[Snyk] Security upgrade react-native from 0.42.3 to 0.69.12#18
[Snyk] Security upgrade react-native from 0.42.3 to 0.69.12#18MHxGH-ServiceAccount wants to merge 1 commit intomasterfrom
Conversation
…rabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MINIMATCH-15309438
|
Upgrading Key Breaking Changes:
Recommendation: This upgrade cannot be performed with a simple version change. It requires a careful, step-by-step migration. Use the official React Native Upgrade Helper web tool to generate a diff between your current version and the target version. It is strongly advised to upgrade incrementally between major versions (e.g., 0.42 → 0.59, then 0.59 → 0.60, etc.) to isolate and address breaking changes systematically. This upgrade will touch almost every part of the application and requires extensive testing.
|
⛔ Snyk checks have failed. 4 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
example/package.jsonexample/package-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-MINIMATCH-15309438
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
Note
High Risk
Major
react-nativeversion jump with a large transitive dependency change-set; likely to introduce build/runtime breakages in the example app despite being a dependency-only PR.Overview
Upgrades the
exampleapp’sreact-nativedependency to0.69.12(from0.42.3) to address the reported ReDoS vulnerability, and refreshesexample/package-lock.jsonwith the resulting updated transitive dependency tree.No application/runtime code changes are included; this is a dependency/lockfile-only update that may require follow-up compatibility fixes in the example project.
Written by Cursor Bugbot for commit db76b2c. This will update automatically on new commits. Configure here.