[Snyk] Upgrade react-native from 0.71.8 to 0.75.3 #85
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade react-native from 0.71.8 to 0.75.3.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version fixes:
SNYK-JS-BABELTRAVERSE-5962462
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-IP-6240864
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-FASTXMLPARSER-5668858
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-UNSETVALUE-2400660
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-FASTXMLPARSER-7573289
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-IP-7148531
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-REACTDEVTOOLSCORE-6023999
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-SEND-7926862
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
SNYK-JS-SERVESTATIC-7926865
Why? Proof of Concept exploit, Has a fix available, CVSS 9.3
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: react-native
Changed
Fixed
Android specific
gradle-tooling-api-builders
- serviceOf failure (1067798a7e by @ cortinico)iOS specific
(05dec917f2 by @ okwasniewski)
Hermes dSYMS:
You can file issues or pick requests against this release here.
To help you upgrade to this version, you can use the Upgrade Helper ⚛️.
View the whole changelog in the CHANGELOG.md file.
Added
Android specific
com.facebook.react.bridge.Dynamic
as parameter for TurboModules (a9588f3718 by @ cortinico)Changed
Fixed
Hermes dSYMS:
You can file issues or pick requests against this release here.
To help you upgrade to this version, you can use the Upgrade Helper ⚛️.
View the whole changelog in the CHANGELOG.md file.
Removed
Android specific
Fixed
Android specific
iOS specific
<KeyboardAvoidingView>
with floating keyboard on iPadOS (3c54e1ee45 by @ renchap)Hermes dSYMS:
You can file issues or pick requests against this release here
To help you upgrade to this version, you can use the upgrade helper ⚛️
You can find the whole changelog history in the changelog.md file.
Commit messages
Package name: react-native
Compare
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs