-
-
Notifications
You must be signed in to change notification settings - Fork 29
Closed
Labels
devDependenciesDependencies only required for local dev or the prod build, NOT prod runtimeDependencies only required for local dev or the prod build, NOT prod runtimesecuritytransitiveTransitive dependenciesTransitive dependencies
Description
Address
- GHSA-67hx-6x53-jw92
- https://socket.dev/npm/package/@babel/traverse/overview/7.21.5
- https://www.cve.org/CVERecord?id=CVE-2023-45133
- https://github.com/leotm/react-native-template-new-architecture/security/dependabot/95
Resolved by
Avoid
- Update dependency @babel/runtime to v7.26.10 [SECURITY] #1774
- Update babel monorepo to v7.28.5 #1765
- these @babel/... devDependencies are far ahead of RN 0.71 (even further ahead of current nightly RN)
- https://github.com/react-native-community/template/blob/main/template/package.json#L18-L21-
- bundle/build ok, but could break runtime
- PR upstream first
Metadata
Metadata
Assignees
Labels
devDependenciesDependencies only required for local dev or the prod build, NOT prod runtimeDependencies only required for local dev or the prod build, NOT prod runtimesecuritytransitiveTransitive dependenciesTransitive dependencies