Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade react-native from 0.55.4 to 0.62.2 #1

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

@snyk-bot snyk-bot commented May 4, 2020

Snyk has created this PR to upgrade react-native from 0.55.4 to 0.62.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
  • The recommended version is 77 versions ahead of your current version.
  • The recommended version was released 25 days ago, on 2020-04-08.

The recommended version fixes:

Severity Issue Exploit Maturity
Denial of Service (DoS)
npm:ws:20171108
Mature
Regular Expression Denial of Service (ReDoS)
npm:plist:20180219
Proof of Concept
Regular Expression Denial of Service (ReDoS)
npm:plist:20180219
Proof of Concept
Arbitrary File Overwrite
SNYK-JS-TAR-174125
No Known Exploit
Denial of Service (DoS)
npm:mem:20180117
No Known Exploit
Time of Check Time of Use (TOCTOU)
npm:chownr:20180731
No Known Exploit
Arbitrary Code Injection
SNYK-JS-MORGAN-72579
Proof of Concept
Prototype Pollution
npm:lodash:20180130
No Known Exploit
Regular Expression Denial of Service (ReDoS)
npm:braces:20180219
Proof of Concept
Prototype Pollution
SNYK-JS-MERGE-72553
Mature
Release notes
Package name: react-native
  • 0.62.2 - 2020-04-08

    This release fixes a few minor issues that were reported by the community. You can view the complete changelog here.

    You can participate in the conversation for the next patch release in the dedicated issue.


    To help you upgrade to this version, you can use the new upgrade helper ⚛️


    You can find the whole changelog history over at react-native-releases.

  • 0.62.1 - 2020-04-03

    This release fixes a YellowBox regression in v0.62.0 where the Flipper network inspector causes YellowBox to crash the app due to using base64 images.

    You can view the complete changelog here.

    You can participate in the conversation for the next patch release in the dedicated issue.


    To help you upgrade to this version, you can use the new upgrade helper ⚛️


    You can find the whole changelog history over at react-native-releases.

  • 0.62.0 - 2020-03-26

    0.62.0

    0.62 stable is here 🎉

    Thanks to everyone who contributed and helped to get this together, everyone worked really hard and we hope you are as excited as we are 🤗

    Some of the major changes that this version brings:

    • Flipper support
    • a new LogBox experience
    • better dark mode support

    Among many others - please refer to the blog post for more details.


    This release comes in the midst of a global pandemic. We’re releasing this version today to respect the work of hundreds of contributors who made this release possible and to prevent the release from falling too far behind master. You can participate in the conversation on the status of this release at this issue, but please be mindful of the reduced capacity of contributors to help with issues and prepare to delay upgrading if necessary.


    You can upgrade to this version using the upgrade helper webtool ⚛️
    And if you are having troubles, please refer to the new Upgrade Support repository by our awesome community.


    You can find the whole changelog history over at react-native-releases.

  • 0.62.0-rc.5 - 2020-03-07

    THIS IS A RELEASE CANDIDATE: this means it's not stable yet, so proceed with care.

    Please only upgrade or create new apps with 0.62.0-rc.5 if you'd like to help us test this before the stable release - which would be super useful 🤗

    To test it, run:

    npx react-native init RN062 --version 0.62.0-rc.5

    This version introduces the new LogBox experience behind a feature flag. To try it out, add the following to your index.js file:

    require('react-native').unstable_enableLogBox()

    This version also introduces Flipper integration and support for a new version of Hermes (0.4.0). For details and to report issues, see this issue.


    This release will be quite massive (there are around 1200 commits of delta between this version and 0.61!) so we don't have the changelog ready yet (draft PR) - it will be fully ready for when we will publish 0.62.0.

    You can participate in the conversation on the RC status this issue for updates, where you can post your bug reports and cherry-pick suggestions.


    You can find the whole changelog history over at react-native-releases.

  • 0.62.0-rc.4 - 2020-03-06

    THIS IS A RELEASE CANDIDATE: this means it's not stable yet, so proceed with care.

    Please only upgrade or create new apps with 0.62.0-rc.4 if you'd like to help us test this before the stable release - which would be super useful 🤗

    To test it, run:

    npx react-native init RN062 --version 0.62.0-rc.4

    This version introduces the new LogBox experience behind a feature flag. To try it out, add the following to your index.js file:

    require('react-native').unstable_enableLogBox()

    This version also introduces Flipper integration and support for a new version of Hermes (0.4.0). For details and to report issues, see this issue.


    This release will be quite massive (there are around 1200 commits of delta between this version and 0.61!) so we don't have the changelog ready yet (draft PR) - it will be fully ready for when we will publish 0.62.0.

    You can participate in the conversation on the RC status this issue for updates, where you can post your bug reports and cherry-pick suggestions.


    You can find the whole changelog history over at react-native-releases.

  • 0.62.0-rc.3 - 2020-02-25

    THIS IS A RELEASE CANDIDATE: this means it's not stable yet, so proceed with care.

    Please only upgrade or create new apps with 0.62.0-rc.3 if you'd like to help us test this before the stable release - which would be super useful 🤗

    To test it, run:

    npx react-native init RN062 --version 0.62.0-rc.3

    RC3 introduces the new LogBox experience behind a feature flag. To try it out, add the following to your index.js file:

    require('react-native').unstable_enableLogBox()

    RC3 also introduces Flipper integration and support for a new version of Hermes (0.4.0). For details and to report issues, see this issue.


    This release will be quite massive (there are around 1200 commits of delta between this version and 0.61!) so we don't have the changelog ready yet (draft PR) - it will be fully ready for when we will publish 0.62.0.

    You can participate in the conversation on the RC status this issue for updates, where you can post your bug reports and cherry-pick suggestions.


    You can find the whole changelog history over at react-native-releases.

  • 0.62.0-rc.2 - 2020-02-13

    THIS IS A RELEASE CANDIDATE: this means it's not stable yet, so proceed with care.

    Please only upgrade or create new apps with 0.62.0-rc.2 if you'd like to help us test this before the stable release - which would be super useful 🤗

    To test it, run:

    npx react-native init RN062 --version 0.62.0-rc.2

    RC2 introduces the new LogBox experience behind a feature flag. To try it out, add the following to your index.js file:

    require('react-native').unstable_enableLogBox()

    RC2 also introduces Flipper integration. For details and to report issues, see this issue.


    This release will be quite massive (there are around 1200 commits of delta between this version and 0.61!) so we don't have the changelog ready yet (draft PR) - it will be fully ready for when we will publish 0.62.0.

    You can participate in the conversation on the RC status this issue for updates, where you can post your bug reports and cherry-pick suggestions.


    You can find the whole changelog history over at react-native-releases.

  • 0.62.0-rc.1 - 2020-01-21

    THIS IS A RELEASE CANDIDATE: this means it's not stable yet, so proceed with care.

    Please only upgrade or create new apps with 0.62.0-rc.1 if you'd like to help us test this before the stable release - which would be super useful 🤗

    To test it, run:

    npx react-native init RN062 --version 0.62.0-rc.1

    This RC1 introduces the new LogBox experience behind a feature flag: to try it out, add in the index.js file:

    require('react-native').unstable_enableLogBox()

    We are also aware of some Android and Hermes related issues, keep an eye on the RC status issue to know more - they are still being investigated but will likely be fixed in the next RC.


    This release will be quite massive (there are around 1200 commits of delta between this version and 0.61!) so we don't have the changelog ready yet (draft PR) - it will be fully ready for when we will publish 0.62.0.

    You can participate in the conversation on the RC status this issue for updates, where you can post your bug reports and cherry-pick suggestions.


    You can find the whole changelog history over at react-native-releases.

  • 0.62.0-rc.0 - 2019-12-18
  • 0.61.5 - 2019-11-23
  • 0.61.4 - 2019-11-04
  • 0.61.3 - 2019-10-29
  • 0.61.2 - 2019-10-02
  • 0.61.1 - 2019-09-25
  • 0.61.0 - 2019-09-24
  • 0.61.0-rc.3 - 2019-09-10
  • 0.61.0-rc.2 - 2019-09-04
  • 0.61.0-rc.0 - 2019-08-27
  • 0.60.6 - 2019-09-24
  • 0.60.5 - 2019-08-13
  • 0.60.4 - 2019-07-18
  • 0.60.3 - 2019-07-11
  • 0.60.2 - 2019-07-11
  • 0.60.1 - 2019-07-11
  • 0.60.0 - 2019-07-03
  • 0.60.0-rc.3 - 2019-06-28
  • 0.60.0-rc.2 - 2019-06-20
  • 0.60.0-rc.1 - 2019-06-10
  • 0.60.0-rc.0 - 2019-05-30
  • 0.59.10 - 2019-07-02
  • 0.59.9 - 2019-06-05
  • 0.59.8 - 2019-05-08
  • 0.59.7 - 2019-05-08
  • 0.59.6 - 2019-04-18
  • 0.59.5 - 2019-04-17
  • 0.59.4 - 2019-04-08
  • 0.59.3 - 2019-04-01
  • 0.59.2 - 2019-03-25
  • 0.59.1 - 2019-03-14
  • 0.59.0 - 2019-03-12
  • 0.59.0-rc.3 - 2019-02-27
  • 0.59.0-rc.2 - 2019-02-18
  • 0.59.0-rc.1 - 2019-02-15
  • 0.59.0-rc.0 - 2019-02-13
  • 0.58.6 - 2019-02-28
  • 0.58.5 - 2019-02-19
  • 0.58.4 - 2019-02-06
  • 0.58.3 - 2019-01-28
  • 0.58.2 - 2019-01-28
  • 0.58.1 - 2019-01-25
  • 0.58.0 - 2019-01-24
  • 0.58.0-rc.3 - 2019-01-17
  • 0.58.0-rc.2 - 2018-12-18
  • 0.58.0-rc.1 - 2018-12-06
  • 0.58.0-rc.0 - 2018-11-22
  • 0.57.8 - 2018-12-13
  • 0.57.7 - 2018-11-27
  • 0.57.6 - 2018-11-26
  • 0.57.5 - 2018-11-13
  • 0.57.4 - 2018-10-25
  • 0.57.3 - 2018-10-12
  • 0.57.2 - 2018-10-04
  • 0.57.1 - 2018-09-21
  • 0.57.0 - 2018-09-12
  • 0.57.0-rc.4 - 2018-09-06
  • 0.57.0-rc.3 - 2018-08-24
  • 0.57.0-rc.2 - 2018-08-22
  • 0.57.0-rc.1 - 2018-08-22
  • 0.57.0-rc.0 - 2018-08-16
  • 0.56.1 - 2018-09-10
  • 0.56.0 - 2018-07-04
  • 0.56.0-rc.5 - 2018-07-04
  • 0.56.0-rc.4 - 2018-06-27
  • 0.56.0-rc.3 - 2018-06-22
  • 0.56.0-rc.2 - 2018-06-15
  • 0.56.0-rc.1 - 2018-06-13
  • 0.56.0-rc - 2018-06-11
  • 0.55.4 - 2018-05-08
from react-native GitHub release notes
Commit messages
Package name: react-native
  • b9944e5 [0.62.2] Bump version numbers
  • f89c509 Make Vibration.vibrate compatible with TurboModules (#27951)
  • 8858d87 Exclude all FlipperKit transitive dependencies from iOS Release builds (#28504)
  • 4fd9c9d Fix Appearance module when using Chrome Debugger
  • 6e530d9 Move DebugEnvironment helper to open source
  • 6b6877d Fix crash when enabling Performance Monitor on iOS 13.4 (#28512)
  • 9a00cec Fix mock for TextInput (#28332)
  • 8e705b7 Merge pull request #28520 from thymikee/fix/flow-types
  • a049130 [General] [Fixed] Flow errors from YellowBox and BubblingEventHandler
  • 25011a6 [0.62.1] Bump version numbers
  • 2b434af [Internal] [Changed] - Update lockfiles.
  • 4067f90 Seed ssh known hosts with github's public key (#28370)
  • eac56b9 [General] [Fixed] - Bump CLI to 4.5.1 to improve DX
  • 27a3248 [iOS] [Fixed] - Revert [previous incomplete fix](https://github.com/facebook/react-native/commit/bd2b7d6c0366b5f19de56b71cb706a0af4b0be43) for [an issue](https://github.com/Modal's onDismiss callback is wrongly implemented in 0.61.0-rc.3 facebook/react-native#26473) with `Modal`’s `onDismiss` prop.
  • 8ba46aa chore: update url of warning message from deprecated imports (#28452)
  • d7d4fae Fix issue with onEndReached
  • 7efc779 Add new DoNotStrip class to proguard config (#27934)
  • cad697d Dark mode support for RCTPerfMonitor (#28130)
  • 30aad14 tapping on iOS status bar should scroll inverted ScrollViews to their top (#27574)
  • 227aa96 Fix YellowBox in 0.62 (#28457)
  • 9101eaf [0.62.0] Bump version numbers
  • 1f8b698 Pressability: Fix Missing `onLongPress` Gestures
  • f6a8452 Bump FlipperKit version on iOS to be compatible with react-native-flipper (#28277)
  • e8a368c Upgrade Flipper Android to 0.33.1 (#28275)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant