[Snyk] Security upgrade react-native from 0.42.3 to 0.69.12#28
[Snyk] Security upgrade react-native from 0.42.3 to 0.69.12#28MHxGH-ServiceAccount wants to merge 1 commit intomasterfrom
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MINIMATCH-15309438
|
Upgrading Key Breaking Changes:
Recommendation: This upgrade cannot be performed with a simple version change. It requires a careful, step-by-step migration. Use the official React Native Upgrade Helper web tool to generate a diff between your current version and the target version. It is strongly advised to upgrade incrementally between major versions (e.g., 0.42 → 0.59, then 0.59 → 0.60, etc.) to isolate and address breaking changes systematically. This upgrade will touch almost every part of the application and requires extensive testing.
|
⛔ Snyk checks have failed. 4 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.
| "dependencies": { | ||
| "react": "15.4.2", | ||
| "react-native": "0.42.3", | ||
| "react-native": "0.69.12", |
There was a problem hiding this comment.
Incompatible React version with upgraded React Native
High Severity
react-native was upgraded from 0.42.3 to 0.69.12, but react remains at 15.4.2. React Native 0.69.x declares react@18.0.0 as a peer dependency. This version mismatch will cause npm peer dependency resolution failures during install, and even if forced, the project will not function at runtime since the React Native internals rely on React 18 APIs not present in React 15. The react-test-renderer at 15.4.2 is similarly incompatible.


Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
examples/SampleRN42/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-MINIMATCH-15309438
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Regular Expression Denial of Service (ReDoS)
Note
Medium Risk
Large React Native version jump that may break the example build/runtime due to upstream breaking changes, but it’s isolated to an example app dependency update.
Overview
Upgrades the
examples/SampleRN42example app’sreact-nativedependency from0.42.3to0.69.12inpackage.json(a Snyk-driven security upgrade).Written by Cursor Bugbot for commit de84b96. This will update automatically on new commits. Configure here.