Commit bff4a8a
Fix CVE-2021-3807: Upgrade transitive dependency ansi-regex from 4.1.1 to 5.0.1
Summary:
Fix CVE-2021-3807: Upgrade transitive dependency ansi-regex from 4.1.1 to 5.0.1
## Summary
Upgrading the transitive dependency `ansi-regex` from 4.1.1 to 5.0.1 to fix CVE-2021-3807 (ReDoS vulnerability).
**Dependency chain:** react-native/tester -> react-native-community/cli-platform-android -> logkitty -> ansi-fragments -> strip-ansi -> ansi-regex@4.1.1
The fix was applied via a temporary yarn resolution, then removed. The version stuck at 5.0.1 without the resolution. Only yarn.lock is changed.
Changelog:
[General][Security] -Upgrade transitive dependency ansi-regex from 4.1.1 to 5.0.1
Differential Revision: D998675051 parent 8bac1df commit bff4a8a
1 file changed
+3
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2681 | 2681 | | |
2682 | 2682 | | |
2683 | 2683 | | |
2684 | | - | |
2685 | | - | |
2686 | | - | |
| 2684 | + | |
| 2685 | + | |
| 2686 | + | |
2687 | 2687 | | |
2688 | 2688 | | |
2689 | 2689 | | |
| |||
0 commit comments