers
  • 83b9ddd Fix post_install_workaround downgrading development targets (#32633) (#32715)
  • 5d7fd00 Revert "Fix Deadlock in RCTi18nUtil (iOS) (#31032)" (#32574) (#32714)
  • 3b5e446 [0.66.3] Bump version numbers
  • 0981564 RN: Rename `Keyboard.remove{Event =>}Listener`
  • 142090a Revert changes in RN preprocessor
  • f35369e Fix npm latest tag issue when releasing patches (#32543)
  • 85f1450 Clean up publish-npm.js and use parseVersion
  • 8a67aaa Extract version parsing from release script
  • d08397a bump-oss-version: Add -v / --to-version argument and use it when bumping nightly releases (now at 20:00 UTC)
  • 6c19dc3 [0.66.2] Bump version numbers
  • 11644d7 Hide the logbox window explicitly. New behavior in iOS SDK appears to… (#32435)
  • 9d601e4 fix: compare the LogBoxData ignorePatterns with the right code (#31977)
  • 7382f55 [LOCAL] reintroduce generated codegen files
  • d48ed4a [0.66.1] Bump version numbers
  • 80e5abd Fix Android border positioning regression (#32398)
  • e94f9fa Addressing various issues with the Appearance API (#28823) (#29106)
  • bd01f16 Fix: find-node.sh location in react-native-xcode.sh script (#32227)
  • 09a21f0 [0.66.0] Bump version numbers
  • d47fd4a [0.66.0-rc.4] Bump version numbers
  • a6a983d OSS: bump-oss-version -- update Podfile.lock later in the flow
  • ef280d6 [LOCAL] Port react-native-codegen new .gitignore from main
  • 9967318 OSS: update Podfile.lock automatically when bumping release version
  • 6b014e8 Don’t hard-code CocoaPods’s sandbox path (#32243)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs