[Snyk] Security upgrade expo from 33.0.7 to 34.0.1 #35

Open
morten-olsen wants to merge 1 commit from snyk-fix-cb09c820741c39712d09c6c12cf8225c into master
morten-olsen commented 2022-10-18 02:38:54 +02:00 (Migrated from github.com)

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

merge advice

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • packages/demo/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-REACTNATIVEREANIMATED-2949507
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: expo The new version differs by 250 commits.
  • 9518929 [templates] fix name of expo-template-bare-typescript in package.json
  • 596c05c [expo] Remove react-google-maps and react-native-maps + the web polyfill and lottie-react-native
  • 4dd7760 [templates] Add bare-typescript template and improve dev dependencies on blank bare
  • 32ae1cf [packages] updated babel-preset-expo dependencies
  • 8ba2a26 [tools-public] Install expo-cli to make project resemble 4e466bd which is last commit on which shell_app_build_ios successfully finished
  • d99a3be Revert "[circle-ci] Install expo-cli globally in CircleCI."
  • 9f2547c [circle-ci] Install expo-cli globally in CircleCI.
  • 850848e [tools][tools-public] Bump xdl.
  • d4b5c55 Update packages
  • 811af7e [expo] Add requiresExtraSetup to files in package.json
  • a58ad56 Update packages
  • 912c336 [expo] Add requiresExtraSetup.json for use upon eject
  • a196398 [xdl] Bump xdl in tools-public. Bump expo-cli.
  • 8138ef5 Bump xdl.
  • c6ca7aa [templates] Bump version and sdk.
  • a242238 [ncl] Revert SDK to UNVERSIONED
  • 5c3af20 [sdk34][expokit] Rebuild and publish 'expokit@34.0.0-rc.4'
  • 5ce6ba9 [tools] Revert changes that broke building shell apps
  • c2cdb5e [ios] bump version to 2.12.1 for iOS 13 fix
  • 64477e3 [sdk34][expokit] Rebuild and publish 'expokit@34.0.0-rc.3'
  • 2c56566 [tools] Restore flags for xdl for building shell apps and add new flags for expokit publishing
  • 45c113f [sdk34][expokit] Rebuild and publish 'expokit@34.0.0-rc.2'
  • 3d5e36f [expo-in-app-purchases] Publish 'expo-in-app-purchases@6.0.0-rc.1'
  • 240b4db [sdk34][expokit] Publish 'expokit-npm-package@34.0.0-rc.1'

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)

<p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.</h3> ![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=expo&from_version=33.0.7&to_version=34.0.1&pr_id=23b9ec85-9df9-402e-8121-8af57a67f14b&visibility=true&has_feature_flag=false) #### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - packages/demo/package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **658/1000** <br/> **Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3 | Regular Expression Denial of Service (ReDoS) <br/>[SNYK-JS-REACTNATIVEREANIMATED-2949507](https://snyk.io/vuln/SNYK-JS-REACTNATIVEREANIMATED-2949507) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised. <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>expo</b></summary> The new version differs by 250 commits.</br> <ul> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/9518929d6f2ba9cf8e0aae81d34cc1eb52f7093a">9518929</a> [templates] fix name of expo-template-bare-typescript in package.json</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/596c05cfaa1b367235fb677f998a4c13b11a187c">596c05c</a> [expo] Remove react-google-maps and react-native-maps + the web polyfill and lottie-react-native</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/4dd7760ae8cc7aa86013c636535215dcfac73583">4dd7760</a> [templates] Add bare-typescript template and improve dev dependencies on blank bare</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/32ae1cf265ee16e6daf49d2549230cde39798911">32ae1cf</a> [packages] updated babel-preset-expo dependencies</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/8ba2a26d5701445dc7f22bc31900a492c8d6b9d4">8ba2a26</a> [tools-public] Install expo-cli to make project resemble 4e466bd which is last commit on which shell_app_build_ios successfully finished</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/d99a3be637b4277d0e4f4e64d85d256d73a14ab5">d99a3be</a> Revert &quot;[circle-ci] Install expo-cli globally in CircleCI.&quot;</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/9f2547c48676c9c7a8d83678b6133be686e4cf68">9f2547c</a> [circle-ci] Install expo-cli globally in CircleCI.</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/850848eb737d08d07a3cad7103d8d99dcceaa766">850848e</a> [tools][tools-public] Bump xdl.</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/d4b5c55e415db2de0ce1c5765d99525e796a6374">d4b5c55</a> Update packages</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/811af7e559aac70eecb8cf20478f0d33b40006cc">811af7e</a> [expo] Add requiresExtraSetup to files in package.json</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/a58ad564463ac3c111e92c87f847720eb7be9ebd">a58ad56</a> Update packages</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/912c336387fffede404c8d2bef33bd9ecd7e1188">912c336</a> [expo] Add requiresExtraSetup.json for use upon eject</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/a196398d674561ebf55b653384de699f9ce99017">a196398</a> [xdl] Bump xdl in tools-public. Bump expo-cli.</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/8138ef5833f4a95555e42e3536d9d0e8abe786dc">8138ef5</a> Bump xdl.</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/c6ca7aa120e4a232c64baf0a30607604c1f1f575">c6ca7aa</a> [templates] Bump version and sdk.</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/a242238e12c3b713a2ec787d8f1cf1574b80875d">a242238</a> [ncl] Revert SDK to UNVERSIONED</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/5c3af20714043697e7761be48b84e5d3fb3144bb">5c3af20</a> [sdk34][expokit] Rebuild and publish &#x27;expokit@34.0.0-rc.4&#x27;</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/5ce6ba91ac1573dbed027da3945c6a9fe59e9829">5ce6ba9</a> [tools] Revert changes that broke building shell apps</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/c2cdb5ed05b6df670c6bae0cb80c58534fadc3ec">c2cdb5e</a> [ios] bump version to 2.12.1 for iOS 13 fix</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/64477e39cb8ec6f0b1a505393d40e73f073914f6">64477e3</a> [sdk34][expokit] Rebuild and publish &#x27;expokit@34.0.0-rc.3&#x27;</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/2c5656634a2f2284a7dbfca420e3714a2c91de56">2c56566</a> [tools] Restore flags for xdl for building shell apps and add new flags for expokit publishing</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/45c113f91f225d7112dcfb4e0347ce53835fc3d0">45c113f</a> [sdk34][expokit] Rebuild and publish &#x27;expokit@34.0.0-rc.2&#x27;</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/3d5e36f1fee6485b845f2653733f290e0d36676c">3d5e36f</a> [expo-in-app-purchases] Publish &#x27;expo-in-app-purchases@6.0.0-rc.1&#x27;</li> <li><a href="https://snyk.io/redirect/github/expo/expo/commit/240b4db8a6911787b3fb623c199e3193934d7fe2">240b4db</a> [sdk34][expokit] Publish &#x27;expokit-npm-package@34.0.0-rc.1&#x27;</li> </ul> <a href="https://snyk.io/redirect/github/expo/expo/compare/f213c9be2a909dae42a0a27d8aa4b9eac8e97be1...9518929d6f2ba9cf8e0aae81d34cc1eb52f7093a">See the full diff</a> </details> </details> Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIyM2I5ZWM4NS05ZGY5LTQwMmUtODEyMS04YWY1N2E2N2YxNGIiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjIzYjllYzg1LTlkZjktNDAyZS04MTIxLThhZjU3YTY3ZjE0YiJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/morten-olsen/project/a90e32d7-b1f4-49fb-9bb1-80512396d067?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/morten-olsen/project/a90e32d7-b1f4-49fb-9bb1-80512396d067?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"23b9ec85-9df9-402e-8121-8af57a67f14b","prPublicId":"23b9ec85-9df9-402e-8121-8af57a67f14b","dependencies":[{"name":"expo","from":"33.0.7","to":"34.0.1"}],"packageManager":"npm","projectPublicId":"a90e32d7-b1f4-49fb-9bb1-80512396d067","projectUrl":"https://app.snyk.io/org/morten-olsen/project/a90e32d7-b1f4-49fb-9bb1-80512396d067?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-REACTNATIVEREANIMATED-2949507"],"upgrade":["SNYK-JS-REACTNATIVEREANIMATED-2949507"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore","merge-advice-badge-shown"],"priorityScoreList":[658]}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lessons/redos/javascript/?loc&#x3D;fix-pr)
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin snyk-fix-cb09c820741c39712d09c6c12cf8225c:snyk-fix-cb09c820741c39712d09c6c12cf8225c
git switch snyk-fix-cb09c820741c39712d09c6c12cf8225c

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch master
git merge --no-ff snyk-fix-cb09c820741c39712d09c6c12cf8225c
git switch snyk-fix-cb09c820741c39712d09c6c12cf8225c
git rebase master
git switch master
git merge --ff-only snyk-fix-cb09c820741c39712d09c6c12cf8225c
git switch snyk-fix-cb09c820741c39712d09c6c12cf8225c
git rebase master
git switch master
git merge --no-ff snyk-fix-cb09c820741c39712d09c6c12cf8225c
git switch master
git merge --squash snyk-fix-cb09c820741c39712d09c6c12cf8225c
git switch master
git merge --ff-only snyk-fix-cb09c820741c39712d09c6c12cf8225c
git switch master
git merge snyk-fix-cb09c820741c39712d09c6c12cf8225c
git push origin master
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
incubator/react-native-debug-console!35
No description provided.