[Snyk] Security upgrade @react-native-community/cli from 1.1.0 to 9.0.0#30
[Snyk] Security upgrade @react-native-community/cli from 1.1.0 to 9.0.0#30mikew-zegon wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-15053838
|
This is a major upgrade across 8 major versions, from Core Breaking Change: Framework Incompatibility The most critical issue is the incompatibility between CLI versions and React Native versions. According to the official compatibility chart, this upgrade implies moving from React Native Key Breaking Changes in the CLI:
Source: React Native Community CLI Releases, React Native Community CLI README Recommendation: This is not a direct dependency upgrade. It must be treated as a full React Native framework upgrade. Developers must follow the official React Native upgrade guides to migrate the project from version
|
Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
package.jsonyarn.lockNote for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the
.yarn/cache/directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to runyarnto update the contents of the./yarn/cachedirectory.If you are not using zero-install you can ignore this as your flow should likely be unchanged.
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-LODASH-15053838
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Prototype Pollution