Commit 1d13b19
committed
fix: resolve Dependabot security vulnerabilities
- Update @react-native-community/cli from 11.3.2 to 17.0.1
- Add resolutions to force secure versions:
- js-yaml: ^3.14.2 (fixes prototype pollution CVE)
- min-document: ^2.19.1 (fixes prototype pollution)
- Transitive dependency updates via yarn.lock:
- on-headers: 1.1.0 (fixes CVE-2025-7339)
- compression: 1.8.1 (fixes CVE-2025-7339)
- brace-expansion: 1.1.12 (fixes ReDoS vulnerability)
Resolves: #53, #54, #59, #611 parent 1da55ae commit 1d13b19
3 files changed
Lines changed: 291 additions & 57 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
48 | | - | |
| 48 | + | |
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
10 | 14 | | |
11 | 15 | | |
12 | 16 | | |
| |||
0 commit comments