Skip to content

Conversation

@titanism
Copy link

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • example/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging. 

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  828  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

@socket-security
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/react-native@0.69.12 environment, network Transitive: eval, filesystem +24 139 MB react-native-bot

🚮 Removed packages: npm/absolute-path@0.0.0, npm/ansi@0.3.1, npm/are-we-there-yet@1.1.2, npm/array-differ@1.0.0, npm/array-filter@0.0.1, npm/array-map@0.0.0, npm/array-reduce@0.0.0, npm/array-union@1.0.2, npm/array-uniq@1.0.3, npm/art@0.10.1, npm/babel-helper-regex@6.22.0, npm/babel-plugin-external-helpers@6.22.0, npm/babel-plugin-transform-es2015-block-scoped-functions@6.22.0, npm/babel-plugin-transform-es2015-object-super@6.22.0, npm/babel-plugin-transform-es2015-sticky-regex@6.22.0, npm/babel-plugin-transform-es2015-unicode-regex@6.22.0, npm/babel-plugin-transform-es3-member-expression-literals@6.22.0, npm/babel-plugin-transform-es3-property-literals@6.22.0, npm/babel-polyfill@6.22.0, npm/babel-preset-es2015-node@6.1.1, npm/babel-preset-fbjs@2.1.0, npm/base64-url@1.3.3, npm/basic-auth-connect@1.0.0, npm/basic-auth@1.0.4, npm/batch@0.5.3, npm/beeper@1.1.1, npm/body-parser@1.13.3, npm/bplist-creator@0.0.4, npm/bplist-parser@0.0.6, npm/bser@1.0.3, npm/buffer-shims@1.0.0, npm/bytes@2.1.0, npm/cli-cursor@1.0.2, npm/cli-width@2.1.0, npm/clone-stats@0.0.1, npm/clone@1.0.2, npm/compressible@2.0.9, npm/compression@1.5.2, npm/connect-timeout@1.6.2, npm/connect@2.30.2, npm/content-type@1.0.2, npm/cookie-parser@1.3.5, npm/cookie-signature@1.0.6, npm/cookie@0.1.3, npm/core-util-is@1.0.2, npm/crc@3.3.0, npm/cross-spawn@3.0.1, npm/csrf@3.0.4, npm/csurf@1.8.3, npm/dateformat@2.0.0, npm/delegates@1.0.0, npm/denodeify@1.2.1, npm/depd@1.0.1, npm/destroy@1.0.4, npm/duplexer2@0.0.2, npm/ee-first@1.1.1, npm/errorhandler@1.4.3, npm/escape-html@1.0.3, npm/etag@1.7.0, npm/event-target-shim@1.1.1, npm/exit-hook@1.1.1, npm/express-session@1.11.3, npm/fancy-log@1.3.0, npm/fbjs-scripts@0.7.1, npm/figures@1.7.0, npm/finalhandler@0.4.0, npm/fresh@0.3.0, npm/fs-extra@0.26.7, npm/gauge@1.2.7, npm/glob@5.0.15, npm/glogg@1.0.0, npm/gulp-util@3.0.8, npm/gulplog@1.0.0, npm/has-gulplog@0.1.0, npm/has-unicode@2.0.1, npm/http-errors@1.3.1, npm/image-size@0.3.5, npm/immutable@3.7.6, npm/imurmurhash@0.1.4, npm/inquirer@0.12.0, npm/isemail@1.2.0, npm/jest-haste-map@17.0.3, npm/joi@6.10.1, npm/json5@0.4.0, npm/jsonfile@2.4.0, npm/klaw@1.3.1, npm/left-pad@1.1.3, npm/lodash._basetostring@3.0.1, npm/lodash._basevalues@3.0.0, npm/lodash._isiterateecall@3.0.9, npm/lodash._reescape@3.0.0, npm/lodash._reevaluate@3.0.0, npm/lodash._reinterpolate@3.0.0, npm/lodash._root@3.0.1, npm/lodash.escape@3.2.0, npm/lodash.pad@4.5.1, npm/lodash.padend@4.6.1, npm/lodash.padstart@4.6.1, npm/lodash.restparam@3.6.1, npm/lodash.template@3.6.2, npm/lodash.templatesettings@3.1.1, npm/lru-cache@4.0.2, npm/media-typer@0.3.0, npm/method-override@2.3.7, npm/methods@1.1.2, npm/mime@1.3.4, npm/moment@2.17.1, npm/morgan@1.6.1, npm/multimatch@2.1.0, npm/multiparty@3.3.2, npm/multipipe@0.1.2, npm/mute-stream@0.0.5, npm/negotiator@0.5.3, npm/node-uuid@1.4.7, npm/npmlog@2.0.4, npm/on-finished@2.3.0, npm/on-headers@1.0.1, npm/onetime@1.1.0, npm/opn@3.0.3, npm/options@0.0.6, npm/pause@0.1.0, npm/pegjs@0.9.0, npm/plist@1.2.0, npm/process-nextick-args@1.0.7, npm/progress@1.1.8, npm/pseudomap@1.0.2, npm/random-bytes@1.0.0, npm/range-parser@1.0.3, npm/raw-body@2.1.7, npm/react-clone-referenced-element@1.0.1, npm/react-native@0.40.0, npm/react-timer-mixin@0.13.3, npm/readable-stream@1.1.14, npm/readline2@1.0.1, npm/rebound@0.0.13, npm/regenerate@1.3.2, npm/regexpu-core@2.0.0, npm/regjsgen@0.2.0, npm/regjsparser@0.1.5, npm/replace-ext@0.0.1, npm/response-time@2.3.2, npm/restore-cursor@1.0.1, npm/rndm@1.2.0, npm/run-async@0.1.0, npm/rx-lite@3.1.2, npm/send@0.13.2, npm/serve-favicon@2.3.2, npm/serve-index@1.7.3, npm/serve-static@1.10.3, npm/shell-quote@1.6.1, npm/simple-plist@0.1.4, npm/slide@1.1.6, npm/sparkles@1.0.0, npm/stacktrace-parser@0.1.4, npm/statuses@1.3.1, npm/stream-buffers@0.2.6, npm/stream-counter@0.2.0, npm/string_decoder@0.10.31, npm/temp@0.8.3, npm/through2@2.0.3, npm/through@2.3.8, npm/time-stamp@1.0.1, npm/topo@1.1.0, npm/tsscmp@1.0.5, npm/type-is@1.6.14, npm/uid-safe@2.0.0, npm/ultron@1.0.2, npm/util-deprecate@1.0.2, npm/utils-merge@1.0.0, npm/vary@1.0.1, npm/vhost@3.0.2, npm/vinyl@0.5.3, npm/write-file-atomic@1.3.1, npm/ws@1.1.1, npm/xcode@0.8.9, npm/xmlbuilder@4.0.0, npm/xmldoc@0.4.0, npm/xmldom@0.1.27, npm/yallist@2.0.0

View full report↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants