[Snyk] Upgrade react-native from 0.63.3 to 0.71.3 #1002
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade react-native from 0.63.3 to 0.71.3.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-SHELLQUOTE-1766506
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1727253
Why? Has a fix available, CVSS 8.1
SNYK-JS-REACTNATIVE-1298632
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1309667
Why? Has a fix available, CVSS 8.1
SNYK-JS-WS-1296835
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-2342071
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-608850
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-629268
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-629748
Why? Has a fix available, CVSS 8.1
SNYK-JS-NODEFETCH-2342118
Why? Has a fix available, CVSS 8.1
SNYK-JS-NODEFETCH-674311
Why? Has a fix available, CVSS 8.1
SNYK-JS-HERMESENGINE-1015406
Why? Has a fix available, CVSS 8.1
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: react-native
Changed
react-native-codegen
to0.71.5
react-native-gradle-plugin
to0.71.15
Fixed
Android specific
iOS specific
pod install --project-directory=...
(ad1ddc241a by @ tido64)You can participate in the conversation on the status of this release in this discussion.
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Added
accessibilityLabelledBy
TypeScript type (e162b07982 by @ DimitarNestorov)accessibilityLanguage
TypeScript type (71c4f57baf by @ DimitarNestorov)Changed
react-native-gradle-plugin
to^0.71.14
in core,@ react-native-community/eslint-config
to^3.2.0
in starting template (785bc8d97b by @ kelset)Fixed
TextInput
'sinputMode
TypeScript types (fac7859863 by @ eps1lon)Android specific
jsRootDir
default value (c0004092f9 by @ cortinico)iOS specific
You can participate in the conversation on the status of this release in this discussion.
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Added
Android specific
jsinspector
to the prefab target (a80cf96fc8 by @ Kudo)iOS specific
initialProps
property toRCTAppDelegate
(b314e6f147 by @ jblarriviere)Changed
Fixed
Android specific
iOS specific
react-native-flipper
whenNO_FLIPPER=1
to prevent iOS build fail (f47b5b8b5d by @ retyui)You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
0.71 stable is out!
This release includes over 1000 commits from 70+ contributors! Thank you to all our contributors new and old!
See the highlights of the release in our release blog post.
resolver.useWatchman: false
inmetro.config.js
.You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
⚙️ Technical Release
This release has no changes from RC5. We are only making it to ensure that after the CircleCI Security Incident, we have rotated all the necessary secrets correctly.
How To Test
Generate a new project with the standard command:
npx react-native init RN0710RC6 --version 0.71.0-rc.6
You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Help us testing 🧪
Let us know how it went by posting a comment in the working group discussion! Please specify with system you tried it on (ex. macos, windows).
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one - or use a different library that is already leveraging the new architecture!
Golden Release Candidate
This is our last release of 2022: we are considering this the golden RC for 0.71, so we'll give it a few weeks to be tested before 0.71.0 in early Jan.
How To Test
Generate a new project with the standard command:
npx react-native init RN0710RC5 --version 0.71.0-rc.5
You can participate in the conversation on the status of this release in the working group.
To help you upgrade to this version, you can use the upgrade helper ⚛️
See changes from this release in the changelog PR
Help us testing 🧪
Let us know how it went by posting a comment in the working group discussion! Please specify with system you tried it on (ex. macos, windows).
Bonus points: It would be even better if you could swap things around: instead of using a fresh new app, use a more complex one - or use a different library that is already leveraging the new architecture!
Fixes
Android Specific
iOS Specific
Added
Android
POST_NOTIFICATIONS
and deprecatePOST_NOTIFICATION
(b5280bbc93 by @ dcangulo)You can participate in the conversation on the status of this release in this discussion
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
This version is a patch release with a mitigation solution for the Android issue on Samsung devices.
Please let us know in the issue if this new version addresses the problem for you.
You can participate in the conversation on the status of this release in this discussion.
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
🚨 IMPORTANT: This is an exceptional release on an unsupported version. We recommend you upgrade to one of the supported versions, listed here.
Hotfix
This version is a patch release with a mitigation solution for the Android issue on Samsung devices.
Please let us know in the issue if this new version addresses the problem for you.
To help you upgrade to new versions, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Commit messages
Package name: react-native
pod install --project-directory=...
facebook/react-native#36096)jsRootDir
default value facebook/react-native#35992)TextInput
'sinputMode
TypeScript types facebook/react-native#35987)aspectRatio
conditionally cause js crash facebook/react-native#35858) (Fix crash by conditional value of aspectRatio style value (#35858) facebook/react-native#35859)Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs