Skip to content

Commit fce9014

Browse files
authored
fix: bump vulnerable lodash and linkify versions (#3384)
## 🎯 Goal Port of [this PR](#3383) to the V8 release branch. ## πŸ›  Implementation details <!-- Provide a description of the implementation --> ## 🎨 UI Changes <!-- Add relevant screenshots --> <details> <summary>iOS</summary> <table> <thead> <tr> <td>Before</td> <td>After</td> </tr> </thead> <tbody> <tr> <td> <!--<img src="" /> --> </td> <td> <!--<img src="" /> --> </td> </tr> </tbody> </table> </details> <details> <summary>Android</summary> <table> <thead> <tr> <td>Before</td> <td>After</td> </tr> </thead> <tbody> <tr> <td> <!--<img src="" /> --> </td> <td> <!--<img src="" /> --> </td> </tr> </tbody> </table> </details> ## πŸ§ͺ Testing <!-- Explain how this change can be tested (or why it can't be tested) --> ## β˜‘οΈ Checklist - [ ] I have signed the [Stream CLA](https://docs.google.com/forms/d/e/1FAIpQLScFKsKkAJI7mhCr7K9rEIOpqIDThrWxuvxnwUq2XkHyG154vQ/viewform) (required) - [ ] PR targets the `develop` branch - [ ] Documentation is updated - [ ] New code is tested in main example apps, including all possible scenarios - [ ] SampleApp iOS and Android - [ ] Expo iOS and Android
1 parent 46b59c3 commit fce9014

File tree

2 files changed

+6
-11
lines changed

2 files changed

+6
-11
lines changed

β€Žpackage/package.jsonβ€Ž

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -74,8 +74,8 @@
7474
"emoji-regex": "^10.4.0",
7575
"i18next": "^25.2.1",
7676
"intl-pluralrules": "^2.0.1",
77-
"linkifyjs": "^4.3.1",
78-
"lodash-es": "4.17.21",
77+
"linkifyjs": "^4.3.2",
78+
"lodash-es": "4.17.23",
7979
"mime-types": "^2.1.35",
8080
"path": "0.12.7",
8181
"react-native-markdown-package": "1.8.2",

β€Žpackage/yarn.lockβ€Ž

Lines changed: 4 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6320,11 +6320,6 @@ lines-and-columns@^1.1.6:
63206320
resolved "https://registry.yarnpkg.com/lines-and-columns/-/lines-and-columns-1.2.4.tgz#eca284f75d2965079309dc0ad9255abb2ebc1632"
63216321
integrity sha512-7ylylesZQ/PV29jhEDl3Ufjo6ZX7gCqJr5F7PKrqc93v7fzSymt1BpwEU8nAUXs8qzzvqhbjhK5QZg6Mt/HkBg==
63226322

6323-
linkifyjs@^4.3.1:
6324-
version "4.3.1"
6325-
resolved "https://registry.yarnpkg.com/linkifyjs/-/linkifyjs-4.3.1.tgz#1f246ebf4be040002accd1f4535b6af7c7e37898"
6326-
integrity sha512-DRSlB9DKVW04c4SUdGvKK5FR6be45lTU9M76JnngqPeeGDqPwYc0zdUErtsNVMtxPXgUWV4HbXbnC4sNyBxkYg==
6327-
63286323
linkifyjs@^4.3.2:
63296324
version "4.3.2"
63306325
resolved "https://registry.yarnpkg.com/linkifyjs/-/linkifyjs-4.3.2.tgz#d97eb45419aabf97ceb4b05a7adeb7b8c8ade2b1"
@@ -6352,10 +6347,10 @@ locate-path@^6.0.0:
63526347
dependencies:
63536348
p-locate "^5.0.0"
63546349

6355-
lodash-es@4.17.21:
6356-
version "4.17.21"
6357-
resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.17.21.tgz#43e626c46e6591b7750beb2b50117390c609e3ee"
6358-
integrity sha512-mKnC+QJ9pWVzv+C4/U3rRsHapFfHvQFoFB92e52xeyGMcX6/OlIl78je1u8vePzYZSkkogMPJ2yjxxsb89cxyw==
6350+
lodash-es@4.17.23:
6351+
version "4.17.23"
6352+
resolved "https://registry.yarnpkg.com/lodash-es/-/lodash-es-4.17.23.tgz#58c4360fd1b5d33afc6c0bbd3d1149349b1138e0"
6353+
integrity sha512-kVI48u3PZr38HdYz98UmfPnXl2DXrpdctLrFLCd3kOx1xUkOmpFPx7gCWWM5MPkL/fD8zb+Ph0QzjGFs4+hHWg==
63596354

63606355
lodash.debounce@^4.0.8:
63616356
version "4.0.8"

0 commit comments

Comments
Β (0)