titanscouting / red-alliance-mobile

Red Alliance App in React
2 stars 5 forks source link

[Snyk] Upgrade react-native-version-check from 3.4.1 to 3.4.2 #65

Closed snyk-bot closed 3 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to upgrade react-native-version-check from 3.4.1 to 3.4.2.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Heap-based Buffer Overflow
SNYK-JS-ELECTRON-1021884
446/1000
Why? Recently disclosed, CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: react-native-version-check
  • 3.4.2 - 2020-10-01

    fix caching json file (#116) @Vitalik7
    Do not fetch store info if latestVersion is specified 8e50d60

  • 3.4.1 - 2020-05-01

    react-native-version-check

    • Resolve issue with overly greedy regex capturing entire response #111 @fnimick

    react-native-version-check-expo

    • Resolve issue with overly greedy regex capturing entire response #111 @fnimick
from react-native-version-check GitHub release notes
Commit messages
Package name: react-native-version-check
  • 1bd0aaf v3.4.2
  • ec3f5ce Prepare releasing 3.4.2
  • 8e50d60 Do not fetch store info if latestVersion is specified
  • c64f6bf Wait for async tesks in test
  • 4103fb5 update package-lock.json file
  • 07d3f1d Bump acorn from 5.7.3 to 5.7.4 (#107)
  • b1973ea Bump lodash from 4.17.15 to 4.17.19 (#117)
  • 8d918f2 fix caching json file (#116)
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs