webraptor / react-native-deck-swiper

tinder like react-native deck swiper
ISC License
126 stars 81 forks source link

5 high severity vulnerabilities #122

Open wp-coin opened 8 months ago

wp-coin commented 8 months ago

npm audit report

node-fetch <=2.6.6 Severity: high The size option isn't honored after following a redirect in node-fetch - https://github.com/advisories/GHSA-w7rc-rwvf-8q5r node-fetch forwards secure headers to untrusted sites - https://github.com/advisories/GHSA-r683-j2x4-v87g fix available via npm audit fix --force Will install react-native-deck-swiper@1.1.7, which is a breaking change node_modules/isomorphic-fetch/node_modules/node-fetch isomorphic-fetch 2.0.0 - 2.2.1 Depends on vulnerable versions of node-fetch node_modules/isomorphic-fetch fbjs 0.7.0 - 1.0.0 Depends on vulnerable versions of isomorphic-fetch node_modules/fbjs prop-types 15.5.0-alpha.0 - 15.6.1 Depends on vulnerable versions of fbjs node_modules/react-native-deck-swiper/node_modules/prop-types react-native-deck-swiper >=1.1.8 Depends on vulnerable versions of prop-types node_modules/react-native-deck-swiper

cheeselemon commented 4 months ago

i believe this is crucial

webraptor commented 4 months ago

Anyone who has the time to open a PR with changes, I'll review / merge / release

YoussefHenna commented 3 months ago

https://github.com/webraptor/react-native-deck-swiper/pull/129 This should address it.

rick427 commented 2 months ago

Any update on this ?

roelofsaj commented 1 week ago

Also looking for an update here...