webraptor / react-native-deck-swiper

tinder like react-native deck swiper
ISC License
126 stars 81 forks source link

Update prop-types Version | Severity: high #113

Closed ebulku closed 11 months ago

ebulku commented 11 months ago

node-fetch <=2.6.6 Severity: high

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor - https://github.com/advisories/GHSA-r683-j2x4-v87g

Will install react-native-deck-swiper@1.1.7, which is a breaking change node_modules/isomorphic-fetch/node_modules/node-fetch isomorphic-fetch 2.0.0 - 2.2.1 Depends on vulnerable versions of node-fetch node_modules/isomorphic-fetch fbjs 0.7.0 - 1.0.0 Depends on vulnerable versions of isomorphic-fetch node_modules/react-native-deck-swiper/node_modules/fbjs prop-types 15.5.0-alpha.0 - 15.6.1 Depends on vulnerable versions of fbjs node_modules/react-native-deck-swiper/node_modules/prop-types react-native-deck-swiper >=1.1.8 Depends on vulnerable versions of prop-types node_modules/react-native-deck-swiper

webraptor commented 11 months ago

Please open a PR for this and bump the patch package version as well. Thanks!

ebulku commented 11 months ago

@webraptor I tried to update it yesterday, but I had problems installing and running it locally. Can you send some stable env details you are using for development?

webraptor commented 11 months ago

I no longer actively work on the package :(