Skip to content

fix: resolve CVE alerts for transitive dependencies#1523

Merged
sapta100ms merged 3 commits intomainfrom
fix-cve-issues
Mar 13, 2026
Merged

fix: resolve CVE alerts for transitive dependencies#1523
sapta100ms merged 3 commits intomainfrom
fix-cve-issues

Conversation

@sapta100ms
Copy link
Contributor

Summary

  • Upgrade @100mslive/react-native-video-plugin devDependency from 1.1.0 to 1.1.3 in
    react-native-room-kit
  • Add npm overrides/resolutions to fix Dependabot security alerts for vulnerable transitive
    dependencies:
    • fast-xml-parser 4.x → ^5.3.4 (in react-native-hms, react-native-room-kit)
    • vm2 3.10.0 → >=3.10.2 (in react-native-room-kit)
    • node-forge 1.3.1 → >=1.3.2 (in react-native-room-kit, room-kit example, expo demo)
    • tar <7.5.7 → >=7.5.7 (in rnhms-expo-demo)
  • All vulnerabilities are in dev-only transitive dependencies (RN CLI, release-it) — no version bump
    or publish required

@sapta100ms sapta100ms requested a review from ygit as a code owner February 6, 2026 09:58
@trunk-io
Copy link

trunk-io bot commented Feb 6, 2026

Merging to main in this repository is managed by Trunk.

  • To merge this pull request, check the box to the left or comment /trunk merge below.

…d install for consistency with node_modules changes
@sapta100ms sapta100ms merged commit ab0e6c3 into main Mar 13, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants