-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
$npm audit fix --force
npm WARN using --force Recommended protections disabled.
npm WARN audit Updating react-native-unimodules to 0.14.10,which is a SemVer major change.
npm WARN deprecated react-native-unimodules@0.14.10: replaced by the 'expo' package, learn more: https://blog.expo.dev/whats-new-in-expo-modules-infrastructure-7a7cdda81ebc
npm WARN deprecated @unimodules/core@7.1.2: replaced by the 'expo' package, learn more: https://blog.expo.dev/whats-new-in-expo-modules-infrastructure-7a7cdda81ebc
npm WARN deprecated @unimodules/react-native-adapter@6.3.9: replaced by the 'expo' package, learn more: https://blog.expo.dev/whats-new-in-expo-modules-infrastructure-7a7cdda81ebc
added 34 packages, removed 42 packages, changed 14 packages, and audited 3038 packages in 10s
169 packages are looking for funding
run `npm fund` for details
# npm audit report
ajv <6.12.3
Severity: moderate
Prototype Pollution in Ajv - https://github.com/advisories/GHSA-v88g-cgmw-v5xw
fix available via `npm audit fix`
node_modules/@expo/schemer/node_modules/ajv
@expo/schemer <=1.4.1
Depends on vulnerable versions of ajv
node_modules/@expo/schemer
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
ansi-html <0.0.8
Severity: high
Uncontrolled Resource Consumption in ansi-html - https://github.com/advisories/GHSA-whgm-jr23-g3j9
fix available via `npm audit fix`
node_modules/ansi-html
webpack-dev-server 2.0.0-beta - 4.7.2
Depends on vulnerable versions of ansi-html
Depends on vulnerable versions of chokidar
Depends on vulnerable versions of selfsigned
node_modules/webpack-dev-server
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
axios <0.21.2
Severity: high
Incorrect Comparison in axios - https://github.com/advisories/GHSA-cph5-m8f7-6c5x
fix available via `npm audit fix`
node_modules/axios
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
browserslist 4.0.0 - 4.16.4
Severity: moderate
Regular Expression Denial of Service in browserslist - https://github.com/advisories/GHSA-w8qv-6jwh-64r5
fix available via `npm audit fix`
node_modules/react-dev-utils/node_modules/browserslist
react-dev-utils 0.6.0-alpha.f55d2212 - 12.0.0-next.60
Depends on vulnerable versions of browserslist
Depends on vulnerable versions of immer
Depends on vulnerable versions of shell-quote
node_modules/react-dev-utils
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
glob-parent <5.1.2
Severity: high
glob-parent before 5.1.2 vulnerable to Regular Expression Denial of Service in enclosure regex - https://github.com/advisories/GHSA-ww39-953v-wcq6
fix available via `npm audit fix`
node_modules/webpack-dev-server/node_modules/glob-parent
chokidar 1.0.0-rc1 - 2.1.8
Depends on vulnerable versions of glob-parent
node_modules/webpack-dev-server/node_modules/chokidar
webpack-dev-server 2.0.0-beta - 4.7.2
Depends on vulnerable versions of ansi-html
Depends on vulnerable versions of chokidar
Depends on vulnerable versions of selfsigned
node_modules/webpack-dev-server
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
got <11.8.5
Severity: moderate
Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97
fix available via `npm audit fix`
node_modules/is-reachable/node_modules/got
node_modules/package-json/node_modules/got
is-reachable 2.0.0 - 4.0.0
Depends on vulnerable versions of got
node_modules/is-reachable
package-json <=6.5.0
Depends on vulnerable versions of got
node_modules/package-json
latest-version 0.2.0 - 5.1.0
Depends on vulnerable versions of package-json
node_modules/latest-version
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
immer <9.0.6
Severity: critical
Prototype Pollution in immer - https://github.com/advisories/GHSA-33f9-j839-rf8h
fix available via `npm audit fix`
node_modules/immer
react-dev-utils 0.6.0-alpha.f55d2212 - 12.0.0-next.60
Depends on vulnerable versions of browserslist
Depends on vulnerable versions of immer
Depends on vulnerable versions of shell-quote
node_modules/react-dev-utils
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
node-forge <=1.2.1
Severity: high
Improper Verification of Cryptographic Signature in node-forge - https://github.com/advisories/GHSA-cfm4-qjh2-4765
URL parsing in node-forge could lead to undesired behavior. - https://github.com/advisories/GHSA-gf8q-jrpm-jvxq
fix available via `npm audit fix`
node_modules/selfsigned/node_modules/node-forge
node_modules/xdl/node_modules/node-forge
selfsigned 1.1.1 - 1.10.14
Depends on vulnerable versions of node-forge
node_modules/selfsigned
webpack-dev-server 2.0.0-beta - 4.7.2
Depends on vulnerable versions of ansi-html
Depends on vulnerable versions of chokidar
Depends on vulnerable versions of selfsigned
node_modules/webpack-dev-server
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
nth-check <2.0.1
Severity: high
Inefficient Regular Expression Complexity in nth-check - https://github.com/advisories/GHSA-rp65-9cf3-cjxr
fix available via `npm audit fix`
node_modules/svgo/node_modules/nth-check
css-select <=3.1.0
Depends on vulnerable versions of nth-check
node_modules/svgo/node_modules/css-select
svgo 1.0.0 - 1.3.2
Depends on vulnerable versions of css-select
node_modules/svgo
postcss-svgo 4.0.0-nightly.2020.1.9 - 5.0.0-rc.2
Depends on vulnerable versions of svgo
node_modules/postcss-svgo
cssnano-preset-default <=4.0.8
Depends on vulnerable versions of postcss-svgo
node_modules/cssnano-preset-default
cssnano 4.0.0-nightly.2020.1.9 - 4.1.11
Depends on vulnerable versions of cssnano-preset-default
node_modules/cssnano
optimize-css-assets-webpack-plugin 3.2.1 || 5.0.0 - 5.0.8
Depends on vulnerable versions of cssnano
node_modules/optimize-css-assets-webpack-plugin
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
shell-quote <=1.7.2
Severity: critical
Improper Neutralization of Special Elements used in a Command in Shell-quote - https://github.com/advisories/GHSA-g4rg-993r-mgx7
fix available via `npm audit fix`
node_modules/expo-cli/node_modules/shell-quote
node_modules/react-dev-utils/node_modules/shell-quote
node_modules/xdl/node_modules/shell-quote
@react-native-community/cli-tools 4.8.0 - 5.0.0-alpha.0 || 5.0.1-alpha.0 - 6.2.0
Depends on vulnerable versions of shell-quote
node_modules/expo-cli/node_modules/@react-native-community/cli-tools
node_modules/xdl/node_modules/@react-native-community/cli-tools
@react-native-community/cli-server-api <=5.0.1
Depends on vulnerable versions of @react-native-community/cli-tools
node_modules/expo-cli/node_modules/@react-native-community/cli-server-api
node_modules/xdl/node_modules/@react-native-community/cli-server-api
@expo/dev-server <=0.1.107
Depends on vulnerable versions of @react-native-community/cli-server-api
node_modules/expo-cli/node_modules/@expo/dev-server
node_modules/xdl/node_modules/@expo/dev-server
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
react-dev-utils 0.6.0-alpha.f55d2212 - 12.0.0-next.60
Depends on vulnerable versions of browserslist
Depends on vulnerable versions of immer
Depends on vulnerable versions of shell-quote
node_modules/react-dev-utils
@expo/webpack-config *
Depends on vulnerable versions of optimize-css-assets-webpack-plugin
Depends on vulnerable versions of react-dev-utils
node_modules/@expo/webpack-config
tar <=4.4.17
Severity: high
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links - https://github.com/advisories/GHSA-qq89-hq3f-393p
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links - https://github.com/advisories/GHSA-9r2w-394v-53qc
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization - https://github.com/advisories/GHSA-3jfq-g458-7qm9
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning - https://github.com/advisories/GHSA-r628-mhmh-qjhw
fix available via `npm audit fix`
node_modules/xdl/node_modules/tar
xdl 42.0.0-alpha.0 - 42.0.0 || >=44.0.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of @expo/schemer
Depends on vulnerable versions of axios
Depends on vulnerable versions of latest-version
Depends on vulnerable versions of node-forge
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of tar
Depends on vulnerable versions of webpack-dev-server
node_modules/xdl
expo-cli 1.1.0-alpha.0 - 2.18.0 || >=3.21.2
Depends on vulnerable versions of @expo/dev-server
Depends on vulnerable versions of react-dev-utils
Depends on vulnerable versions of xdl
node_modules/expo-cli
xmldom *
Severity: moderate
Misinterpretation of malicious XML input - https://github.com/advisories/GHSA-5fg8-2547-mr8q
fix available via `npm audit fix --force`
Will install react-native-unimodules@0.15.0, which is a breaking change
node_modules/xmldom
@expo/plist <=0.0.13
Depends on vulnerable versions of xmldom
node_modules/react-native-unimodules/node_modules/@expo/plist
@expo/config-plugins <=3.0.8
Depends on vulnerable versions of @expo/plist
node_modules/react-native-unimodules/node_modules/@expo/config-plugins
@expo/config 3.3.23-alpha.0 - 5.0.8
Depends on vulnerable versions of @expo/config-plugins
node_modules/react-native-unimodules/node_modules/@expo/config
expo-constants 10.1.2 - 11.1.0
Depends on vulnerable versions of @expo/config
node_modules/react-native-unimodules/node_modules/expo-constants
react-native-unimodules 0.13.2 - 0.15.0-alpha.0
Depends on vulnerable versions of expo-constants
node_modules/react-native-unimodules
37 vulnerabilities (1 low, 13 moderate, 15 high, 8 critical)
To address issues that do not require attention, run:
npm audit fix
To address all issues (including breaking changes), run:
npm audit fix --force
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels